2.1 Computer Viruses
109
options are possible: it can decipher himself all at once, or it can perform such decryption “along the way,” he can re-encrypt the already spent sections. All this is done
for the difficulty of analyzing a virus-carrying code.
A Trojan horse is a very common malicious program, usually containing some
predetermined destructive function, which is activated only when a certain condition
of triggering occurs. Usually, such programs are always disguised as some useful
utilities.
In general, Trojan Horses are attacking programs that also implement, in addition
to their main functions, described in technical documentation, some other specific
functions associated with the dangerous violation of generally accepted safety rules
and destructive actions. The literature and expert observations show that there have
been cases of creating such programs specifically to facilitate the propagation of
viruses. Of course, lists of such programs are periodically widely published in the
foreign press. As follows from analytical articles of computer security specialists
who deal with this difficult problem, usually such parasitic programs are disguised as
game or entertainment programs and harm (perform their criminal tasks) as beautiful
pictures or music.
It’s worth paying attention to the fact that computer viruses and Trojan
horses cause damage by means of avalanche-type self-replication or obvious selfdestruction; the main function of worm-type viruses operating in computer networks
is a compromise of the attacked system, i.e., penetration for security and integrity
violation purposes.
A Trojan horse is a program that contains some destructive function that is activated when a certain condition of triggering occurs. Usually, such programs are
disguised as some useful utilities. Viruses can carry Trojan horses or “trojanize”
other programs and bring destructive functions into them.
A Trojan horse program usually looks like a useful application, for example, a
simple application for a user’s browser. However, while this user is “sitting in a
browser,” this malicious program sends its own copy by e-mail to virtually every
subscriber recorded in this user’s address book. For example, all your subscribers
(including supervisors) receive a “game” via e-mail. The Trojan program automatically transmits not only user names, but also their passwords and other confidential
information to its malicious creators. It is clear that this creates a big problem for a
user, because, as a rule, the absolute majority of users often use the same login and
password for many applications and systems used. The names of the most famous
Trojan programs of this type are Back Orifice, TDL-4, Pinch, Trojan Winlock, Crackerjack, Backdoor, Dick, and Crack2000. So, the Crackerjack program tests the relative “power” of passwords located in the selected file. After launching, it displays
a list of all cracked passwords and prompts the user to delete this file. Yet, the
first version of this program not only cracked even very complex passwords, but
also transferred them to the author of this Trojan horse. So, Bionet 318 and Antilam
provide the ability to open communication ports, allowing you to get “remote control”
over any user’s computer. In more than 80% of computer crimes investigated by the
FBI, attackers penetrate a system under attack via the global Internet. When such
Précédent

- 130/839

Suivant