The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    Win32:Parite- Files getting infected out of nowhere?!?!

    Discussion in 'Security and Anti-Virus Software' started by Dark Heart, Jun 11, 2008.

  1. Dark Heart

    Dark Heart Notebook Consultant

    Reputations:
    0
    Messages:
    100
    Likes Received:
    0
    Trophy Points:
    30
    Ok, this all started when I tried to make a self-extracting archive with PeaZip. Avast! almost immediately deemed the file infected and when I tried to repair it, Avast! blocked it to such an extent, that WIndows Explorer would freeze when I right-clicked it.

    So I deleted the file from Safe-Mode, thats good, I kept going...made a .zip file instead. I recently formatted and reinstalled windows to fix a bunch of issues with my sound card drivers, which went successfully.

    I later found a CD with "Worms World Party". Good ol' game. Loved playing it when i was little. After a reboot, Avast! again started deeming that the "landgen.exe" (a critical file for the game) was infected and the same quarrel with Avast! occurred. What i am worried about is that the file size of the .exe file is twice the size of the file before the reboot. Meaning it did get infected.

    But how? I have even less software now than I did before the reinstall, and the virus does not seem to spread, even after I executed the file in safe-mode. Parite was supposed to begin eating away every .exe file, because it was there, but it didn't, it just stood stationary in that one file and signs of infection were obvious, even without an A.V.

    How could a virus just appear out of nowhere on a system, that has no other traces of it, even "Windows malicious software removal tool" detected only that file as infected.
     
  2. Baserk

    Baserk Notebook user

    Reputations:
    2,503
    Messages:
    1,794
    Likes Received:
    1
    Trophy Points:
    56
    Did a scan of the CD come up clean?
    As you wrote the size of the 'landgen.exe' file grew, certainly indicating Win32 :parite typical activity.
    Does a scan with an online scanner like Eset's also give a positive on landgen.exe on the CD?
     
  3. Dark Heart

    Dark Heart Notebook Consultant

    Reputations:
    0
    Messages:
    100
    Likes Received:
    0
    Trophy Points:
    30
    Ok, Baserk, The CD was scanned and is clean, but I cannot do anymore scans on the laptop until I delete landgen.exe, because every scanner, even Avast!'s stops at that file and refuses to move onward, so I have to get rid of the file in Safe Mode...

    I will do full scans on my system with Windows Malicious Software Removal tool (MRT.exe), HouseCall and Eset, and will come back with the results.
     
  4. Dark Heart

    Dark Heart Notebook Consultant

    Reputations:
    0
    Messages:
    100
    Likes Received:
    0
    Trophy Points:
    30
    Without any scans I have pinpointed the source of the infection...On my own network I have a desktop PC that has a severe parite infection. It's so severe that neither Avast, nor Bitdefender could clean it properly and the ONLY, ONLY way is to format the two hard disks on that PC.

    Unfortunately, since we are all busy, until probably July, my family and I have not had the time to pick out individual files to backup. (We have to, otherwise what's the point of reformatting, if the backups contain the virus too)

    Anyways, back on topic, the folder on my PC, with Network Discovery and file sharing on, that has WWP is fully shared, with full control for all users. Unfortunately, due to my low attention span, I assumed that the virus cannot travel through the wireless network without an infected file being moved to the infected computer.

    I tested this and was 100% correct. I removed my USB network adapter and Avast! did not detect the re-installed WWP as infected, nor did any file sizes grow/change. When I plugged the adapter back in (stupid, incompetent Vista does not allow me to turn off Network Discovery and File sharing without being connected to a network first) the .exe files became infected immediately.

    So (wipes forehead and 'phews') WWP is not the problem. I have solved the problem by simply turning off Network Discovery and file sharing and now, when we have time, I, and my family will backup all files (except .exe's and .scr's, since they are the two target files of Parite) and reformat the two hard disks on that desktop PC, before the virus screws itself up too.

    Anyways thanks for the help, but it's up to me now!