Member Panel


Sponsors and Ads

Join the Team

Live Tag Cloud

PC Forum PC Help Forum » Tutorials » Security Tutorials » Malware/spyware/virus/trojan etc. what are they?

Security Tutorials - Malware/spyware/virus/trojan etc. what are they? posted in the Tutorials forums; Adware Adware are programs which will, after installation, display advertisements. These come in two types, the first being used in shareware programs to 'pay' for development, the advertisements are integrated ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 11-11-2005
btalman's Avatar
Elite Member
 
Join Date: Nov 2005
Posts: 504
btalman - See this Members User comments on their Profile page
Default Malware/spyware/virus/trojan etc. what are they?

Adware
Adware are programs which will, after installation, display advertisements. These come in two types, the first being used in shareware programs to 'pay' for development, the advertisements are integrated into the program. Here adware means advertised supported software. The second category is the one which causes trouble, this adware, provided by companies like gator, but also included in messenger plus! (don't check the box next to install with sponsors), give you advertisements at random times when online. You don't see the software is there, and when getting those ads, it can be hard to tell with which program the adware came. The last category can also be recognized by a ridicilous ammount of advertisements and pop-ups.

Backdoors
A backdoor is a piece of software to bypass login procedures, thus giving the person who spread the backdoor, full access to your system. Having a backdoor exposes your computer to the internet in a seriously threatning way.
How does a backdoor work? Basically it opens your computer to anyone who knows your computer is infected. This usually happens by exploiting bugs in the operating system or just by installing and running itself. There are two types of backdoors:
  • Backdoor/trojan, the backdoor is part of a program, or a file is infected. Once you launch the file, the backdoor is installed. The program only runs when the infected file/program is run and spreads itself using the infected computer like a trojan does
  • Backdoor/worm, the backdoor is launched while booting and thus runs continually when the computer is turned on. Some of these backdoors login to an irc room so your computer, and thousands of infected others, can be used for different purposes like DDoS-Attacks (Distributed Denial of Service)
You can quite easily prevent backdoors with a good firewall and virusscanner

Browser Helper Objects (BHO's)
A Browser Helper Object (BHO) is a DLL module that loads everytime you start your browser. Usually, a BHO is installed on your system by another software program or installed when visiting a website. An example of a BHO installed by software is the Adobe PDF plugin so you can read pdf documents without manually starting Acrobat Reader, when surfing the web. An BHO installed by a website is the google toolbar.
BHO's can do "anything" but most of the time they provide some sort of extra functionality to the user like a toolbar. These BHO's require your permission to be installed on the system. Some BHO's get installed secretly or are shipped with a program as a 'third party application' such as the BHO's supplied with Messenger Plus. This last category, the 'hidden' BHO's are a safety threat. Most of the time they'l annoy you by creating dozens of popups or redirecting your site searches. But they can do virtually anything like reading or writeing on your system, sending data about you and your surfing habits etc.
Most BHO's require user approval before being installed even those semi-hidden BHO's, described as third party programs. Ever wondered where information about those third party programs is 'hidden'? It isn't that hard to find, before installing a, usually 'free', program take a good look at the license agreement. If it's too big, select all text (control-a) copy it (control-c) and paste it (control-v) in a word document. Then search (control-f) for terms like 'third (3rd)' or 'third (3rd) party'. See? The info is there but it's hidden in a lot of judicial terms.


Browser Hijacker
When starting your browser you notice a different homepage, not the one you set it be or, when you misspell a web address you get a search engine loaded with sponsored links or ads, finally, when you enter a web address you're sure of, is right, you end up at an advertising page. These are all signs of a Browser Hijacker.


Dialer

A dialer is a piece of software which changes your default internet connection to an expensive phonenumber even when you have a broandband connection you can be struck by the effects of a dialer.
You get a dialer by downloading/installing it, the same way you get adware and spyware, though viruses can also contain dialers or install them. Most of the time you get dialers after visiting a site with specific content only available to you when you call a special number with your computer, after you dial the number and break the connection the dialer sets itself as the default connection. This way you can browse the net but, unknowingly, pay great ammounts of money to do so. You don't notice anything wrong, untill the next phonebill arrives.


Keyloggers

Keylogging is the capturing of everything entered using the keyboard and storing this information. Viruses, Trojans and Worms can contain keyloggers and thus log everything you type, and send it to the creator of the malware. Not a real problem when you only use our computer for editing and printing word documents.
Think again, a keylogger wil save EVERYTHING you enter using the keyboard, including passwords, the, sensitive, information in the document and much more. Much more, well, everything, imagine having your creditcard info out in the open. Luckily most modern virusscanners can detect keyloggers even unknown keyloggers, since most of them use certain code which most keyloggers contain. Nevertheless the risk, how minimal it may be, is still a risk.


