 
                                
                    
                        Re: Crono: Crap damn crap.
                        Posted by 7dk2h4md720ih on 
    Sun Mar 21st 2004 at 11:42am
                     
                    
                        
                        Posted 
    2004-03-21 11:42am
                     
                 
                
            
            
                
    
            1976 posts
        198 snarkmarks
        Registered: 
    Oct 9th 2001
                     
                
                        Hey, I can't actually read the topic I just started, it closes my browser each time I click on it, whatever the trigger word is.. Anyhow, I'm in the snarkpit irc channel in quakenet.net if anyone wants to help me out. Thanks. :smile:
                                    
             
        
            
            
                                     
                                
                    
                        Re: Crono: Crap damn crap.
                        Posted by 7dk2h4md720ih on 
    Sun Mar 21st 2004 at 11:44am
                     
                    
                        
                        Posted 
    2004-03-21 11:44am
                     
                 
                
            
            
                
    
            1976 posts
        198 snarkmarks
        Registered: 
    Oct 9th 2001
                     
                
                        I found it with avg, It's called win32/parite. How do I go about removing it completely? I deleted both infected files but it's still there.
                                    
             
        
            
            
                                     
                                
                    
                        Re: Crono: Crap damn crap.
                        Posted by Crono on 
    Sun Mar 21st 2004 at 11:55am
                     
                    
                        
                        Posted 
    2004-03-21 11:55am
                     
                 
                
            
            
                
    
                    
                             Crono
                            Crono
            
                        super admin
     
            6628 posts
        700 snarkmarks
        Registered: 
    Dec 19th 2003
                            Location: Oregon, USA
             
                
                        That's the PINF thing ... it's annoying as hell.
Here's what you need to do. Log in as the administrator, goto the temp directory of the user which is infected, just delete everything there (if something is there a program needs the program will re-create it, so no worries) They are enbeded in *.tmp files, however, that is a normal extention, just to be clear. Anyway, just delete all of the files there, then run a virus scan again have it delete all the files it finds infected.
Now, restart, go into your normal user. goto Start >> run >> regedit
Now goto the directory:
HKEY_CURRENT_USER >> Software >> Microsoft >> Windows >> Current Version >> Explorer
In the right hand view: delete the file called "PINF" scan your computer once more, just to make sure ... and it wont hurt to restart.
It's a little bastard of a virus too. It doesn't really do anything, but it's operations slow your computer down. I think it changes some file sizes too. (So windows wont run them, because they are physically a different size then what their properties say)
Hope you can read this lol. and I hope it helps.
Might as well print it out or something.
I hope that's the virus it is, because that's what it said it was when I looked it up, and I've dealt with it numerous times. So I hope this helps, because I'm going to bed lol. (4 am).
                                    
             
        
            
            
                                     
                                
                    
                        Re: Crono: Crap damn crap.
                        Posted by 7dk2h4md720ih on 
    Sun Mar 21st 2004 at 12:03pm
                     
                    
                        
                        Posted 
    2004-03-21 12:03pm
                     
                 
                
            
            
                
    
            1976 posts
        198 snarkmarks
        Registered: 
    Oct 9th 2001
                     
                
                        Damn, bad timing so. It won't let me run regedit. I think I found the offending file that started it all. It doens't show up as a virus but it won't let me delete it because it says it's currently in use. How do I go about removing this? Thanks for the help bud.
Probably should say I cant ctrl-alt-delete either.
                                    
             
        
            
            
                                     
                                
                    
                        Re: Crono: Crap damn crap.
                        Posted by Crono on 
    Sun Mar 21st 2004 at 12:13pm
                     
                    
                        
                        Posted 
    2004-03-21 12:13pm
                     
                 
                
            
            
                
    
                    
                             Crono
                            Crono
            
                        super admin
     
            6628 posts
        700 snarkmarks
        Registered: 
    Dec 19th 2003
                            Location: Oregon, USA
             
                
                        log in as Administrator.
Then do all the stuff I said to do. the virus will be gone by that point and you'd be able to go into the registry ... I hope.
(I decided to check one more time before I went to bed lol)
                                    
             
        
            
            
                                
                    
                        Re: Crono: Crap damn crap.
                        Posted by scary_jeff on 
    Sun Mar 21st 2004 at 12:18pm
                     
                    
                        
                        Posted 
    2004-03-21 12:18pm
                     
                 
                
            
            
                
    
            1614 posts
        191 snarkmarks
        Registered: 
    Aug 22nd 2001
                     
                
                        hah, that's the stupid thing with windows that lets all these virii work - people are always logged in as administrator :smile:
                                    
             
        
            
            
                                     
                                
                    
                        Re: Crono: Crap damn crap.
                        Posted by 7dk2h4md720ih on 
    Sun Mar 21st 2004 at 12:46pm
                     
                    
                        
                        Posted 
    2004-03-21 12:46pm
                     
                 
                
            
            
                
    
            1976 posts
        198 snarkmarks
        Registered: 
    Oct 9th 2001
                     
                
                        I'm in administrator mode. How do I boot in safe mode? I can get into the bios, but I can't find how to boot in safe mode. I can't run msconfig to enable it that way.
                                    
