Our November Competition
User Reviews - Add Yours!
The PCHF Lounge
Go Back   PC Help Forum » Tutorials » Security Tutorials
Register for a Free Account

Security Tutorials - Malware/Spyware/Viruses/Trojans What Are They posted in the Tutorials forums; Adware Adware are programs which will, after installation, display advertisements. These come in two types, the first being used in shareware programs to 'pay' for development, the advertisements are integrated ...


Reply
Free PC Performance Scan
Old 11-11-2005   #1
Elite Member
 
Join Date: Nov 2005
Posts: 499
Default Malware/Spyware/Viruses/Trojans What Are They

Adware
Adware are programs which will, after installation, display advertisements. These come in two types, the first being used in shareware programs to 'pay' for development, the advertisements are integrated into the program. Here adware means advertised supported software. The second category is the one which causes trouble, this adware, provided by companies like gator, but also included in messenger plus! (don't check the box next to install with sponsors), give you advertisements at random times when online. You don't see the software is there, and when getting those ads, it can be hard to tell with which program the adware came. The last category can also be recognized by a ridicilous ammount of advertisements and pop-ups.

Backdoors
A backdoor is a piece of software to bypass login procedures, thus giving the person who spread the backdoor, full access to your system. Having a backdoor exposes your computer to the internet in a seriously threatning way.
How does a backdoor work? Basically it opens your computer to anyone who knows your computer is infected. This usually happens by exploiting bugs in the operating system or just by installing and running itself. There are two types of backdoors:
  • Backdoor/trojan, the backdoor is part of a program, or a file is infected. Once you launch the file, the backdoor is installed. The program only runs when the infected file/program is run and spreads itself using the infected computer like a trojan does
  • Backdoor/worm, the backdoor is launched while booting and thus runs continually when the computer is turned on. Some of these backdoors login to an irc room so your computer, and thousands of infected others, can be used for different purposes like DDoS-Attacks (Distributed Denial of Service)
You can quite easily prevent backdoors with a good firewall and virusscanner

Browser Helper Objects (BHO's)
A Browser Helper Object (BHO) is a DLL module that loads everytime you start your browser. Usually, a BHO is installed on your system by another software program or installed when visiting a website. An example of a BHO installed by software is the Adobe PDF plugin so you can read pdf documents without manually starting Acrobat Reader, when surfing the web. An BHO installed by a website is the google toolbar.
BHO's can do "anything" but most of the time they provide some sort of extra functionality to the user like a toolbar. These BHO's require your permission to be installed on the system. Some BHO's get installed secretly or are shipped with a program as a 'third party application' such as the BHO's supplied with Messenger Plus. This last category, the 'hidden' BHO's are a safety threat. Most of the time they'l annoy you by creating dozens of popups or redirecting your site searches. But they can do virtually anything like reading or writeing on your system, sending data about you and your surfing habits etc.
Most BHO's require user approval before being installed even those semi-hidden BHO's, described as third party programs. Ever wondered where information about those third party programs is 'hidden'? It isn't that hard to find, before installing a, usually 'free', program take a good look at the license agreement. If it's too big, select all text (control-a) copy it (control-c) and paste it (control-v) in a word document. Then search (control-f) for terms like 'third (3rd)' or 'third (3rd) party'. See? The info is there but it's hidden in a lot of judicial terms.


Browser Hijacker
When starting your browser you notice a different homepage, not the one you set it be or, when you misspell a web address you get a search engine loaded with sponsored links or ads, finally, when you enter a web address you're sure of, is right, you end up at an advertising page. These are all signs of a Browser Hijacker.


Dialer

A dialer is a piece of software which changes your default internet connection to an expensive phonenumber even when you have a broandband connection you can be struck by the effects of a dialer.
You get a dialer by downloading/installing it, the same way you get adware and spyware, though viruses can also contain dialers or install them. Most of the time you get dialers after visiting a site with specific content only available to you when you call a special number with your computer, after you dial the number and break the connection the dialer sets itself as the default connection. This way you can browse the net but, unknowingly, pay great ammounts of money to do so. You don't notice anything wrong, untill the next phonebill arrives.


Keyloggers

Keylogging is the capturing of everything entered using the keyboard and storing this information. Viruses, Trojans and Worms can contain keyloggers and thus log everything you type, and send it to the creator of the malware. Not a real problem when you only use our computer for editing and printing word documents.
Think again, a keylogger wil save EVERYTHING you enter using the keyboard, including passwords, the, sensitive, information in the document and much more. Much more, well, everything, imagine having your creditcard info out in the open. Luckily most modern virusscanners can detect keyloggers even unknown keyloggers, since most of them use certain code which most keyloggers contain. Nevertheless the risk, how minimal it may be, is still a risk.


