Computing.Net > Forums > Security and Virus > Parite Virus

Parite Virus

Reply to Message Icon

Original Message
Name: Nemi
Date: February 12, 2005 at 13:45:30 Pacific
Subject: Parite Virus
OS: Win XP
CPU/Ram: Pentium 4, 512 MB Ram
Comment:

Okei, so I have a Parite virus on my comp. AVG detected it, I ran it and it found the virus, but was unable to remove it. I downloaded an anti-parite tool from bit defender and it didn't even detect the virus. Now, AVG keeps popping up with "virus detected" blah blah but when I run AVG now, it doesn't detect it in the actual scan.

What's worse is that when I went to go to the location in which the virus was detected, which was C:\System Volume Information, it said "access denied". Not only that but that fold isn't visable to me when I have hidden files turned on.

Am I just screwed here? And if I am, are zip files containing .exe's safe since they're zipped?

Let me link you guys to some info about this one as well

http://www.antivirusworld.com/articles/parite.php

Thanks in advance.


PS- read some previous post. I didn't disable system restore until just now and now I'm d/ling the Norton Antivirus trial. I got some info from Symantec. Hopefully it will work! If not, then I'll just come and amend my post. >.<


Report Offensive Message For Removal


Response Number 1
Name: Sabertooth
Date: February 12, 2005 at 14:22:38 Pacific
Reply: (edit)

0. Leave system restore turned OFF.
1. Reboot into safemode.
2. Run RAVScan.
3. Delete all errant files found.
4. Reenable system restore.

B4 you criticize a bigger man, walk a mile in his shoes. That way, you're a mile away, and you have his shoes.


Report Offensive Follow Up For Removal

Response Number 2
Name: Nemi
Date: February 12, 2005 at 18:45:19 Pacific
Reply: (edit)

The download section for that site is closed, so I was unable to d/l the 30 day trial.

I followed those exact steps using both Norton and AVG and neither detected anything.

And also, now my internet isn't working from my computer. I'm now using a family member's computer to reply.

Thank you though.


Report Offensive Follow Up For Removal

Response Number 3
Name: Sabertooth
Date: February 12, 2005 at 19:58:50 Pacific
Reply: (edit)

You do not need to d/l or install anything all you need to do is run the online scan from that link.

What do you mean "my internet isn't working from my computer", are you getting page cannot be displayed or what?


B4 you criticize a bigger man, walk a mile in his shoes. That way, you're a mile away, and you have his shoes.


Report Offensive Follow Up For Removal

Response Number 4
Name: stay_positive
Date: February 16, 2005 at 23:04:02 Pacific
Reply: (edit)

Hey Friend,
Parite/Pinfi is one of the MOST destructive viruses around. But almost all antivirus websites under-rate it's destructive abiliities. I got this virus on my networked pcs, 4 in all, and had a helluva time getting it out. But now it's gone. I tried most of the removal tools found on the net, I won't name them but none was abt to disinfect my pcs completely. Probably, there is some line of code or a specific file in your system that has to be removed to get rid of this virus, and Trendmicro's scan engine manages to do that successfully.

Here is the solution:
Download the below scan engine provided by www.Trendmicro.com and also the latest pattern file and then run the scan engine.

-----------------
Scan engine can be downloaded from:
http://www.trendmicro.com/download/dcs.asp


Go to the Section:
"If you are not a Trend Micro customer please download the following file.

Sysclean Package 2.5MB"
(Download this)

------------------

The latest pattern file can be downloaded from:
http://www.trendmicro.com/download/pattern.asp

------------------

THANKS A LOT TRENDMICRO! U GUYS ARE SIMPLY GR8!



Report Offensive Follow Up For Removal

Response Number 5
Name: dstarfire
Date: March 15, 2005 at 17:11:41 Pacific
Reply: (edit)

I had this virus as well, and it is very nasty and pernicious.

Apparently the section you read didn't say anything about how the virus works/spreads. Check out http://www.bitdefender.com/bd/site/virusinfo.php?menu_id=1&v_id=137 for more detailed info, but here's the short version:


parnite/pinfi/... initially attaches itself to explorer.exe, then scans your system for .exe and .scr files, infecting each one it finds.

So, if you're still infected, odds are it's because you didn't get it cleaned out of explorer.exe, which is a core component of windows and is always running (it controls the graphical interface).

Norton AV supposedly has instructions to totally remove parite, but I haven't had much luck there, so far.



Report Offensive Follow Up For Removal







Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: Parite Virus

Comments:

 


  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 
Data Recovery Software




Have you ever used OpenOffice?

Yes, as my main suite.
Yes, occationally.
Yes, but only once.
No, never.


View Results

Poll Finishes In 5 Days.
Discuss in The Lounge