             
        
            
            
                                     
                                
                    
                        Re: Crono: Crap damn crap.
                        Posted by 7dk2h4md720ih on 
    Sun Mar 21st 2004 at 12:51pm
                     
                    
                        
                        Posted 
    2004-03-21 12:51pm
                     
                 
                
            
            
                
    
            1976 posts
        198 snarkmarks
        Registered: 
    Oct 9th 2001
                     
                
                        Nevermind i'm in safe mode now. Anyone know how to delete a file that is "currently in use"?
                                    
             
        
            
            
                                     
                                
                    
                        Re: Crono: Crap damn crap.
                        Posted by 7dk2h4md720ih on 
    Sun Mar 21st 2004 at 12:52pm
                     
                    
                        
                        Posted 
    2004-03-21 12:52pm
                     
                 
                
            
            
                
    
            1976 posts
        198 snarkmarks
        Registered: 
    Oct 9th 2001
                     
                
                        There's no PINF file in that place in the registry Crono.
                                    
             
        
            
            
                                     
                                
                    
                        Re: Crono: Crap damn crap.
                        Posted by 7dk2h4md720ih on 
    Sun Mar 21st 2004 at 9:23pm
                     
                    
                 
                
            
            
                
    
            1976 posts
        198 snarkmarks
        Registered: 
    Oct 9th 2001
                     
                
                        Ok, thanks for all the help Crono, I got it sorted.
I booted in safe mode with network support. I was able to run my virus scanner which found nothing :rolleyes: I did all 3 online virus scans and they removed about 15 infected files altogether. I couldn't delete the original offending file because it was "currently in use by the system". I switched to dos and was able to delete it from there.
I never really thought about using a limited account for myself, nobody else has physical access to my pc. I'm using one now. Thanks again Crono and everyone. :smile:
                                    
             
        
            
            
                                     
                                
                    
                        Re: Crono: Crap damn crap.
                        Posted by Crono on 
    Sun Mar 21st 2004 at 9:44pm
                     
                    
                 
                
            
            
                
    
                    
                             Crono
                            Crono
            
                        super admin
     
            6628 posts
        700 snarkmarks
        Registered: 
    Dec 19th 2003
                            Location: Oregon, USA
             
                
                        Whoa, hang on there buckaroo, the user can have administrative rights. Just don't use Administrator as your user lol. I mean if it didn't admin rights you couldn't really install much of anything, such as most drivers. Anyway, I'm sure that's what you made ... even though you said limited lol. anyway, rockin' roll, go play some games lol.
                                    
             
        
            
            
                                     
                                
                    
                        Re: Crono: Crap damn crap.
                        Posted by 7dk2h4md720ih on 
    Mon Mar 22nd 2004 at 3:53pm
                     
                    
                 
                
            
            
                
    
            1976 posts
        198 snarkmarks
        Registered: 
    Oct 9th 2001
                     
                
                        Ok I don't think it's completly gone yet. If i try and switch users now it tells me that I do not have permission to do this. I'm on the root admin account though trying to access a  non pasworded account... argh.
Doing the online virus scans again.
                                    
             
        
            
            
                                     
                                
                    
                        Re: Crono: Crap damn crap.
                        Posted by Loco on 
    Mon Mar 22nd 2004 at 7:17pm
                     
                    
                 
                
            
            
                
    
                    
                             Loco
                            Loco
            
                        member
     
            615 posts
        121 snarkmarks
        Registered: 
    Aug 29th 2003
                    Occupation: Student
                            Location: UK
             
                
                        Solution: buy/borrow Norton, change the boot priority (if you can) to boot from a CD, insert the Norton CD, reboot, and off you go. Thats all I can think of for the time being!
                                    
             
        
            
            
                                     
                                
                    
                        Re: Crono: Crap damn crap.
                        Posted by Hornpipe2 on 
    Mon Mar 22nd 2004 at 10:36pm
                     
                    
                        
                        Posted 
    2004-03-22 10:36pm
                     
                 
                
            
            
                
    
            636 posts
        123 snarkmarks
        Registered: 
    Sep 7th 2003
                    Occupation: Programmer
                            Location: Conway, AR, USA
             
                
                        Yeah, you should never do normal computer work as the administrator.  Security and virus concerns aside, the reason I have a non-admin account on my Linux box is to prevent me from doing stupid things like deleting all the important system commands, or moving everything in my home directory to /bin.