W32.Crypto

Name W32.Crypto
Type
Affected
Risk Level 1: Very Low
Discovered December 30, 1999
Update February 13, 2007 11:33:11 AM
Length
Info W32.Crypto is not known to be in the wild yet. The payload for this is similar to the One_Half . This means the Crypto will encrypt the data on your hard drive, and if you remove the , the data will be inaccessible – and effectively held hostage. Crypto uses strong cryptographic algorithms to encrypt the data on the hard disk, making recovery unlikely without a backup.

W32.Crypto uses the Microsoft Crypto API to encrypt accessed DLLs on the system with an encryption key that is added by the to the infected system, and installed in the registry as:

SOFTWARE\Microsoft\Cryptography\UserKeys\Prizzy/29A.

The first infects the operating system file KERNEL32.DLL. Once infected, KERNEL32.DLL controls all access to DLLs on the system and the encrypts all such accessed DLL files. While the is active in memory, it will automatically decrypt encrypted DLL files so they can be used. However, if the is not active in memory, the DLLs will not be decrypted and the system will fail to work. Unless the is active and running, all DLL files that have been encrypted will be inaccessible. This means that an infected system can only be cleaned by restoring all affected DLL files from backup copies, and deleting all infected executable files. Data files are not encrypted by this release of the .

Threat Assessment

Wild

  • Wild Level: Low
  • Number of Infections: 0 – 49
  • Number of Sites: 0 – 2
  • Geographical Distribution: Low
  • Threat Containment: Easy
  • Removal: Easy

Damage

  • Damage Level: Low

Distribution

  • Distribution Level: Low
Writeup By: Peter Szor
Details >W32.Crypto
convert this post to pdf. Tags: ,

Related Virus

"Free Scan W32.Crypto

Print This Virus article Print This Virus article

Maryland Term Life Insurance
satellite tv on pc software

Leave a Comment

You must be logged in to post a comment.