Misguided Trojan Deletes Porn, Warez, and Music in Attempt to Defeat Malware
CYBERSPACE — File this one under “possibly well-intended but fucked up.”A Trojan with a misplaced sense of ethics is on the loose and trying its best to protect infected PCs from the evils of malware picked up while browsing peer-to-peer networks – but its efforts may be causing nearly as much trouble as it’s trying to prevent.
The Windows Trojan/Erazer-A Trojan peeks into default folders while an infected computer downloads AVI, Gif, MPEG, MP3, WMV, and Zip graphic and video files – and then deletes anything it comes across with those extensions.
Virus experts believe that for whatever reason, the Trojan is trying to protect the files it’s simultaneously infecting, since it only removes those in the targeted download directories. In order to do this, the program does its best to perform an end-run around installed security measures, meaning that it puts users at an increased overall risk of infection or instability. Adding insult to injury, the pest also appears to walk away with information.
Sophos, which was first to spot the bipolar virus, has labeled it a “vigilante” Trojan, an uncommon form of malware that isn’t entirely bad; just misguided.
According to Graham Cluley of Sophos, “The Erazer Trojan is a vigilante worthy of a Charles Bronson movie, taking the law into its own hands. However, it’s perfectly possible for the Trojan to aim poorly and wipe out innocent files, too.”
Cluley isn’t convinced that the beneficial side of the Trojan is intentional, given that it does its level best to shut down protective security. Other than giving users a false sense of safety, there’s always the chance that the next version won’t be anywhere near as benign.
For more about the Windows Trojan/Erazer-A Trojan, visit http://www.sophos.com/virusinfo/analyses/trojerazera.html