This malware infects EXPLORER.EXE to gain memory-residency. Once resident, it gradually infects all .EXE and .SCR files found on the infected system and network shares with read and write access.
It infects files by adding a new section to the target file then appending its code at the end of the target.
Note that Trend Micro detects files infected by this virus as PE_PARITE.A.
It is dropped and executed by PE_PARITE.A in the Windows Temporary folder, with a random file name and a TMP extension.
This malware runs on Windows 95, 98, ME, NT, 2000 and XP.