PDA

View Full Version : Vigilante Trojan wipes out P2P directories


paularoid
05-16-2006, 03:29 PM
http://www.cdfreaks.com/news/13429

Vigilante Trojan wipes out P2P directories
Posted by Dan Bell on 16 May 2006 - 18:50 - Source: PC World

Here we have an interesting Trojan discovered recently by Sophos, that is spread over chat programs and P2P. In addition to shutting down your anti-virus, it searches typical directories looking for MP3, AVI, MPEG, WMV, Gif, Zip graphic and video files and wipes out anything it finds with these extensions. Yes, even your precious porn collection is at risk!

What is a bit odd is, some are saying this malware, in deleting such files, is actually "protecting" the end user. However, how in the world this Trojan can determine legal files from illegal makes this theory quite shakey at best, because it cannot of course, do that. If it could, the RIAA would jump on it like a pot of gold records. Many people rip their CD collections to disc to play over networks etc., so this would be a very disruptive virus to some.

The Erazer Trojan is a vigilante worthy of a Charles Bronson movie, taking the law into its own hands. However, it's perfectly possible for the Trojan to aim poorly and wipe out innocent files too," commented Graham Cluley of Sophos.

Vigilante it might be, but the Trojan spreads in the same way as those pieces of malware it appears to be targeting -- via P2P file sharing. It can also, of course, be used for malicious purposes, so this is a beneficial program most users would probably not want help from.

"I don't think this was written with good intentions because it attempts to turn off security," said Cluley. There would be nothing more dangerous than for people to become accustomed to the idea of "beneficial malware" because that might create a false sense of security.

You can check out the story in it's entirety at the source, by visiting this link to PC World. http://www.pcworld.idg.com.au/index.php/id;1036928739;fp;2;fpid;1

You may also wish to visit the Sophos site, for the birds eye lowdown on this nasty. http://www.sophos.com/virusinfo/analyses/trojerazera.html
.

Des
05-16-2006, 04:21 PM
What I want to know is...when are they going to create a virus program that stops viruses from shutting down your virus protection?

It seems pointless paying for virus protection when after you get a virus, you can't run the scan. I had to restore my hard drive to a previous date when this happened to me.

I have a conspiracy theory. I think the makers of Norton, MacAfee et al, employ virus creators to deploy viruses to all computers. Just so they get sales from virus protection programs.:D

DaveM
05-20-2006, 12:17 AM
I've wondered about that myself, Des.