Virus known as: Win32.Parite.a [KAV], W32/Pate.a [McAfee], Win32.Pinfi.A [CA], PE_PARITE.A [Trend], W32/Parite-A [Sophos], Win32/Parite.A [RAV]
Hello People,
my PC was infected by this virus too. I wrote several Programs that are able to get only the infected code from exe-files. Today i will write a virus scanner to get this virus away from my system cause Norman Antivirus ist f*****g bullsh*t.
I reinstalled my system and formatted my HD and i executed an old infected exefile from my backup... (i fool). And then the virus was there again. But i was able to get and analyse the infected code. It's very difficult to get infected files cause the infected code is encrypted with another Code by the virus. But if you are interested in a virus-scanner just send an email to daniel-platt@gmx.de and i will see if i get the scanner ready the next days for you all :) to help you. I hate virusses and this was the first time ever, my system was infected by a virus :-(
Important things how you can prevent a reinfection after reinstallation of windows:
- Format ALL Drives on your local harddisk
- Run fdisk and rewrite the Bootsector on your HD (only to prevent a reinfection if the bootsector on the harddisk is infected)
- if you install new software you have selfburned on CD-Rom first scan the Exefiles on the CD with your virus canner, cause they are maybe infected
- Before reinstallation of windows, you have to disconnect from the network to prevent reinfection
- Before you reconnect to the network first scan the PC's from the network about this virus and if they are infected you have to do the same procedure on each PC like described in the steps before
-> OR you have to disconnect each PC from the Network and than let the virus scanner first clean each PC and after it you are able to reconnect and not get infected again
VERY IMPORTANT: If you do this step and all files are repaired by the virus scanner REBOOT your System imadiately (don't wait), cause the virus causes a process (not visible in Task-Manager) that is linked to explorer.exe. If you wait after the virusscanner repaired infected files, any new files will be infected again. Shutdown of your system means to tighten the plug out of the power-Socket (sorry about my bad english.. I'm german)
I hope, this will help you. I'm working on virus scanner to remove this virus from my system. If you want that virus scanner just write to daniel-platt@gmx.de
With kind regards
Daniel Platt