Win32/Kryptik.VO
Win32/Kryptik.VO is detection for a Trojan that will self-replicate and spreads over a computer network. It targets Windows platform. Win32/Kryptik.VO is able to hide its presence on the infected PC by embedding its own code on legitimate system files. Additional malicious files will be downloaded from a remote computer. The Trojan will not allow any legitimate antivirus programs to interfere with its harmful activities so their process is disabled. Win32/Kryptik.VO has this re-spawning mechanism that able to bring back its own deleted files.
Damage Level: Medium
Systems Affected: Windows 9x, 2000, XP, Windows Vista
Characteristics
Once Win32/Kryptik.VO is executed, it will rename certain files under system folder of Windows. It allows automatic start-up by adding own value on Windows registry. The Trojan will search for running processes that are related to anti-virus or firewall application and ends immediately when found.
Additional effect of this Trojan is to communicate to a remote computer and perform other activities such as the following:
- Update the existing configuration file.
- Download more malware and execute on the compromised PC.
- Allow remote attacker to access the infected computer via backdoor port.
- Block access to legitimate security web sites and prevent updates on locally installed software.
Distribution
Although Trojans are spreading in a number of methods, Win32/Kryptik.VO will propagate in a selected process only. It will pose as installation file for popular programs like games, photo editing, or multimedia. These harmful files are using unsecured file-sharing server to reach computer users and employs a tricky file name to lure victims into file execution.
Symptoms
- Computer will experience a reduced in performance so as system crashes.
- Various pop-up advertisements will overflow on screen.
- The Trojan will redirect Internet traffic that will lead to additional virus infection.
- Security settings are set to minimum that gives Trojan free access to all files and folders.
How to Remove Win32/Kryptik.VO
Automatic Removal Procedure
1. Temporarily Disable System Restore (Windows Me/XP). [how to]
2. To identify even the most recent variant of Win32/Kryptik.VO, open your antivirus application and update the virus definitions.
3. Start Windows in Safe Mode with Networking.
- From a power-off state, turn on the computer and press F8 repeatedly.
- Your computer will display Windows Advanced Boot Options menu. Select Safe Mode with Networking.
- System will boot Windows loading only necessary drivers and system files.
4. Open your antivirus program and run a full system scan. After the scan, delete all infected items. If unable to delete, better place them in quarantine. Once the scan is complete please proceed with the next step.
Scan with Stinger
Stinger is a portable security tool that can detect and remove particular viruses. It utilizes a highly developed scan engine technology that includes process scanning and scan function optimization.
5. Go to Stinger and download Norton Power Eraser. Save it to your desktop.
6. Once the download completes, double click on the file to run the program.
7. The Stinger main program will open.
8. Default directory to scan is the system drive (C:\). You may add additional drives to scan by clicking on Add button.
9. Click on Scan Now button to begin scanning assigned drives.
10. Stinger will now scan and repair/delete all infected files.
11. When done, you may now close McAfee Stinger and restart Windows in normal mode.
Microsoft Windows operating systems has built-in tool to reinstate system files and programs to its original normal state. Restoring Windows (see how) to its previous settings will override all the changes that Win32/Kryptik.VO has caused to the system. However, this process is only useful if a restore point is created before the virus infection.
Mateo
Jul 09, 2009 @ 12:00:43
I also have this Trojan and I can`t remove it please help.
Mateo
Jul 09, 2009 @ 13:08:02
i remove it with Malwarebytes’ Anti-Malware
Korbicz
Jul 10, 2009 @ 08:32:31
I tried it with no successful result.
mico
Jul 10, 2009 @ 15:18:25
Hi. I have the same problem with Kriptik.vo. I will try to remove all off these Trojans.
Moonlee
Jul 11, 2009 @ 11:01:15
Same problem help ! Win32/Kryptik.VO Trojan also found by NOD32.
Johnny
Jul 13, 2009 @ 14:38:21
I have the same Trojan , the issue that I’m using cracked NOD and it’s not getting updating anymore! I hope you will notify us about solutions guys. Thanks
Galshan
Aug 03, 2009 @ 09:21:52
Go into task Manager, processes and find the process with the file name NOD cant delete, stop these processes (I had 2) and then go to the file location and delete it.
Good luck.
James
Jan 07, 2010 @ 23:45:57
I went to the processes, ended all four or five and deleted the files it said were infected but whenever i restart my computer or anything boom they’re back. NOD 32 can’t do a thing to them
gerry
Feb 02, 2010 @ 02:18:09
try here hxxp://users.telenet.be/marcvn/spyware/1970547.htm
regards
gerry
Feb 02, 2010 @ 02:20:41
Your log key should look like this
C:\HaxFix\process.exe Win32/PrcView application cleaned by deleting – quarantined
C:\HaxFix\reboot.exe Win32/Reboot.NAA application cleaned by deleting – quarantined
C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL Win32/Toolbar.AskSBar application cleaned by deleting – quarantined
C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL Win32/Toolbar.AskSBar application cleaned by deleting – quarantined
C:\Program Files\Live-Player\live-player.exe Win32/Adware.LivePlayer.AA application cleaned by deleting – quarantined
C:\WINDOWS\system32\1A9.tmp a variant of Win32/Kryptik.BXN Trojan cleaned by deleting – quarantined
hope this helps
raj
Mar 20, 2010 @ 07:10:11
hi, my laptop is not able to detect the pen drive which type of virus could be present in the pen drive it only shows pen drive access for 1 minute
gayle
Nov 23, 2010 @ 12:24:30
I quarantined the virus but now I am unable to open some of my applications when I double click on them.
* Microsoft Word “no application found”
* Volume “not found”
* Excel “open with”
* Internet Explorer “open with”
how do I fix this?