Trojan simulates hard drive failure

mzkhadir

Diamond Member
Mar 6, 2003
9,509
1
76
http://www.symantec.com/connect/fr/...e-rogue-defragger-sales?API1=100&API2=4176444

Have you ever had a hard drive failure? I have. It happen to me in my first ever computer job. I was about six months in, working on a small part of a big project, and we had a milestone in two days when it happened. I can remember the pit in my stomach as I checked our version control software for anything I had submitted. I searched files on drives D through Z, hoping that I may have copied files over. I checked floppy disk after floppy disk for the code I brought home that one weekend. I was petrified. I would have paid a week’s wages to recover those files.

Hard disk failures are a fact of life in the tech world. It’s something many of us have experienced, and not with fond memories. Trojan.FakeAV writers are aware of this, and the end of last year saw a move by some into the creation of fake hard disk scanners and defragmentation tools, which we covered in Fake Disk Cleanup Utilities: The Ruse. In this blog we are going to look at Trojan.Fakefrag. What sets this apart from standard fake disk cleanup utilities is that the Trojan makes changes on the computer and displays messages that make it appear as though the hard disk is failing. Then it drops a member of the UltraDefragger family called Windows Recovery, which offers to repair these disk errors for a mere $79.50!

We’ve put together a short screencast that takes you through the experience.

Trojan.Fakefrag is essentially a wrapper around UltraDefragger. Its aim is to increases the likelihood of you purchasing a copy of UltraDefragger by craftily convincing you that your hard drive is failing. It attempts to do this by doing the following:

It fakes hardware failure messages, such as this:

It moves all the files in the "All Users" folder to a temporary location and hides files in the "Current User" folder. This makes it look like you have lost all the files on your desktop.
It stops you from changing your background image.
It disables the Task Manager.
It sets both the “HideIcons” and “Superhidden” registry entries to give the impression that more icons have been deleted.
It does a really convincing job of making it appear as though something is wrong—the failure messages look just like something Windows would display. Plus, when it “deletes” files from your desktop, it does so in a very prominent way. (Given this is where I personally keep my really important stuff, seeing it suddenly disappear would certainly give me pause.)

It then "helpfully" displays a message recommending that you run a diagnostic utility on your computer, launches the Windows Recovery misleading application, and adds a link it on both your desktop and the start menu. The misleading application finishes the job, hoping that the victim will pull out their credit card for the $79.50 price tag.



I can’t remember how much I made a week in my first job, but $79.50 sounds like a bargain to recover your files. I still recall confiding in a senior developer, who directed me to the IT Administrator, who popped in a new hard drive, and then restored everything from back up while I calmed myself down. Fortunately with Trojan.Fakefrag all the files are still on your hard drive. A quick search will find anything you need—after you run an up-to-date antivirus scan to delete the Trojan of course.

Thanks to Ben Nahorney and Sean Kieran.
 
Last edited:

Chiefcrowe

Diamond Member
Sep 15, 2008
5,052
195
116
I know someone who had this. REALLY annoying. eventually the easiest thing to do was to reformat... ugh!
 

SetecAstronomy

Junior Member
Oct 8, 2007
13
0
0
I have had the displeasure of dealing with this malware many times at work. I would say almost half the infected computers that are coming in have this on them. It's removal is not that difficult of a task and un hiding all the files it hides is as easy as running "attrib -h /s /d" at the root of C in a cmd prompt. What makes this thing such a royal pain is that it actually deletes all your start menu shortcuts as opposed to hiding them. In the first variants i saw the shortcuts were just hidden and would reappear in the menu after unhiding all the files. In the more recent versions you have to manually recreate the start menu shortcuts and it's a nightmare. It will at least leave the folders the shortcuts go in however.
 

Modelworks

Lifer
Feb 22, 2007
16,240
7
76
The best malware never reveals itself as being on the system. Ones like this that do things like deleting files ,immediately set off red flags that something is wrong and I wouldn't think it was hardware failure, but I guess the average consumer might assume that.
 

cheez

Golden Member
Nov 19, 2010
1,722
69
91
I had exact same problem with one my clients PC's the OP has posted here. I ran hard drive diagnostics and it was healthy and strong as ox. It turned out to be trojan virus like the thread pointed out. Our anti-virus program could not detect it. I did C:\wipe_ass (aka format).


p.s. you can retrieve those files by pulling up hidden folders in windows folder options.

Good thread.:thumbsup:
 
Last edited: