Virus Name  : W32/Kriz

Alias             : Win32.Kriz, PE_KRIZ

Virus type    : PE File Infector

Threat level : Medium

Virus details :

                      W32/Kriz is a Windows file virus infects PE files under Win9x and WinNT 4.0 platforms. This virus will wake up or get activated on 25th of December [Christmas day] and it will damage the motherboard and the hard disk. The damage caused could be extreme and expensive.

                     When the virus is first run, it patches the critical operating system file KERNEL32.DLL and stores it in the name of KRIZED.TT6. On the next startup it replaces original KERNEL32.DLL file with KRIZED.TT6. The variants of Kriz will use different name to patch KERNEL32.DLL. Then it become memory resident and infects all accessed Windows Portable Executable files.


                     The payload of W32/Kriz is stolen from deadly W95/CIH virus. The computer motherboards manufactured in the last few years store their BIOS on a flash ROM chip which are rewritable. W32/Kriz virus directly attacks the code stored in the flash ROM chip and makes the computer unbootable.

                     In certain motherboard the BIOS chip are replaceable and solution is possible by inserting a new chip. However in most of the cases the BIOS chip is soldered to the motherboard and there is no solution except to replace the motherboard which could be expensive. If the Flash BIOS is write-protected by jumper set then the Kriz virus will delete all the data stored on hard disk, which puts every computer at risk irrespective of the BIOS layout.

                     At present there are 5 known versions of Kriz variants reported which destroys the motherboard and hard disk. W32/Kriz.4271 is most frequently reported in the wild. Solo cleans W32/Kriz and its variants without problems.

How can I protect my system?

                   Solo has incorporated Win32/Kriz in its signature file to protect users from this virus attack. Solo antivirus registered users are already protected from this virus. Make sure that you have installed registered version of Solo Antivirus to protect your system from all virus threats.

How to remove this virus?

                   If you are already infected with this virus, you can remove it from your computer using Solo Antivirus software. Solo antivirus can detect and remove Win32/Kriz safely. Use the following link to Download 30 day trial version of Solo antivirus to remove viruses from your computer.

                   Solo anti-virus not only scans for all viruses, it contains a unique System Integrity Checker to protect you from New Internet Worms, Backdoors and malicious VB, Java Scripts. It also effectively removes all existing Internet Worms, File viruses, malicious VB, Java scripts, Trojans, Backdoors, boot sector, partition table and macro viruses.