Malware
Malware/Malicious Software, is all software designed to damage, take-over or do things to your computer without you knowing it. So when someone speaks about malware or malicious software he/she can be talking about:
  • Adware
  • Backdoors
  • BHO's
  • Browser Hijackers
  • Dialers
  • Keyloggers
  • Spyware
  • Trojan Horses
  • Viruses
  • Wabbits
  • Worms
  • Etc.
Spyware
Spyware consists of a program or programs to collect data about your surfing behaviour and report it to advertisers so they can target you with spam, customize their ads when you browse the web etc. Programs confirmed containing spyware :
  • Bearshare
  • Bonzi Buddy
  • Dope Wars
  • Download Accelerator Pro (DAP)
  • Errorguard
  • Flashget (free)
  • Grokster
  • Kazaa
  • Radlight
  • Weatherbug
  • Wildtangent (they mostly produce winamp and WMP plugins/games)
Trojan Horse
Remember the story about the ancient Greeks and Troy? Instead of the wooden horse and a bunch of soldiers a computerized trojan horse replaces the horse by a program and the pack of soldiers by malware. A Trojan horse can contain everything, ranging from a 'simple' executable file which erases your harddrives to sophisticated viruses entering you into a bot network. So a Trojan horse is nothing more, or less, then disguised malware.
Most Torjan horses serve these purposes:
  1. The Remote Control Trojan, which gives the creator of the trojan control over the entire computer of the victim or certain parts ie. a backdoor
  2. The Password Trojan, which remembers/logs every password you enter and sends it to the creator of the trojan
  3. The keylogger, which doesn't only save your passwords, like above, but anything you enter using the keyboard
  4. The FTP Trojan. This variety creates an ftp server giving the creator of the trojan no direct control over your computer, but allows him/her to browse through all your files, modify, delete or downlaod files or even to add more files
  5. The DDoS/bot trojan which turns your computer into a zombie used for sending spam, or atacking/infecting other computers
Since Trojan horses use specific ports to communicate, a good firewall will prevent trojans 'calling home'/communicating


Viruses

The term virus is usually applied to all forms of malware even spyware and adware, though a virus, usually, isn't. A virus is a piece of code which replicates itself, unlike a trojan horse for example, by infecting files on your computer or by creating infected files. Viruses can do a lot of things to your computer, ranging from annoying, infecting all your files, to destructive, deleting your data.
Viruses can reside anywhere on your computer, including
  • Macro's
  • Scripts
  • Executables (com, exe, bat, pif etc.)
  • Boot sectors of disks, like floppy's
  • The master boot sector of your harddrive
Wabbits
A Wabbit is very uncommon to encounter, one of the reasons is they don't spread to other computers by itself. Once a wabbit is executed it start to replicate itself real quick, hence the name, creating lots and lots of files on your computer causing your harddrive to be filled up and system unstability.
Some wabbits are a little more advanced and start copies of the newly created files, thus creating more wabbits in an exponential way,t aking up more harddrive space, pushing your CPU and memory and, finally, crashing or freezing your computer. Wabbits are annoying but not that harmfull, unless more malicious code is added but then a wabbit isn't a wabbit, but it turns into a virus.


Worms

A worm is the same as a virus but with these differences:
  • It doesn't need a host to attach to, it's stand-alone
  • It spreads using network connections (a virus only infects local files)
  • It can contain other malicious code such as a Trojan Horse or backdoor
Copyright Surfing Safe
Comments on this post
martinzx13 comments: Excellent, thanks
__________________
btalman is offline   Reply With Quote
Advertisement - Register to Remove

Old 11-11-2005   #2
Friend of PCHF
 
Join Date: Sep 2004
Location: Right here !
Posts: 2,148
Default

:read2:
Lovely, absolutely lovely....

Thanks again btalman.
Zimbo is offline   Reply With Quote
Old 11-11-2005   #3
Elite Member
 
Join Date: Nov 2005
Posts: 499
Default

*blushing, thanks. As soon as I finish more of these tutorials/infosheets I'll post them
__________________
btalman is offline   Reply With Quote
Old 11-12-2005   #4
Elite Member
 
Spaceman3750's Avatar
 
Join Date: Jan 2004
Location: Riverton, IL, USA
Posts: 1,472
PC Experience: Very Experienced
Default

Wow, this beats my guide ("Spyware and Adware and Malware, oh my!"). Nice work .
__________________
- Ryan
http://www.spaceman3750.info
http://www.conglomerate-game.net

Cisco Academy - CCNA student
Spaceman3750 is offline   Reply With Quote
Old 11-12-2005   #5
Elite Member
 
Join Date: Nov 2005
Posts: 499
Default

:-) Thanks
__________________
btalman is offline   Reply With Quote
Old 12-01-2005   #6
Bronze Member
 
Join Date: Nov 2005
Posts: 3
Default

really Nice work
thanks
vidall is offline   Reply With Quote
Old 12-01-2005   #7
Elite Member
 
Join Date: Nov 2005
Posts: 499
Default

Thanks Vidall and a warm welcome to PHCF :-)
__________________
btalman is offline   Reply With Quote

Reply

Bookmarks

Tags
information, Information:
Similar discussions...
Thread Thread Starter Forum Replies Last Post
Lots of spyware and trojans pns1 [Pending] HJT Logs 15 04-02-2009 11:58 PM
Pending: Trojans, Spys, and VIruses MrTurtle [Pending] HJT Logs 9 04-02-2009 11:52 PM
Fixed: Need Help with getting rid of trojans/viruses LifeIsABeach2191 [Fixed] Hijackthis! Logs 16 12-24-2008 06:06 AM
Doing prework,, lots of trojans and viruses found angpace [Fixed] Hijackthis! Logs 7 12-20-2007 05:02 AM
[Fixed] I have tons of malware and trojans! help!! Oender [Fixed] Hijackthis! Logs 25 12-23-2005 12:50 AM

Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On




All times are GMT. The time now is 08:41 AM.
Powered by vBulletin
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2