Find a Partner
This window is encrypted for your security.
Need help? Ask the community or hire an expert.
Go to Avira Answers
Win32.Parite.a [KAV], W32/Pate.a [McAfee], Win32.Pinfi.A [CA], PE_PARITE.A [Trend], W32/Parite-A [Sophos], Win32/Parite.A [RAV], W32.Pinfi
Spreads over shared network resources.
W32/Parite spreads over shared network resources.
If a file infected with W32/Parite is opened, it registers: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer PINF
The worm hangs on Explorer.exe, to remain on resident memory, and it also hangs on all .EXE and .SCR files it finds on local and mapped drives.
The virus has a procedure that prolongs the infection, meaning that the virus infects only some files at a time.
W32/Partie creates a temp file in the existing directory. It reaches the directory in which it can use Windows API. The temp file created by the virus has always the following name:
[3 random letters][4 random hexadecimal digits].tmp
Description inserted by Crony Walker on Tuesday, June 15, 2004