2.2 Implants: Types, Ways of Injection, and Methods of Protection
123
these sectors that takes over control for further loading of the operating system
itself);
• Driver implants associated with drivers (files containing the information necessary
for the operating system to control peripheral devices connected to the computer);
• Application implants associated with general-purpose application software (text
editors, utility programs, antivirus monitoring tools, and software shells);
• Executable implants associated with executable software modules containing the
code of this implant (these modules are most often designed as package files, i.e.,
files containing the operating system commands executed in sequence, as if typed
with the computer keyboard);
• Simulator implants, the interface of which coincides with the interface of
certain service programs demanding input of confidential information (passwords,
cryptographic keys, credit card numbers);
• Masked implants that are disguised as computer optimization tools (file archivers,
disk defragmenters) or as gaming and entertainment software.
Software implants can be classified based on the time they spend in RAM:
• Resident implants: They are permanently stored in memory from a certain moment
until completion of the work session of the personal computer (power-off or
rebooting);
• Non-resident: They start work after a similar event but end it autonomously after
a certain amount of time or an event, fully unloading themselves from memory.
Software implants can also be classified based on the type of their effect on the
system:
• Implants introducing random changes in the program codes stored in the random
access memory of the computer (first type implants);
• Implants transferring fragments of information from certain areas of random
access or external memory of the computer to other areas (second type implants);
• Implants distorting the information output to external computer devices or into the
communication channel and received as a result of operation of other programs
(third type implants).
As stated above, Trojans are usually created with the sole purpose of damaging the
computer by means of unauthorized actions: data theft, corruption or destruction of
confidential information, impairment of PC operation, or utilization of its resources
for malicious purposes.
Even though some program implants (Trojans) are capable of bypassing protection
of the computing system, in most cases they enter a PC with another virus. Therefore,
Trojan programs can be considered as additional malware. Users frequently download
such Trojan horse software from the Internet on their own.
Lifecycle of a Trojan consists of three stages:
– Penetration into the system;
– Activation;
– Performance of malicious actions.
Précédent

- 144/839

Suivant