Before I move to explain the features of this Trojan you need to know what exactly is a Trojan horse
and how it works. As most of us think a Trojan or a Trojan horse is not
a virus. In simple words a Trojan horse is a program that appears to
perform a desirable function but in fact performs undisclosed malicious
functions that allow unauthorized access to the host machine or create a
damage to the computer.
Now lets move to the working of our Trojan
The Trojan horse which I have made appears itself as an antivirus
program that scans the computer and removes the threats. But in reality
it does nothing but occupy the hard disk space on the root drive by just
filling it up with a huge junk file. The rate at which it fills up the
hard disk space it too high. As a result the the disk gets filled up to
100% with in minutes of running this Trojan. Once the disk space is
full, the Trojan reports that the scan is complete. The victim will not
be able to clean up the hard disk space using any cleanup program. This
is because the Trojan intelligently creates a huge file in the Windows\System32 folder with the .dll extension. Since the junk file has the .dll
extention it is often ignored by disk cleanup softwares. So for the
victim, there is now way to recover the hard disk space unless
reformatting his drive.
The algorithm of the Trojan is as follows1. Search for the root drive
2. Navigate to WindowsSystem32 on the root drive
3. Create the file named “spceshot.dll”
4. Start dumping the junk data onto the above file and keep increasing it’s size until the drive is full
5. Once the drive is full, stop the process.
You can download the Trojan source code HERE. Please note that I have not included the executabe for security reasons. You need to compile it to obtain the executable.
How to compile, test and remove the damage?
Testing:
To test the Trojan, just run the SpaceEater.exe
file on your computer. It’ll generate a warning message at the
beginning. Once you accept it, the Trojan runs and eats up hard disk
space.
NOTE: To remove the warning message you’ve to edit the source code and then re-compile it.
How to remove the Damage and free up the space?
To remove the damage and free up the space, just type the following in the “run” dialog box.
%systemroot%\system32
Now search for the file “spceshot.dll“. Just delete it and you’re done. No need to re-format the hard disk.
0 comments:
Post a Comment