This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Parite.b And Rbot.ce - How To Remove

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi!

I have 2 Worms and I dont know how to remove them. First, there is Rbot.CE. I used Google to find removal tools -> nothing. Now I installed AntiVir and when it finds the Worm, I can delete it but a few seconds later its there again. Antivir says "Vsmon.exe is infected with Rbot.CE".

The second Worm is Parite.B. I used Kaspersky Antivirus to eliminate it. Every exe was infected with Parite.B. Kaspersky delete every exe so I had to reinstall Windows(XP Pro). But after reinstalling it with SP1 it was there again.

There is also a problem now, I cant search Internet Site with Ctrl+F, I cant copy links and some links don't open when I click on it.

So, my simple Question is, how can I remove them.
I read something about HiJack This! in this forum so I download it and I post the Log now, hope this can help. Thanks in advance!

Logfile of HijackThis v1.97.7
Scan saved at 17:43:00, on 10.08.2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Programme\Messenger\msmsgs.exe
C:\Programme\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\vsmon.exe
C:\WINDOWS\System32\msconfg.exe
C:\Programme\AVPersonal\AVWUPSRV.EXE
C:\Programme\AVPersonal\AVGUARD.EXE
C:\Programme\AVPersonal\AVGNT.EXE
C:\Programme\Internet Explorer\iexplore.exe
C:\Programme\Internet Explorer\iexplore.exe
C:\Programme\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\notepad.exe
C:\WUTemp\com_microsoft.840374_XPSP2_WinSE_92384\WindowsXP-KB840374-x86-DEU.EXE
c:\93303efffdb786072d8c1341\xpsp1hfm.exe
c:\93303efffdb786072d8c1341\sp2\update\update.exe
C:\Dokumente und Einstellungen\mk\Desktop\HijackThis.exe

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Microsoft Update] msconfg.exe
O4 - HKLM\..\Run: [AVGCtrl] "C:\Programme\AVPersonal\AVGNT.EXE" /min
O4 - HKLM\..\RunServices: [Microsoft Update] msconfg.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Recherchieren (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/…B?38209.3009375
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FD818781-154E-46D6-A6EA-DD0C38947726}: NameServer = 195.3.96.67 195.3.96.68

Something is german, so Ill translate it:
Programme = Programs
Dokumente und Einstellunge = Documents and Settings

/edit: I tried to open the settings of my Internet Connection and it says, there is an unexpected error.
Greetings and welcome to TomCoyote.com!

Please try these free online virus scans of your system:

Trend-Micro:
http://housecall.trendmicro.com/housecall/start_corp.asp

Panda:
http://www.pandasoftware.com/activescan/

Etrust:
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx

Choose fix or clean.

Let them remove any infections found. Reboot inbetween each scan.

Important: Create a folder on the C: drive called C:\HJT.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HJT.
Download the NEWEST version HijackThis into this folder.

If required a tutorial is here:

http://russelltexas.com/malware/createhjtfolder.htm

Links to Hijack This! v 1.98.2:

http://tools.radiosplace.com/HijackThis.exe
http://tools.radiosplace.com/hijackthis.zip
http://www.downloads.subratam.org/hijackthis.zip
http://tools.zerosrealm.com/hjt.zip
http://spywarewarrior.com/files/hijackthis.zip
http://spywarewarrior.com/files/HijackThis.exe

When complete, reboot and post a new log file. :)

Does your system say you are still infected now? :unsure:
Ok, I do this now. It finds a lot of Parite.B in the Folder "System Volume INformation\_restore" on every drive(c, d and e). But i cant find this folder in the Windows Explorer. What the hell is this? Why am I not able to see this folder?
That is your "system restore" information.

Do this:

Go here to read how to turn system restore on and off.

http://service1.symantec.com/SUPPORT/tsgen…src=sec_doc_nam

Now, turn your system restore OFF.

Run the virus scans as described before.

Reboot after the last one.

Turn system restore back ON, then reboot once more. :)
Hi! Sorry, my ISP had problems so I couldnt go online. I disabled it and now Ill start the Virus scans again. I did two scans yesterday and it founds a lot of worms in this "System Restore Information". Do I need this? I never did a System Restore, so do I have to enable it afterwards?
Yesterday I did two scans. They found about 1k Worms today nothing.
HiJack This! Log:

Logfile of HijackThis v1.98.2
Scan saved at 14:28:23, on 11.08.2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\AVPersonal\AVGNT.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Programme\AVPersonal\AVGUARD.EXE
C:\Programme\AVPersonal\AVWUPSRV.EXE
C:\HJT\HijackThis.exe

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Microsoft Update] msconfg.exe
O4 - HKLM\..\Run: [AVGCtrl] "C:\Programme\AVPersonal\AVGNT.EXE" /min
O4 - HKLM\..\RunServices: [Microsoft Update] msconfg.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall-Kontrolle) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab

The last three entries are from the online virus scans. Why are they there? I rebooted after each scan so why are they here?

What AntiVirus programm can you recommend?
After the scans you MUST turn system restore back on, and reboot

You will need that in the event of some major malfunction of your system.

Those last three items in the log are the active-x components loaded on your machine by the online virus scanning programs.

You still have one worm on your machine:

O4 - HKLM\..\Run: [Microsoft Update] msconfg.exe

As described here:

http://www3.ca.com/securityadvisor/virusin…s.aspx?id=39662

Please do this:

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Fix these items with Hijack This!:

O4 - HKLM\..\Run: [Microsoft Update] msconfg.exe

O4 - HKLM\..\RunServices: [Microsoft Update] msconfg.exe

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

Reboot in "safe" mode. Use the link in my signature to explain how if necessary.

Find and delete:

msconfg.exe

I think it will be in this folder:

C:\WINDOWS\System32

It may be "hidden". Use the link in my signature to explain how to show "hidden" files if necessary.

WARNING!!!

DO NOT GET THIS MALWARE FILE CONFUSED WITH "msconfig.exe"!!!!

msconfig.exe <— GOOD FILE, KEEP!!!

msconfg.exe <— BAD FILE, DELETE!!!

BE SURE TO NOTE THE DIFFERENCE!!!!

Reboot in normal mode and post a new log file.

I have always used Norton antivirus. I have never been infected with a virus, so I guess it does a good job.

I did get my browser hijacked one time, but Norton doesn't guard against such attacks. :)
Ok, i did it as you wrote it but there was no msconfg.exe. There was a ****msconfg.exe.pref (* = random letter) and it was at C:\Windows\Prefetch. I dont know exactly if it was a pref file, it was something with "p". I think it doesnt matter. Anyway, I deleted it, now there is nothing about msconfg in the HiJack This! log:
Logfile of HijackThis v1.98.2
Scan saved at 15:40:28, on 11.08.2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Programme\Messenger\msmsgs.exe
C:\Programme\AVPersonal\AVGUARD.EXE
C:\Programme\AVPersonal\AVWUPSRV.EXE
C:\HJT\HijackThis.exe

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [AVGCtrl] "C:\Programme\AVPersonal\AVGNT.EXE" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall-Kontrolle) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab

Isnt Norton slowing down the system?
Good work!!!

The log is clean now. :thumbup:

I have a Compaq Presario with a 1.5 gig processor and 512 MB of RAM.

I use Norton, and I don't think my system is slow. Your results may be different than mine.

If you do decide to switch antivirus software, be sure to uninstall your current antivirus software FIRST!

I'll leave you with my list of things to consider to help prevent futire infections.

GOD bless!!!

M68 :)

Items you may wish to consider to harden your defenses against future infections:

Read "How did I get infected in the first place?" here:

http://boards.cexx.org/viewtopic.php?t=957

Download IE-Spyad here:

https://netfiles.uiuc.edu/ehowes/www/resource.htm

IE-Spyad puts over 4000 known malicious web sites into IE's "restricted zone" to help prevent you from getting infected.

Check your browser settings here:

http://browsercheck.qualys.com/index.php

A series of "tests" (and suggested fixes) to help tweak IE's settings to help prevent infections when surfing the web.

Follow safe Internet practices:

1. Keep your virus definitions up to date, and scan your system regularly.

2. Don't open email, or download attachments from unrecognized email addresses.

3. Be careful when downloading email attachments, EVEN FROM PEOPLE YOU KNOW! Many virii, worms, and trojans infect a persons system then immeadiately spread themselves to the people in the infected persons addressbook via email attachments.

4. Be careful downloading files from the Internet. Scan all downloaded files with a reliable UP-TO-DATE antivirus program. Scan "zip" files BEFORE unzipping, and scan all unzipped files BEFORE USING THEM.

5. Keep your Windows and IE current with all the latest patches and updates.

Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI