132
2 Computer Viruses, Malicious Logic, and Spyware
Table 2.2 (continued)
Name of the Trojan program
Purpose and functioning features
Trojan-DDoS
Trojan network attacks
They use the user’s computer to send multiple
requests to a remote server. The server has not
enough resources to process requests, and it stops
working (Denial-of-service (DoS)). Such
programs are often used to infect multiple
computers to attack a single server using them
Trojan-IM
Trojan programs stealing data of instant
messaging program users
These programs steal numbers and passwords of
users of Internet messengers, such as ICQ, MSN
Messenger, AOL Instant Messenger, Yahoo
Pager, or Skype. They transfer the information to
the intruder via e-mail, FTP, web page hit, or
otherwise
Rootkit
Rootkits
They hide other malware programs and their
activity, thus prolonging the time spent by these
programs in the system; they can hide files,
processes in the memory of the infected
computer, or register keys that run malicious
programs, as well as data exchange between
applications on the user’s computer and other
computers in the network
Trojan-SMS
Trojan-SMS messengers
These problems infect mobile phones and use
them to send SMS messengers to paid numbers
Trojan-gamethief
Trojan programs stealing data of users of
Internet games
These Trojans steal details of user accounts in
network computer games and transfer the
information to the intruder via e-mail, FTP, web
page hits, or otherwise
Trojan-banker
Trojans stealing bank accounts
These Trojans steal details of bank accounts or
accounts in e-money systems and transfer the
information to the intruder via e-mail, FTP, web
page hits, or otherwise
Trojan-mailfinder
Trojan programs for collection of electronic
addresses
They collect e-mail addresses from the computer
and transfer them to the intruder via e-mail, FTP,
web page hit, or otherwise. Intruders can send
spam to the collected addresses
they will be forced to search for the implant, and the intruder will not be able to
access the system. If the administrator manages to track destination of such packets,
he will ultimately be able to identify the intruder. Due to this reason, experienced
intruders always try to hide their connections and tasks of the implant. To do this,
they use several methods of disguise; some of them are briefly described below.
Cryptography Use
In many cases, intruders use cryptography to encode the data transferred between
the victim’s system and the intruder. They use various encryption methods to
dens commands and transfer data between the victim’s device and the intruder’s
Précédent

- 153/839

Suivant