Win32/Parite [Threat Name] go to Threat

Win32/Parite [Threat Variant Name]

Category virus
Detection created Dec 11, 2002
Detection database version 1335
Short description

Win32/Parite is a polymorphic file infector.

Installation

When executed the virus drops in folder %temp% the following file:

  • %variable%.tmp

A string with variable content is used instead of %variable% .


The virus loads and injects the %variable%.tmp library into the following processes:

  • explorer.exe

The following Registry entries are created:

  • [KEY_CURRENT_USER\­Software\­Microsoft\­Windows\­CurrentVersion\­Explorer]
    • "PINF" = %binvalue%
Executable file infection

Win32/Parite is a polymorphic file infector.


The virus searches local and network drives for files with one of the following extensions:

  • .exe
  • .scr

Files are infected by adding a new section that contains the virus .


The host file is modified in a way that causes the virus to be executed prior to running the original code.


The size of the inserted code is variable.

Please enable Javascript to ensure correct displaying of this content and refresh this page.