Malware
Malware/Malicious Software, is all software designed to damage, take-over or do things to your computer without you knowing it. So when someone speaks about malware or malicious software he/she can be talking about:
  • Adware
  • Backdoors
  • BHO's
  • Browser Hijackers
  • Dialers
  • Keyloggers
  • Spyware
  • Trojan Horses
  • Viruses
  • Wabbits
  • Worms
  • Etc.
Spyware
Spyware consists of a program or programs to collect data about your surfing behaviour and report it to advertisers so they can target you with spam, customize their ads when you browse the web etc. Programs confirmed containing spyware :
  • Bearshare
  • Bonzi Buddy
  • Dope Wars
  • Download Accelerator Pro (DAP)
  • Errorguard
  • Flashget (free)
  • Grokster
  • Kazaa
  • Radlight
  • Weatherbug
  • Wildtangent (they mostly produce winamp and WMP plugins/games)
Trojan Horse
Remember the story about the ancient Greeks and Troy? Instead of the wooden horse and a bunch of soldiers a computerized trojan horse replaces the horse by a program and the pack of soldiers by malware. A Trojan horse can contain everything, ranging from a 'simple' executable file which erases your harddrives to sophisticated viruses entering you into a bot network. So a Trojan horse is nothing more, or less, then disguised malware.
Most Torjan horses serve these purposes:
  1. The Remote Control Trojan, which gives the creator of the trojan control over the entire computer of the victim or certain parts ie. a backdoor
  2. The Password Trojan, which remembers/logs every password you enter and sends it to the creator of the trojan
  3. The keylogger, which doesn't only save your passwords, like above, but anything you enter using the keyboard
  4. The FTP Trojan. This variety creates an ftp server giving the creator of the trojan no direct control over your computer, but allows him/her to browse through all your files, modify, delete or downlaod files or even to add more files
  5. The DDoS/bot trojan which turns your computer into a zombie used for sending spam, or atacking/infecting other computers
Since Trojan horses use specific ports to communicate, a good firewall will prevent trojans 'calling home'/communicating


Viruses

The term virus is usually applied to all forms of malware even spyware and adware, though a virus, usually, isn't. A virus is a piece of code which replicates itself, unlike a trojan horse for example, by infecting files on your computer or by creating infected files. Viruses can do a lot of things to your computer, ranging from annoying, infecting all your files, to destructive, deleting your data.
Viruses can reside anywhere on your computer, including
  • Macro's
  • Scripts
  • Executables (com, exe, bat, pif etc.)
  • Boot sectors of disks, like floppy's
  • The master boot sector of your harddrive
Wabbits
A Wabbit is very uncommon to encounter, one of the reasons is they don't spread to other computers by itself. Once a wabbit is executed it start to replicate itself real quick, hence the name, creating lots and lots of files on your computer causing your harddrive to be filled up and system unstability.
Some wabbits are a little more advanced and start copies of the newly created files, thus creating more wabbits in an exponential way,t aking up more harddrive space, pushing your CPU and memory and, finally, crashing or freezing your computer. Wabbits are annoying but not that harmfull, unless more malicious code is added but then a wabbit isn't a wabbit, but it turns into a virus.


Worms

A worm is the same as a virus but with these differences:
  • It doesn't need a host to attach to, it's stand-alone
  • It spreads using network connections (a virus only infects local files)
  • It can contain other malicious code such as a Trojan Horse or backdoor
Copyright Surfing Safe


__________________
  #2  
Old 11-11-2005
Zimbo's Avatar
Friend of PCHF
 
Join Date: Sep 2004
Location: Right here !
Posts: 2,150
Zimbo - See this Members User comments on their Profile page
Default

:read2:
Lovely, absolutely lovely....

Thanks again btalman.


  #3  
Old 11-11-2005
btalman's Avatar
Elite Member
 
Join Date: Nov 2005
Posts: 504
btalman - See this Members User comments on their Profile page
Default

*blushing, thanks. As soon as I finish more of these tutorials/infosheets I'll post them


__________________
  #4  
Old 11-12-2005
Spaceman3750's Avatar
Elite Member
My PC
 
Join Date: Jan 2004
Location: Riverton, IL, USA
Posts: 1,511
PC Experience: Very Experienced
Spaceman3750 - See this Members User comments on their Profile page
Send a message via AIM to Spaceman3750 Send a message via MSN to Spaceman3750 Send a message via Yahoo to Spaceman3750
Default

Wow, this beats my guide ("Spyware and Adware and Malware, oh my!"). Nice work .


__________________
- Ryan
http://www.spaceman3750.info
http://www.conglomerate-game.net

Cisco Academy - CCNA student
  #5  
Old 11-12-2005
btalman's Avatar
Elite Member
 
Join Date: Nov 2005
Posts: 504
btalman - See this Members User comments on their Profile page
Default

:-) Thanks


__________________
  #6  
Old 12-01-2005
vidall's Avatar
Bronze Member
 
Join Date: Nov 2005
Posts: 3
vidall - See this Members User comments on their Profile page
Default

really Nice work
thanks



Reply
New! Norton Internet Security 2008 – Download Now Click Here

Bookmarks

Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


All times are GMT +1. The time now is 10:41 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top