我与同学都中过此毒,同学用2005正版瑞星能够杀此毒,但好像效果不是很如意,有一些文件被删除,但大部分文件被修复。总体上讲杀毒反倒没有重装快。我是格系统,删其它盘的EXE重装的。瑞星无法正确清除该毒的scrrun.dll。
我对比过中毒与未中毒的文件,该毒修改EXE文件头的长度信息,并在程序入口插入转向代码,跳到文件尾先执行完感染主体再回跳执行宿主程序。我试着修改回来,但没有成功。(水平太次,`.`)
在网上找到的有关这个病毒的中文描述千篇一律,以下这篇文章是E版的,叙述得比较好。
转载出处:
http://www.bitdefender.com/bd/si ... _id=1&v_id=137#
Win32.Parite.A/B/C ( Win32/Parite )
--------------------------------------------------------------------------------
Virus Encyclopedia
Spreading: MEDIUM Discovered : 2002 Jan 06
Damage: LOW
Size: ~180K
FREE REMOVAL TOOL : Download
SYMPTOMS:
Sensible decrease in hard-drive free space;
A file about 180K, executable in temporary folder written in Borland C++;
Most exe files have over 200K in size.
TECHNICAL DESCRIPTION:
The virus is a file infector that is composed of two parts: a small stub written in Assembler, appended to the files infected that decrypts the main virus body, also appended to the infected file. The main virus body is a PE file written in Borland C++ that it’s dropped in the Windows\TEMP directory (or whatever location temporary files have on your system).
The virus infects PE files, and searches for files with *.exe and *.scr extensions, on local drives, network drives and network shares on local network. Because the virus appends to every infected file the main body, which is ~180K in size, there should be a visible decrease in free space on your volumes. The virus doesn’t show it’s presence in any way, and does not use email for spreading.
Versions A and B are mostly the same, while version C uses a somewhat tricky method of encrypting the original PE file’s entry point. Infected files have the last section’s name consisting of 3 randomly chosed letters followed by a non-printable character.
If in your exe files the last section name is .jbd or .xgt or something like that, then it’s probably a file infected with Parite.
The virus does not damage the file it infects.
REMOVAL INSTRUCTIONS:
BitDefender can disinfect or delete automatically the files infected by this particular virus. The modified registry entries should be corrected manually.
If you don't have BitDefender installed click here to download an evaluation version;
Make sure that you have the latest updates using BitDefender Live!;
Perform a full scan of your system (selecting, from the Action tab, the option Prompt user for action). Choose to disinfect all the files infected with Parite.
ANALIZED BY:
Daniel Ionita
BitDefender Virus Researcher.