Wipeout! New Trojan (Trojan.KillFiles.904) Can Obliterate Your Computer

by Lee on June 9, 2009

in Malware

The Russian anti-virus vendor Doctor Web has issued a warning about a new Trojan that can, potentially, delete every single file and folder on a compromised computer.

(If you don’t already know what a Trojan is, then check out this post : What Exactly Is A Trojan?)

trojan-kill-files-9041

The new Trojan has an appropriate name – Trojan.KillFiles.904 and has been confirmed in the wild since the beginning of this month.

If you are unfortunate enough to be infected with Trojan.KillFiles.904 then all of your files and data are at serious risk.

The Trojan will search all drives on your system, both internal and external, and including small devices such as USB sticks and flash memory cards.

Trojan.KillFiles.904 will search for drives in reverse logical order, i.e. it will look for drive Z: first and A: last.

Whenever it finds a drive it will attempt to remove all files and folders contained on it, whether they are visible or hidden.

Talking of hidden files, if the Trojan cannot delete a file for some reason, such as the fact that it may be currently in use, then it will assign the ‘hidden’ attribute to it, making it inconvenient at best for a user to then find it.

The only files and folders that the Trojan will leave untouched are Windows system files whiich mean that you could actually continue to use your computer as normally whilst being blissfully unaware of what was happening in the background.

The KillFiles.904 Trojan is therefore quite unique because it doesn’t attempt to steal personal data or lead to any kind of extortion from the programmer.

Instead it is designed with the singular purpose of destroying any system it finds its way onto.

Nasty!

As ever, having a good anti-virus program installed is a great way of avoiding such a devastating attack but I would also urge anyone who has large amounts of important information on their computer to back it up on a regular basis, just in case.

Related Posts

  • Trojan KillRDDL.A – The Hash N Slash Horror
  • Guy Kawasaki Has Twitter Account Hacked. Spreads Malware Link. Mac OS Users Beware.
  • What Exactly Does A Trojan Horse Do?
  • Could The Antivirus Industry Be Writing The Viruses That Cause Us To Buy Their Products?
  • Money For Nothing And Your DDoS For Free
  • In The World Of Online Crime, The Drive By Method Is Most Effective
  • Admin, Server, Dos, Log, Steal And Kill – The 6 Types Of Trojans
  • I’m Scared Of Getting A Virus – What Sort Of Sites Should I Be Wary Of?
  • Trojan Horses
  • What Exactly Is A Trojan?
  • { 3 trackbacks }

    What Exactly Does A Trojan Horse Do?
    March 14, 2010 at 11:12 pm
    Could The Antivirus Industry Be Writing The Viruses That Cause Us To Buy Their Products?
    March 14, 2010 at 11:47 pm
    Trojan KillRDDL.A – The Hash N Slash Horror
    March 14, 2010 at 11:51 pm

    { 6 comments… read them below or add one }

    1 Anon July 11, 2009 at 7:00 pm

    Though it probably sounds like idle speculation and paranoia, a very reasonable and viable explanation for the amount of time and effort placed into such seemingly pointless creations is that it is for the benefit of the anti-virus industry. The more dangerous the virus the more paranoia it can instill, encouraging profit and thus active development within the AV industry. One could go so far as to suspect that a larger portion of new viruses come from anti-virus companies themselves than from tech-savvy teens with nothing to gain. Aside from that, there have been many cases in the past of proficient and notorious virus writers being hired by large software firms, including some specializing in digital security no doubt. Paranoia perhaps, but paranoia based in logic.

    Reply

    2 Guy N. Cognito July 10, 2009 at 11:09 pm

    What about encrypted files such as with true crypt?

    Reply

    3 anonymoose June 10, 2009 at 5:49 am

    WTF would people create this shit for? Fucking idiot trolls.

    Reply

    4 Lee June 10, 2009 at 12:24 pm

    Who knows what motivates someone to create such a Trojan – boredom, misspent youth perhaps?

    Reply

    5 Tyler July 11, 2009 at 4:31 am

    Yeah, it should delete those as well. This trojan isn’t out to farm data (in which case, your encrypted files should not be able to be accessed), just destroy files. Encryption won’t keep files from being erased.

    Reply

    6 anon July 11, 2009 at 5:59 am

    Well the files are encrypted, but not necessarily read/write protected.
    Thats a good question, but my assumption is that it would be gone like the rest of your files

    Reply

    Leave a Comment

    Previous post:

    Next post: