Trojan list sorted on used ports:
port 0 REx
port 1 (UDP) - Sockets des Troie
port 2 Death
port 5 yoyo
port 11 Skun
port 16 Skun
port 17 Skun
port 18 Skun
port 19 Skun
port 20 Amanda
port 21 ADM worm, Back Construction, Blade Runner, BlueFire, Bmail, Cattivik FTP Server, CC Invader, Dark FTP, Doly Trojan, FreddyK, Invisible FTP, KWM, MscanWorm, NerTe, NokNok, Pinochet, Ramen, Reverse Trojan, RTB 666, The Flu, WinCrash, Voyager Alpha Force
port 22 InCommand, Shaft, Skun
port 23 ADM worm, Aphex's Remote Packet Sniffer , AutoSpY, ButtMan, Fire HacKer, My Very Own trojan, Pest, RTB 666, Tiny Telnet Server - TTS, Truva Atl
port 25 Antigen, Barok, BSE, Email Password Sender , Gip, Laocoon, Magic Horse, MBT , Moscow Email trojan, Nimda, Shtirlitz, Stukach, Tapiras, WinPC
port 27 Assasin
port 28 Amanda
port 30 Agent 40421
port 31 Agent 40421, Masters Paradise, Skun
port 37 ADM worm
port 39 SubSARI
port 41 Deep Throat , Foreplay
port 44 Arctic
port 51 fu** Lamers Backdoor
port 52 MuSka52, Skun
port 53 ADM worm, li0n, MscanWorm, MuSka52
port 54 MuSka52
port 66 AL-Bareki
port 69 BackGate Kit, Nimda, Pasana, Storm, Storm worm, Theef
port 69 (UDP) - Pasana
port 70 ADM worm
port 79 ADM worm, Firehotcker
port 80 711 trojan (Seven Eleven), AckCmd, BlueFire, Cafeini, Duddie, Executor, God Message, Intruzzo , Latinus, Lithium, MscanWorm, NerTe, Nimda, Noob, Optix Lite, Optix Pro , Power, Ramen, Remote Shell , Reverse WWW Tunnel Backdoor , RingZero, RTB 666, Scalper, Screen Cutter , Seeker, Slapper, Web Server CT , WebDownloader
port 80 (UDP) - Penrox
port 81 Asylum
port 101 Skun
port 102 Delf, Skun
port 103 Skun
port 105 NerTe
port 107 Skun
port 109 ADM worm
port 110 ADM worm
port 111 ADM worm, MscanWorm
port 113 ADM worm, Alicia, Cyn, DataSpy Network X, Dosh, Gibbon, Taskman
port 120 Skun
port 121 Attack Bot, God Message, JammerKillah
port 123 Net Controller
port 137 Chode, Nimda
port 137 (UDP) - Bugbear, Msinit, Opaserv, Qaz
port 138 Chode, Nimda
port 139 Chode, Fire HacKer, Msinit, Nimda, Opaserv, Qaz
port 143 ADM worm
port 146 Infector
port 146 (UDP) - Infector
port 166 NokNok
port 170 A-trojan
port 171 A-trojan
port 200 CyberSpy
port 201 One Windows Trojan
port 202 One Windows Trojan, Skun
port 211 One Windows Trojan
port 212 One Windows Trojan
port 221 Snape
port 222 NeuroticKat, Snape
port 230 Skun
port 231 Skun
port 232 Skun
port 285 Delf
port 299 One Windows Trojan
port 334 Backage
port 335 Nautical
port 370 NeuroticKat
port 400 Argentino
port 401 One Windows Trojan
port 402 One Windows Trojan
port 411 Backage
port 420 Breach
port 443 Slapper
port 445 Nimda
port 455 Fatal Connections
port 511 T0rn Rootkit
port 513 ADM worm
port 514 ADM worm
port 515 MscanWorm, Ramen
port 520 (UDP) - A UDP backdoor
port 555 711 trojan (Seven Eleven), Phase Zero, Phase-0
port 564 Oracle
port 589 Assasin
port 600 SweetHeart
port 623 RTB 666
port 635 ADM worm
port 650 Assasin
port 661 NokNok
port 666 Attack FTP, Back Construction, BLA trojan, NokNok, Reverse Trojan, Shadow Phyre, Unicorn, yoyo
port 667 NokNok, SniperNet
port 668 Unicorn
port 669 DP trojan , SniperNet
port 680 RTB 666
port 692 GayOL
port 700 REx
port 777 Undetected
port 798 Oracle
port 808 WinHole
port 831 NeuroticKat
port 901 Net-Devil, Pest
port 902 Net-Devil, Pest
port 903 Net-Devil
port 911 Dark Shadow, Dark Shadow
port 956 Crat Pro
port 991 Snape
port 992 Snape
port 999 Deep Throat , Foreplay
port 1000 Der Späher / Der Spaeher, Direct Connection, GOTHIC Intruder , Theef
port 1001 Der Späher / Der Spaeher, GOTHIC Intruder , Lula, One Windows Trojan, Theef
port 1005 Pest, Theef
port 1008 AutoSpY, li0n
port 1010 Doly Trojan
port 1011 Doly Trojan
port 1012 Doly Trojan
port 1015 Doly Trojan
port 1016 Doly Trojan
port 1020 Vampire
port 1024 Latinus, Lithium, NetSpy, Ptakks
port 1025 AcidkoR, BDDT, DataSpy Network X, Fraggle Rock , KiLo, MuSka52, NetSpy, Optix Pro , Paltalk, Ptakks, Real 2000, Remote Anything, Remote Explorer Y2K, Remote Storm, RemoteNC
port 1025 (UDP) - KiLo, Optix Pro , Ptakks, Real 2000, Remote Anything, Remote Explorer Y2K, Remote Storm, Yajing
port 1026 BDDT, Dark IRC, DataSpy Network X, Delta Remote Access , Dosh, Duddie, IRC Contact, Remote Explorer 2000, RUX The TIc.K
port 1026 (UDP) - Remote Explorer 2000
port 1027 Clandestine, DataSpy Network X, KiLo, UandMe
port 1028 DataSpy Network X, Dosh, Gibbon, KiLo, KWM, Litmus, Paltalk, SubSARI
port 1028 (UDP) - KiLo, SubSARI
port 1029 Clandestine, KWM, Litmus, SubSARI
port 1029 (UDP) - SubSARI
port 1030 Gibbon, KWM
port 1031 KWM, Little Witch, Xanadu, Xot
port 1031 (UDP) - Xot
port 1032 Akosch4, Dosh, KWM
port 1032 (UDP) - Akosch4
port 1033 Dosh, KWM, Little Witch, Net Advance
port 1034 KWM
port 1035 Dosh, KWM, RemoteNC, Truva Atl
port 1036 KWM
port 1037 Arctic , Dosh, KWM, MoSucker
port 1039 Dosh
port 1041 Dosh, RemoteNC
port 1042 BLA trojan
port 1042 (UDP) - BLA trojan
port 1043 Dosh
port 1044 Ptakks
port 1044 (UDP) - Ptakks
port 1047 RemoteNC
port 1049 Delf, The Hobbit Daemon
port 1052 Fire HacKer, Slapper, The Hobbit Daemon
port 1053 The Thief
port 1054 AckCmd, RemoteNC
port 1080 SubSeven 2.2, WinHole
port 1081 WinHole
port 1082 WinHole
port 1083 WinHole
port 1092 Hvl RAT
port 1095 Blood Fest Evolution, Hvl RAT, Remote Administration Tool - RAT
port 1097 Blood Fest Evolution, Hvl RAT, Remote Administration Tool - RAT
port 1098 Blood Fest Evolution, Hvl RAT, Remote Administration Tool - RAT
port 1099 Blood Fest Evolution, Hvl RAT, Remote Administration Tool - RAT
port 1104 (UDP) - RexxRave
port 1111 Daodan, Ultors Trojan
port 1111 (UDP) - Daodan
port 1115 Lurker, Protoss
port 1116 Lurker
port 1116 (UDP) - Lurker
port 1122 Last 2000, Singularity
port 1122 (UDP) - Last 2000, Singularity
port 1133 SweetHeart
port 1150 Orion
port 1151 Orion
port 1160 BlackRat
port 1166 CrazzyNet
port 1167 CrazzyNet
port 1170 Psyber Stream Server , Voice
port 1180 Unin68
port 1183 Cyn, SweetHeart
port 1183 (UDP) - Cyn, SweetHeart
port 1200 (UDP) - NoBackO
port 1201 (UDP) - NoBackO
port 1207 SoftWAR
port 1208 Infector
port 1212 Kaos
port 1215 Force
port 1218 Force
port 1219 Force
port 1221 fu** Lamers Backdoor
port 1222 fu** Lamers Backdoor
port 1234 KiLo, Ultors Trojan
port 1243 BackDoor-G, SubSeven , Tiles
port 1245 VooDoo Doll
port 1255 Scarab
port 1256 Project nEXT, RexxRave
port 1272 The Matrix
port 1313 NETrojan
port 1314 Daodan
port 1349 BO dll
port 1369 SubSeven 2.2
port 1386 Dagger
port 1415 Last 2000, Singularity
port 1433 Voyager Alpha Force
port 1441 Remote Storm
port 1492 FTP99CMP
port 1524 Trinoo
port 1560 Big Gluck, Duddie
port 1561 (UDP) - MuSka52
port 1600 Direct Connection
port 1601 Direct Connection
port 1602 Direct Connection
port 1703 Exploiter
port 1711 yoyo
port 1772 NetControle
port 1772 (UDP) - NetControle
port 1777 Scarab
port 1826 Glacier
port 1833 TCC
port 1834 TCC
port 1835 TCC
port 1836 TCC
port 1837 TCC
port 1905 Delta Remote Access
port 1911 Arctic
port 1966 Fake FTP
port 1967 For Your Eyes Only , WM FTP Server
port 1978 (UDP) - Slapper
port 1981 Bowl, Shockrave
port 1983 Q-taz
port 1984 Intruzzo , Q-taz
port 1985 Black Diver, Q-taz
port 1985 (UDP) - Black Diver
port 1986 Akosch4
port 1991 PitFall
port 1999 Back Door, SubSeven , TransScout
port 2000 A-trojan, Der Späher / Der Spaeher, Fear, Force, GOTHIC Intruder , Last 2000, Real 2000, Remote Explorer 2000, Remote Explorer Y2K, Senna Spy Trojan Generator, Singularity
port 2000 (UDP) - GOTHIC Intruder , Real 2000, Remote Explorer 2000, Remote Explorer Y2K
port 2001 Der Späher / Der Spaeher, Duddie, Glacier, Protoss, Senna Spy Trojan Generator, Singularity, Trojan Cow
port 2001 (UDP) - Scalper
port 2002 Duddie, Senna Spy Trojan Generator, Sensive
port 2002 (UDP) - Slapper
port 2004 Duddie
port 2005 Duddie
port 2023 Ripper Pro
port 2060 Protoss
port 2080 WinHole
port 2101 SweetHeart
port 2115 Bugs
port 2130 (UDP) - Mini BackLash
port 2140 The Invasor
port 2140 (UDP) - Deep Throat , Foreplay , The Invasor
port 2149 Deep Throat
port 2150 R0xr4t
port 2156 Oracle
port 2222 SweetHeart, Way
port 2222 (UDP) - SweetHeart, Way
port 2281 Nautical
port 2283 Hvl RAT
port 2300 Storm
port 2311 Studio 54
port 2330 IRC Contact
port 2331 IRC Contact
port 2332 IRC Contact, Silent Spy
port 2333 IRC Contact
port 2334 IRC Contact, Power
port 2335 IRC Contact
port 2336 IRC Contact
port 2337 IRC Contact, The Hobbit Daemon
port 2338 IRC Contact
port 2339 IRC Contact, Voice Spy
port 2339 (UDP) - Voice Spy
port 2343 Asylum
port 2345 Doly Trojan
port 2407 yoyo
port 2418 Intruzzo
port 2555 li0n, T0rn Rootkit
port 2565 Striker trojan
port 2583 WinCrash
port 2589 Dagger
port 2600 Digital RootBeer
port 2702 Black Diver
port 2702 (UDP) - Black Diver
port 2772 SubSeven
port 2773 SubSeven , SubSeven 2.1 Gold
port 2774 SubSeven , SubSeven 2.1 Gold
port 2800 Theef
port 2929 Konik
port 2983 Breach
port 2989 (UDP) - Remote Administration Tool - RAT
port 3000 InetSpy, Remote Shut, Theef
port 3006 Clandestine
port 3024 WinCrash
port 3031 MicroSpy
port 3119 Delta Remote Access
port 3128 Reverse WWW Tunnel Backdoor , RingZero
port 3129 Masters Paradise
port 3131 SubSARI
port 3150 Deep Throat , The Invasor, The Invasor
port 3150 (UDP) - Deep Throat , Foreplay , Mini BackLash
port 3215 XHX
port 3215 (UDP) - XHX
port 3292 Xposure
port 3295 Xposure
port 3333 Daodan
port 3333 (UDP) - Daodan
port 3410 Optix Pro
port 3417 Xposure
port 3418 Xposure
port 3456 Fear, Force, Terror trojan
port 3459 Eclipse 2000, Sanctuary
port 3505 AutoSpY
port 3700 Portal of Doom
port 3721 Whirlpool
port 3723 Mantis
port 3777 PsychWard
port 3791 Total Solar Eclypse
port 3800 Total Solar Eclypse
port 3801 Total Solar Eclypse
port 3945 Delta Remote Access
port 3996 Remote Anything
port 3996 (UDP) - Remote Anything
port 3997 Remote Anything
port 3999 Remote Anything
port 4000 Remote Anything, SkyDance
port 4092 WinCrash
port 4128 RedShad
port 4128 (UDP) - RedShad
port 4156 (UDP) - Slapper
port 4201 War trojan
port 4210 Netkey
port 4211 Netkey
port 4225 Silent Spy
port 4242 Virtual Hacking Machine - VHM
port 4315 Power
port 4321 BoBo
port 4414 AL-Bareki
port 4442 Oracle
port 4444 CrackDown, Oracle, Prosiak, Swift Remote
port 4445 Oracle
port 4447 Oracle
port 4449 Oracle
port 4451 Oracle
port 4488 Event Horizon
port 4567 File Nail
port 4653 Cero
port 4666 Mneah
port 4700 Theef
port 4836 Power
port 5000 Back Door Setup, Bubbel, Ra1d, Sockets des Troie
port 5001 Back Door Setup, Sockets des Troie
port 5002 Shaft
port 5005 Aladino
port 5011 Peanut Brittle
port 5025 WM Remote KeyLogger
port 5031 Net Metropolitan
port 5032 Net Metropolitan
port 5050 R0xr4t
port 5135 Bmail
port 5150 Pizza
port 5151 Optix Lite
port 5152 Laphex
port 5155 Oracle
port 5221 NOSecure
port 5250 Pizza
port 5321 Firehotcker
port 5333 Backage
port 5350 Pizza
port 5377 Iani
port 5400 Back Construction, Blade Runner, Digital Spy
port 5401 Back Construction, Blade Runner, Digital Spy , Mneah
port 5402 Back Construction, Blade Runner, Digital Spy , Mneah
port 5418 DarkSky
port 5419 DarkSky
port 5419 (UDP) - DarkSky
port 5430 Net Advance
port 5450 Pizza
port 5503 Remote Shell
port 5534 The Flu
port 5550 Pizza
port 5555 Daodan, NoXcape
port 5555 (UDP) - Daodan
port 5556 BO Facil
port 5557 BO Facil
port 5569 Robo-Hack
port 5650 Pizza
port 5669 SpArTa
port 5679 Nautical
port 5695 Assasin
port 5696 Assasin
port 5697 Assasin
port 5742 WinCrash
port 5802 Y3K RAT
port 5873 SubSeven 2.2
port 5880 Y3K RAT
port 5882 Y3K RAT
port 5882 (UDP) - Y3K RAT
port 5888 Y3K RAT
port 5888 (UDP) - Y3K RAT
port 5889 Y3K RAT
port 5933 NOSecure
port 6000 Aladino, NetBus , The Thing
port 6006 Bad Blood
port 6267 DarkSky
port 6400 The Thing
port 6521 Oracle
port 6526 Glacier
port 6556 AutoSpY
port 6661 Weia-Meia
port 6666 AL-Bareki, KiLo, SpArTa
port 6666 (UDP) - KiLo
port 6667 Acropolis, BlackRat, Dark FTP, Dark IRC, DataSpy Network X, Gunsan, InCommand, Kaitex, KiLo, Laocoon, Net-Devil, Reverse Trojan, ScheduleAgent, SlackBot, SubSeven , Subseven 2.1.4 DefCon 8, Trinity, Y3K RAT, yoyo
port 6667 (UDP) - KiLo
port 6669 Host Control, Vampire, Voyager Alpha Force
port 6670 BackWeb Server, Deep Throat , Foreplay , WinNuke eXtreame
port 6697 Force
port 6711 BackDoor-G, Duddie, KiLo, Little Witch, Netkey, Spadeace, SubSARI, SubSeven , SweetHeart, UandMe, Way, VP Killer
port 6712 Funny trojan, KiLo, Spadeace, SubSeven
port 6713 KiLo, SubSeven
port 6714 KiLo
port 6715 KiLo
port 6718 KiLo
port 6723 Mstream
port 6766 KiLo
port 6766 (UDP) - KiLo
port 6767 KiLo, Pasana, UandMe
port 6767 (UDP) - KiLo, UandMe
port 6771 Deep Throat , Foreplay
port 6776 2000 Cracks, BackDoor-G, SubSeven , VP Killer
port 6838 (UDP) - Mstream
port 6891 Force
port 6912 <img src=\'http://www.killanet.net/forum3/public/s ... nsored.gif\' class=\'bbc_emoticon\' alt=\'(cens)\' /> Heep
port 6969 2000 Cracks, BlitzNet, Dark IRC, GateCrasher, Kid Terror, Laphex, Net Controller, SpArTa, Vagr Nocker
port 6970 GateCrasher
port 7000 Aladino, Gunsan, Remote Grab, SubSeven , SubSeven 2.1 Gold, Theef
port 7001 Freak88, Freak2k
port 7007 Silent Spy
port 7020 Basic Hell
port 7030 Basic Hell
port 7119 Massaker
port 7215 SubSeven , SubSeven 2.1 Gold
port 7274 AutoSpY
port 7290 NOSecure
port 7291 NOSecure
port 7300 NetSpy
port 7301 NetSpy
port 7306 NetSpy
port 7307 NetSpy, Remote Process Monitor
port 7308 NetSpy, X Spy
port 7312 Yajing
port 7410 Phoenix II
port 7424 Host Control
port 7424 (UDP) - Host Control
port 7597 Qaz
port 7626 Glacier
port 7648 XHX
port 7673 Neoturk
port 7676 Neoturk
port 7677 Neoturk
port 7718 Glacier
port 7722 KiLo
port 7777 God Message
port 7788 Last 2000, Last 2000, Singularity
port 7788 (UDP) - Singularity
port 7789 Back Door Setup
port 7800 Paltalk
port 7826 Oblivion
port 7850 Paltalk
port 7878 Paltalk
port 7879 Paltalk
port 7979 Vagr Nocker
port 7983 (UDP) - Mstream
port 8011 Way
port 8012 Ptakks
port 8012 (UDP) - Ptakks
port 8080 Reverse WWW Tunnel Backdoor , RingZero, Screen Cutter
port 8090 Aphex's Remote Packet Sniffer
port 8090 (UDP) - Aphex's Remote Packet Sniffer
port 8097 Kryptonic Ghost Command Pro
port 8100 Back streets
port 8110 DLP
port 8111 DLP
port 8127 9_119, Chonker
port 8127 (UDP) - 9_119, Chonker
port 8130 9_119, Chonker, DLP
port 8131 DLP
port 8301 DLP
port 8302 DLP
port 8311 SweetHeart
port 8322 DLP
port 8329 DLP
port 8488 (UDP) - KiLo
port 8489 KiLo
port 8489 (UDP) - KiLo
port 8685 Unin68
port 8732 Kryptonic Ghost Command Pro
port 8734 AutoSpY
port 8787 Back Orifice 2000
port 8811 Fear
port 8812 FraggleRock Lite
port 8821 Alicia
port 8848 Whirlpool
port 8864 Whirlpool
port 8888 Dark IRC
port 9000 Netministrator
port 9090 Aphex's Remote Packet Sniffer
port 9117 Massaker
port 9148 Nautical
port 9301 DLP
port 9325 (UDP) - Mstream
port 9329 DLP
port 9400 InCommand
port 9401 InCommand
port 9536 Lula
port 9561 Crat Pro
port 9563 Crat Pro
port 9870 Remote Computer Control Center
port 9872 Portal of Doom
port 9873 Portal of Doom
port 9874 Portal of Doom
port 9875 Portal of Doom
port 9876 Rux
port 9877 Small Big Brother
port 9878 Small Big Brother, TransScout
port 9879 Small Big Brother
port 9919 Kryptonic Ghost Command Pro
port 9999 BlitzNet, Oracle, Spadeace
port 10000 Oracle, TCP Door, XHX
port 10000 (UDP) - XHX
port 10001 DTr, Lula
port 10002 Lula
port 10003 Lula
port 10008 li0n
port 10012 Amanda
port 10013 Amanda
port 10067 Portal of Doom
port 10067 (UDP) - Portal of Doom
port 10084 Syphillis
port 10084 (UDP) - Syphillis
port 10085 Syphillis
port 10086 Syphillis
port 10100 Control Total, GiFt trojan, Scalper
port 10100 (UDP) - Slapper
port 10167 Portal of Doom
port 10167 (UDP) - Portal of Doom
port 10498 (UDP) - Mstream
port 10520 Acid Shivers
port 10528 Host Control
port 10607 Coma
port 10666 (UDP) - Ambush
port 10887 BDDT
port 10889 BDDT
port 11000 DataRape, Senna Spy Trojan Generator
port 11011 Amanda
port 11050 Host Control
port 11051 Host Control
port 11111 Breach
port 11223 Progenic trojan, Secret Agent
port 11225 Cyn
port 11225 (UDP) - Cyn
port 11660 Back streets
port 11718 Kryptonic Ghost Command Pro
port 11831 DarkFace, DataRape, Latinus, Pest, Vagr Nocker
port 11977 Cool Remote Control
port 11978 Cool Remote Control
port 11980 Cool Remote Control
port 12000 Reverse Trojan
port 12310 PreCursor
port 12321 Protoss
port 12321 (UDP) - Protoss
port 12345 Ashley, BlueIce 2000, Mypic , NetBus , Pie Bill Gates, Q-taz , Sensive, Snape, Vagr Nocker, ValvNet , Whack Job
port 12345 (UDP) - BlueIce 2000
port 12346 NetBus
port 12348 BioNet
port 12349 BioNet, The Saint
port 12361 Whack-a-mole
port 12362 Whack-a-mole
port 12363 Whack-a-mole
port 12623 ButtMan
port 12623 (UDP) - ButtMan, DUN Control
port 12624 ButtMan, Power
port 12631 Whack Job
port 12684 Power
port 12754 Mstream
port 12904 Rocks
port 13000 Senna Spy Trojan Generator, Senna Spy Trojan Generator
port 13013 PsychWard
port 13014 PsychWard
port 13028 Back streets
port 13079 Kryptonic Ghost Command Pro
port 13370 SpArTa
port 13371 Optix Pro
port 13500 Theef
port 13753 <img src=\'http://www.killanet.net/forum3/public/s ... nsored.gif\' class=\'bbc_emoticon\' alt=\'(cens)\' /> FTP
port 14194 CyberSpy
port 14285 Laocoon
port 14286 Laocoon
port 14287 Laocoon
port 14500 PC Invader
port 14501 PC Invader
port 14502 PC Invader
port 14503 PC Invader
port 15000 In Route to the Hell, R0xr4t
port 15092 Host Control
port 15104 Mstream
port 15206 KiLo
port 15207 KiLo
port 15210 (UDP) - UDP remote shell backdoor server
port 15382 SubZero
port 15432 Cyn
port 15485 KiLo
port 15486 KiLo
port 15486 (UDP) - KiLo
port 15500 In Route to the Hell
port 15512 Iani
port 15551 In Route to the Hell
port 15695 Kryptonic Ghost Command Pro
port 15845 (UDP) - KiLo
port 15852 Kryptonic Ghost Command Pro
port 16057 MoonPie
port 16484 MoSucker
port 16514 KiLo
port 16514 (UDP) - KiLo
port 16515 KiLo
port 16515 (UDP) - KiLo
port 16523 Back streets
port 16660 Stacheldraht
port 16712 KiLo
port 16761 Kryptonic Ghost Command Pro
port 16959 SubSeven , Subseven 2.1.4 DefCon 8
port 17166 Mosaic
port 17449 Kid Terror
port 17499 CrazzyNet
port 17500 CrazzyNet
port 17569 Infector
port 17593 AudioDoor
port 17777 Nephron
port 18753 (UDP) - Shaft
port 19191 BlueFire
port 19216 BackGate Kit
port 20000 Millenium, PSYcho Files, XHX
port 20001 Insect, Millenium, PSYcho Files
port 20002 AcidkoR, PSYcho Files
port 20005 MoSucker
port 20023 VP Killer
port 20034 NetBus 2.0 Pro, NetBus 2.0 Pro Hidden, Whack Job
port 20331 BLA trojan
port 20432 Shaft
port 20433 (UDP) - Shaft
port 21212 Sensive
port 21544 GirlFriend, Kid Terror
port 21554 Exploiter, FreddyK, Kid Terror, Schwindler, Sensive, Winsp00fer
port 21579 Breach
port 21957 Latinus
port 22115 Cyn
port 22222 Donald Dick, G.R.O.B., Prosiak, Ruler, RUX The TIc.K
port 22223 RUX The TIc.K
port 22456 Clandestine
port 22554 Schwindler
port 22783 Intruzzo
port 22784 Intruzzo
port 22785 Intruzzo
port 23000 Storm worm
port 23001 Storm worm
port 23005 NetTrash, Oxon
port 23006 NetTrash, Oxon
port 23023 Logged
port 23032 Amanda
port 23321 Konik
port 23432 Asylum
port 23456 Clandestine, Evil FTP, Vagr Nocker, Whack Job
port 23476 Donald Dick
port 23476 (UDP) - Donald Dick
port 23477 Donald Dick
port 23777 InetSpy
port 24000 Infector
port 24289 Latinus
port 25002 MOTD
port 25002 (UDP) - MOTD
port 25123 Goy'Z TroJan
port 25555 FreddyK
port 25685 MoonPie
port 25686 DarkFace, MoonPie
port 25799 FreddyK
port 25885 MOTD
port 25982 DarkFace, MoonPie
port 26274 (UDP) - Delta Source
port 26681 Voice Spy
port 27160 MoonPie
port 27184 Alvgus trojan 2000
port 27184 (UDP) - Alvgus trojan 2000
port 27373 Charge
port 27374 Bad Blood, Fake SubSeven, li0n, Ramen, Seeker, SubSeven , SubSeven 2.1 Gold, Subseven 2.1.4 DefCon 8, SubSeven 2.2, SubSeven Muie, The Saint
port 27379 Optix Lite
port 27444 (UDP) - Trinoo
port 27573 SubSeven
port 27665 Trinoo
port 28218 Oracle
port 28431 Hack´a´Tack
port 28678 Exploiter
port 29104 NETrojan, NetTrojan
port 29292 BackGate Kit
port 29559 AntiLamer BackDoor , DarkFace, DataRape, Ducktoy, Latinus, Pest, Vagr Nocker
port 29589 KiLo
port 29589 (UDP) - KiLo
port 29891 The Unexplained
port 29999 AntiLamer BackDoor
port 30000 DataRape, Infector
port 30001 Err0r32
port 30005 Litmus
port 30100 NetSphere
port 30101 NetSphere
port 30102 NetSphere
port 30103 NetSphere
port 30103 (UDP) - NetSphere
port 30133 NetSphere
port 30303 Sockets des Troie
port 30331 MuSka52
port 30464 Slapper
port 30700 Mantis
port 30947 Intruse
port 31320 Little Witch
port 31320 (UDP) - Little Witch
port 31335 Trinoo
port 31336 Butt Funnel
port 31337 ADM worm, Back Fire, Back Orifice (Lm), Back Orifice russian, BlitzNet, BO client, BO Facil, BO2, Freak88, Freak2k, NoBackO
port 31337 (UDP) - Back Orifice, Deep BO
port 31338 Back Orifice, Butt Funnel, NetSpy (DK)
port 31338 (UDP) - Deep BO, NetSpy (DK)
port 31339 Little Witch, NetSpy (DK), NetSpy (DK)
port 31339 (UDP) - Little Witch
port 31340 Little Witch
port 31340 (UDP) - Little Witch
port 31382 Lithium
port 31415 Lithium
port 31416 Lithium
port 31416 (UDP) - Lithium
port 31557 Xanadu
port 31745 BuschTrommel
port 31785 Hack´a´Tack
port 31787 Hack´a´Tack
port 31788 Hack´a´Tack
port 31789 Hack´a´Tack
port 31789 (UDP) - Hack´a´Tack
port 31790 Hack´a´Tack
port 31791 Hack´a´Tack
port 31791 (UDP) - Hack´a´Tack
port 31792 Hack´a´Tack
port 31887 BDDT
port 32000 BDDT
port 32001 Donald Dick
port 32100 Peanut Brittle, Project nEXT
port 32418 Acid Battery
port 32791 Acropolis, Rocks
port 33270 Trinity
port 33333 Prosiak
port 33545 G.R.O.B.
port 33567 li0n, T0rn Rootkit
port 33568 li0n, T0rn Rootkit
port 33577 Son of PsychWard
port 33777 Son of PsychWard
port 33911 Spirit 2000, Spirit 2001
port 34312 Delf
port 34313 Delf
port 34324 Big Gluck
port 34343 Osiris
port 34444 Donald Dick
port 34555 (UDP) - Trinoo (for Windows)
port 35000 Infector
port 35555 (UDP) - Trinoo (for Windows)
port 35600 SubSARI
port 36794 Bugbear
port 37237 Mantis
port 37651 Charge
port 38741 CyberSpy
port 38742 CyberSpy
port 40071 Ducktoy
port 40308 SubSARI
port 40412 The Spy
port 40421 Agent 40421, Masters Paradise
port 40422 Masters Paradise
port 40423 Masters Paradise
port 40425 Masters Paradise
port 40426 Masters Paradise
port 41337 Storm
port 41666 Remote Boot Tool , Remote Boot Tool
port 43720 (UDP) - KiLo
port 44014 Iani
port 44014 (UDP) - Iani
port 44444 Prosiak
port 44575 Exploiter
port 44767 School Bus
port 44767 (UDP) - School Bus
port 45092 BackGate Kit
port 45454 Osiris
port 45632 Little Witch
port 45673 Acropolis, Rocks
port 46666 Taskman
port 46666 (UDP) - Taskman
port 47017 T0rn Rootkit
port 47262 (UDP) - Delta Source
port 47698 KiLo
port 47785 KiLo
port 47785 (UDP) - KiLo
port 47891 AntiLamer BackDoor
port 48004 Fraggle Rock
port 48006 Fraggle Rock
port 48512 Arctic
port 49000 Fraggle Rock
port 49683 Fenster
port 49683 (UDP) - Fenster
port 49698 (UDP) - KiLo
port 50000 SubSARI
port 50021 Optix Pro
port 50130 Enterprise
port 50505 Sockets des Troie
port 50551 R0xr4t
port 50552 R0xr4t
port 50766 Schwindler
port 50829 KiLo
port 50829 (UDP) - KiLo
port 51234 Cyn
port 51966 Cafeini
port 52365 Way
port 52901 (UDP) - Omega
port 53001 Remote Windows Shutdown - RWS
port 54283 SubSeven , SubSeven 2.1 Gold
port 54320 Back Orifice 2000
port 54321 Back Orifice 2000, School Bus , yoyo
port 55165 File Manager trojan, File Manager trojan
port 55555 Shadow Phyre
port 55665 Latinus, Pinochet
port 55666 Latinus, Pinochet
port 56565 Osiris
port 57163 BlackRat
port 57341 NetRaider
port 57785 G.R.O.B.
port 58134 Charge
port 58339 Butt Funnel
port 59211 Ducktoy
port 60000 Deep Throat , Foreplay , Sockets des Troie
port 60001 Trinity
port 60008 li0n, T0rn Rootkit
port 60068 The Thing
port 60411 Connection
port 60551 R0xr4t
port 60552 R0xr4t
port 60666 Basic Hell
port 61115 Protoss
port 61337 Nota
port 61348 Bunker-Hill
port 61440 Orion
port 61603 Bunker-Hill
port 61746 KiLo
port 61746 (UDP) - KiLo
port 61747 KiLo
port 61747 (UDP) - KiLo
port 61748 (UDP) - KiLo
port 61979 Cool Remote Control
port 62011 Ducktoy
port 63485 Bunker-Hill
port 64101 Taskman
port 65000 Devil, Sockets des Troie, Stacheldraht
port 65289 yoyo
port 65421 Alicia
port 65422 Alicia
port 65432 The Traitor (= th3tr41t0r)
port 65432 (UDP) - The Traitor (= th3tr41t0r)
port 65530 Windows Mite
port 65535 RC1 trojan
Ports Database
Trojans - Information & Port Listings
Moderators: Moderator, Global Moderator
Trojans - Information & Port Listings

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Trojans - Information & Port Listings
IMPORTANT -- THIS DOCUMENT IS FOR INFORMATIONAL PURPOSES ONLY. To the maximum
extent permitted by applicable law, in no event shall Frame4 Security Systems
be liable for any damages whatsoever, (including, without limitation, damages
for loss of any business profits, business interruption, loss of any business
information, or other pecuniary loss) arising out of the use, or inability to
use any software, and/or procedures outlined in this document, even if Frame4
Security Systems has been advised of the possibility of such damage(s). There
are NO warranties with regard to this information, but the paper may help you
improve your Windows security a lot.
This paper is the property of Frame4 Security Systems, all rights reserved.
Copyright © 1999-2002 Frame4 Security Systems -- http://www.frame4.com/
-------------------------------------------------------------------------------
Author's Notes:
This is the updated version of my paper written a long while ago. During that
time I have seen it on every security/hacking site I came across and I'm glad
you're all placing it in your archives as recommended reading. Now, many more
sections and updates have been added so be sure that you will reading new and
interesting aspects regarding the topic. The paper will answer many questions
people keep asking in general about trojans like "how are attackers infecting
me" and "how to protect from trojans".
If you have any other questions about the topic including ideas, suggestions,
comments, etc., please do not hesitate to express your opinion. If you have a
lot to say on the topic and/or I have missed some aspects then please contact
me and contribute to the next update, and of course full credit will be given
to you and your ideas.
-------------------------------------------------------------------------------
Table of Contents
-----------------
01.What Is This Paper About
02.What Is A Trojan Horse
03.How Do Trojans Work
04.Trojans Variations
-Remote Access Trojans
-Password Sending Trojans
-Keylogging Trojans
-Destructive Trojans
-Denial Of Service (DoS) Attack Trojans
-Proxy/Wingate Trojans
-FTP Trojans
-Detection Software Killers
05.The Future Of Windows Trojans
06.How Can I Get Infected
-Via ICQ
-Via IRC
-Via Attachments
-Via Physical Access
-Via Browser And E-mail Software Bugs
-Via Netbios(File Sharing)
07.Fake Programs
08.Untrusted Sites And FreeWare Software
09.How Are They Detecting My Internet Presence
10.What Is The Attacker Looking For
11.Intelligence With Trojans
12.Trojan Ports
13.How Do I Know I'm Infected
14.Anti-Virus (AV) Scanners
15.Anti-Trojan Software
16.After You Clean Yourself
17.Online Scanning Services
18.Advice
19.Links Section
20.Final Words
-------------------------------------------------------------------------------
1.What is this paper about?
-------------------------
The Complete Trojans Text is a paper about Windows Trojans, how they work,
their variations and, of course, strategies to minimise the risk of infection.
Links to special detection software are included as well as many other topics
never discussed before. This paper is not only intended to be for the average
Internet/Windows user who wants to know how to protect his/her machine from
Trojan Horses or just want to know about their usage, variations, prevention
and future, but will also be interesting for the advanced user, to read
another point of view.
Windows Trojans are just a small aspect of Windows Security but you will soon
realise how dangerous and destructive they could be while reading the paper.
2.What Is A Trojan Horse?
-----------------------
A Trojan horse is:
- An unauthorised program contained within a legitimate program. This
unauthorised program performs functions unknown (and probably unwanted) by
the user.
- A legitimate program that has been altered by the placement of unauthorised
code within it; this code performs functions unknown (and probably unwanted)
by the user.
- Any program that appears to perform a desirable and necessary function but
that (because of unauthorised code within it that is unknown to the user)
performs functions unknown (and definitely unwanted) by the user.
The Trojan Horse got its name from the old mythical story about how the
Greeks gave their enemy a huge wooden horse as a gift during the war. The
enemy accepted this gift and they brought it into their kingdom, and during
the night, Greek soldiers crept out of the horse and attacked the city,
completely overcoming it.
3.How Do Trojans Work?
--------------------
Trojans come in two parts, a Client part and a Server part. When the victim
(unknowingly) runs the server on its machine, the attacker will then use the
Client to connect to the Server and start using the trojan. TCP/IP protocol
is the usual protocol type used for communications, but some functions of the
trojans use the UDP protocol as well. When the Server is being run on the
victim's computer, it will (usually) try to hide somewhere on the computer,
start listening on some port(s) for incoming connections from the attacker,
modify the registry and/or use some other autostarting method.
It's necessary for the attacker to know the victim's IP address to connect to
his/her machine. Many trojans have features like mailing the victim's IP, as
well as messaging the attacker via ICQ or IRC. This is used when the victim
has dynamic IP which means every time you connect to the Internet you get a
different IP (most of the dial-up users have this). ADSL users have static
IPs so the infected IP is always known to the attacker and this makes it
considerably easier to connect to your machine.
Most of the trojans use Auto-Starting methods so even when you shut down your
computer they're able to restart and again give the attacker access to your
machine. New auto-starting methods and other tricks are discovered all the
time. The variety starts from "joining" the trojan into some executable file
you use very often like explorer.exe, for example, and goes to the known
methods like modifying the system files or the Windows Registry. System files
are located in the Windows directory and here are short explanations of their
abuse by the attackers:
- Autostart Folder
The Autostart folder is located in C:\Windows\Start Menu\Programs\startup
and as its name suggests, automatically starts everything placed there.
- Win.ini
Windows system file using load=Trojan.exe and run=Trojan.exe to execute
the Trojan
- System.ini
Using Shell=Explorer.exe trojan.exe results in execution of every file
after Explorer.exe
- Wininit.ini
Setup-Programs use it mostly; once run, it's being auto-deleted, which is
very handy for trojans to restart
- Winstart.bat
Acting as a normal bat file trojan is added as @trojan.exe to hide its
execution from the user
- Autoexec.bat
It's a DOS auto-starting file and it's used as auto-starting method like
this -> c:\Trojan.exe
- Config.sys
Could also be used as an auto-starting method for trojans
- Explorer Startup
Is an auto-starting method for Windows95, 98, ME and if c:\explorer.exe
exists, it will be started instead of the usual c:\Windows\Explorer.exe,
which is the common path to the file.
Registry is often used in various auto-starting methods. Here are some known
ways:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Info"="c:\directory\Trojan.exe"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Info"="c:\directory\Trojan.exe"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
"Info"="c:\directory\Trojan.exe"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce]
"Info="c:\directory\Trojan.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Info"="c:\directory\Trojan.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Info"="c:\directory\Trojan.exe"
- Registry Shell Open
[HKEY_CLASSES_ROOT\exefile\shell\open\command]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
A key with the value "%1 %*" should be placed there and if there is some
executable file placed there, it will be executed each time you open a
binary file. It's used like this: trojan.exe "%1 %*"; this would restart
the trojan.
- ICQ Net Detect Method
[HKEY_CURRENT_USER\Software\Mirabilis\ICQ\Agent\Apps\]
This key includes all the files that will be executed if ICQ detects Internet
connection. As you can understand,this feature of ICQ is very handy but it's
frequently abused by attackers as well.
- ActiveX Component
[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\KeyName]
StubPath=C:\directory\Trojan.exe
These are the most common Auto-Starting methods using Windows system files, and
the Windows registry.
4.Trojans Variations
------------------
There are so many variations out there, it will be hard to list and describe
each and every one of them, but most are a combination of all the trojan
features you will read about below, or have many other functions still not,
and probably will never be known to the public.
Remote Access Trojans
These are probably the most publicly used trojans,just because they give the
attackers the power to do more things on the victim's machine than the victim
itself, while standing in front of the machine. Most of these trojans are
often a combination of the other variations you'll read below. The idea of
these trojans is to give the attacker a COMPLETE access to someone's machine,
and therefore access to files, private conversations, accounting data, etc.
Password Sending Trojans
The purpose of these trojans is to rip all the cached passwords and also look
for other passwords you're entering then send them to a specific mail address,
without the user noticing anything. Passwords for ICQ, IRC, FTP, HTTP or any
other application that require a user to enter a login+password are being sent
back to the attacker's e-mail address, which in most cases is located at some
free web based e-mail provider. Most of them do not restart when Windows is
loaded, as the idea is to gather as much info about the victim's machine as
passwords, mIRC logs, ICQ conversations and mail them; but it depends on the
needs of the attacker and the specific situation.
Keyloggers
These trojans are very simple.The only one thing they do is to log the
keystrokes of the victim and then let the attacker search for passwords or
other sensitive data in the log file. Most of them come with two functions
like online and offline recording. Of course they could be configured to
send the log file to a specific e-mail address on a daily basis.
Destructive
The only function of these trojans is to destroy and delete files. This makes
them very simple and easy to use. They can automatically delete all your core
system files (for example: .dll, .ini or .exe files, possibly others) on your
machine. The trojan is being activated by the attacker or sometimes works like
a logic bomb and starts on a specific day and at specific hour.
Denial Of Service (DoS) Attack Trojans
These trojans are getting very popular these days, giving the attacker power
to start DDoS if having enough victims of course. The main idea is that if you
have 200 ADSL users infected and start attacking the victim simultaneously,
this will generate a LOT of traffic (more then the victim's bandwidth, in most
cases) and its the access to the Internet will be shut down. WinTrinoo is a
DDoS tool that has become really popular recently, and if the attacker has
infected many ADSL users, major Internet sites could be shut down as a result,
as we've seen it happen in the past few months.
Another variation of a DoS trojan is the mail-bomb trojan, whose main aim is
to infect as many machines as possible and simultaneously attack specific
e-mail address/addresses with random subjects and contents which cannot be
filtered.
Proxy/Wingate Trojans
Interesting feature implemented in many trojans is turning the victim's
computer into a proxy/wingate server available to the whole world or to the
attacker only. It's used for anonymous Telnet, ICQ, IRC, etc., and also to
register domains with stolen credit cards and for many other illegal
activities. This gives the attacker complete anonymity and the chance to do
everything from YOUR computer and if he/she gets caught the trace leads back
to you.
FTP Trojans
These trojans are probably the most simple ones and are kind of outdated as
the only thing they do is to open port 21(the port for FTP transfers) and
let EVERYONE connect to your machine or just the attacker. Newer versions
are password protected so only the one that infected you may connect to your
computer.
Software Detection Killers
There are such functionalities built into some trojans, but there are also
separate programs that will kill ZoneAlarm, Norton Anti-Virus and many other
(popular anti-virus/firewall) programs, that protect your machine. When they
are disabled, the attacker will have full access to your machine, to perform
some illegal activity, use your computer to attack others and often disappear.
Even though you may notice that these programs are not working or functioning
properly, it will take you some time to remove the trojan, install the new
software, configure it and get back online with some sense of security.
I would like you to look at a list created by SnakeByte (nice work dude!):
http://www.snake-basket.de/e/AV.txt
Check it out and you will get my point how easily these programs could be
disabled. It's a list of Anti-Virus detection software with its Window Names,
associated files and many more things that attackers found as a way to disable
certain protection software. I've seen only several anti-trojan packages that
let the user specify another location of the program (installation) files,
different from the default one, also Window names and many other features that
will make it harder for the attacker to disable the software.
5.The Future Of Windows Trojans
-----------------------------
Windows users will always be targets of malicious attackers because most of
them don't know the real meaning of the word security, and think that some
firewall is the only solution they need for protection but they actually don't
have a clue how it works, or how to configure it properly. Windows Trojans
will be a big security problem in the future and I'm sure attackers realise
that, and many more unique functions will be implemented into their trojans
but will mostly be used for the attacker's private purposes. Programmable or
scriptable "automated hacking" functions will be used to solve various
attacker's problems starting from anonymous port scanning and going up to
Distributed Denial Of Service Attacks(DDoS). A recommended resource related to
the subject is
http://staff.washington.edu/dittrich/misc/ddos/
How about distributed cracking of password files like on all of these contests
around the world but in that case a network created by attacker/attackers for
their own purposes? Has anyone ever thought of "spamming" function, built into
trojans, similar to all of these spam programs out there, crawling around the
Internet, searching for e-mails? And these are just small examples, but trust
me, there are much more advanced features, built into Windows Trojans, that
probably will never be released to the public.
At this year's Defcon the security company SensePost made a demonstration with
a trojan, called Setiri, bypassing all the firewalls and IDS's giving access
to the attacker even the machine was in a restricted environment. More info is
available at:
http://www.computercops.biz/modules.php ... e&sid=1321
6.How Can I Get Infected?
-----------------------
A lot of people out there can't differ various ways of infection just because
in their minds the only way of getting infected is by downloading and running
server.exe and they will never do it as they say. As you'll read here, there
are many more ways for malicious attackers to infect your machine and start
using it for illegal activities. Please take all of these topics I'm reviewing
here really seriously; read them carefully and remember that prevention is way
better than the cure!
6.1 ICQ
6.2 IRC
6.3 Attachments
6.4 Physical Access
6.5 Browser And E-mail Software Bugs
6.6 Netbios(FileSharing)
6.1 Via ICQ
People don't understand that they can also get infected while talking via ICQ
or any other Instant Messenger Application. It's all risky when it's about
receiving files no matter from who, and no matter from where.
Believe it or not, there are still guys out there, using really old versions
of ICQ and it's all because they can see the IP of the person they're talking
to. The older versions of ICQ had such functionality and it was useful for
everyone capable of using winnuke and other DoS tools, but really how hard it
is to click with the mouse? These people are often potential victims of
someone that is more knowledgeable on Windows Trojans and takes advantage of
their old ICQ versions.
Let's review various ways of getting infected via ICQ:
- You can never be 100% sure who's on the other side of the computer at the
particular moment. It could be someone that hacked your friend's ICQ UIN
(Unique Identification Number)and wants to spread some trojans over his/her
friends. You'll definitely trust your best dude Bob if he offers you
something interesting, but is it really Bob on the other side?
- Old versions of ICQ had bugs in the WebServer feature, that creates a site
on your computer, with your info from the ICQ database. The bug consists in
that the attacker can have access to EVERY file on your machine and if you
read the previous sections carefully and know the auto-start methods, you'll
probably realise what could happen if someone has access to your win.ini or
other system file, namely a trojan installed in a few minutes.
- Trojan.exe is renamed like Trojan....(150 spaces).txt.exe, icon changed to a
real .txt file and this will definitely get you infected. This bug must be
fixed in the newer versions for sure.
No matter which Instant Messenger Application you're using, you could always
get yourself infected by certain program bug you never had the chance to hear
about, and never took care of checking for newer versions of the application,
also when it's about receiving files no matter where, and no matter from who,
take that very seriously and realise the dangers of your naivety.
6.2 Via IRC
So many people LIVE on IRC and this is another place where you can get
yourself infected. Trust is vital no matter what you're doing. No matter who
is sending you files, pretending to be free porn archive, software for "free
internet", hacking Hotmail program, DO NOT get any of these files. Newbies are
often targets of these fakes, and believe me, many people are still newbies
about their security. Users get infected from porn-trade channels, and, of
course, warez channels, as they don't think about the risk, but how to get
free porn and free programs instead.
Here are several scenarios of you getting infected while using IRC:
- You're talking with someone, a "girl" probably, have great time and, of
course, you want to see the person you're talking to. You ask for a picture
or the "girl" offers you her pictures and I'm sure you'll definitely want to
see them. The "girl" says that she has just created her first screensaver,
using some known free or commercial software to do this, and offers it to
you, but how about if "she" mentions several pictures are naked ones?! You
have been talking to "her" for a week or so, you get this screensaver.exe,
you run it and, yeah, VERY nice pics, some are naked and she didn't lie to
you so nothing bad or suspicious has happened BUT think again what really
has happened!
- Trojan.exe could also be renamed into Trojan.scr like a screensaver
extension and will again run properly when you execute it so pay attention
about these file extensions.
- Trojan.exe is being renamed like Trojan....(150 spaces).txt.exe you'll get
the file over IRC in the DCC it will appear as .TXT and you won't get
worried about anything, run it and get yourself infected again. In all of
these examples the icon of the file is changed, of course, because it needs
to be the same icon as a normal .TXT and this fools victims very often.
Most people don't notice in their Explorer that the Type of the file is
Application BUT with a .TXT icon. So BEFORE you run something, even if it's
with a .TXT icon, check its extension and make sure it's really a text file.
6.3 Via Attachments
I'm always amazed how many people got themselves infected by an attachment,
sent into their mailboxes. Most of these users are new to the Internet and are
pretty naive. When they receive a mail,containing an attachment, saying they
will get free porn, free Internet access etc., they run it without completely
understanding the risks for their machines. Check the following scenario: you
know your friend Alex is a very skilled Visual Basic programmer. You also know
he's coding his latest program but you're curious what it is all about, and
you wait for an e-mail from him with the attachment when he finishes coding
the application. Yeah, but the person targeting YOU also knows that. The
attacker also knows your friend's e-mail address. Then the attacker will
simply code some program or get some freeware one, use some relaying mail
server to fake the e-mail's FROM field and make it look like your friend's
one; Alex's e-mail address is alex@example.com so the attacker's FROM field
will be changed to alex@example.com and, of course, it will include the
TROJANED attachment... You'll check your mail, see that Alex finally got his
program ready and sent it, you'll download and run it without thinking that it
might be a trojan or something else, because, hey, Alex wouldn't do something
like that to me, he's my friend, and you'll get yourself infected.
Information Is Power! Just because the attacker knew you were waiting for some
particular file, he found Alex's e-mail address and got you infected... the
right moment assumes importance here. And it all happened just because you
were naive, just because you saw alex@example.com in the FROM field, and just
because you didn't check the mail headers to see that the mail came from some
.jp mail server relaying e-mails and, has been used from spammers for several
months.
Many people got themselves infected by the famous "Microsoft Internet Explorer
Update" sent directly to their mailboxes, by the nonexistent Microsoft Updates
Staff. I understand you felt great because Microsoft are paying attention
especially to you, and sent you the latest updates, but these "updates" are
definitely trojans. Microsoft will NEVER send you updates of their software
via e-mail no matter you see the FROM field is updates@microsoft.com and as
you've noticed in the previous example the FROM field could and IS faked. If
you ever notice some mail in your mailbox with subjects like "Microsoft IE
Update" and such, delete WITHOUT viewing or reading the e-mail, because some
E-Mail clients like Outlook Express and others, have bugs that automatically
execute the file being attached in the e-mail WITHOUT you even touching it. As
you can imagine this is a extremely dangerous problem that requires you to be
always up to date with the latest version of any software you're using.
6.4 Physical Access
Physical access is vital for your computer's security. Imagine what can an
attacker do while having physical access on your machine, and let's not
mention if you're always connected to the Internet and leave the room for
several minutes... long enough to get you infected. Here I'll point you
several scenarios, often used by attackers to infect your computer while
they're having physical access to your machine. There are some very smart
people out there that keep thinking of new ways of getting physical access
to someone's computer. Here are some tricks that are interesting:
- Your "friend" wants to infect you with a trojan and he/she has physical
access to your machine. Let's say you were at home surfing the net,
chatting or whatever. Suddenly your "friend" asks you for a glass of
water, knowing that you'll go in another room and will be away for 1 or
2 minutes. While you do that he/she takes out a diskette of the pocket
and infects your unprotected PC. You came back and everything is OK
because your "friend" is doing exactly the same thing before you left
...surfing the net.
- The next example is when 2 guys want to take revenge on you cause of
something and are supporting each other to accomplish the task. Again you
are at home with your "friend", surfing, chatting, whatever you're doing;
suddenly the telephone rings and a "friend" of yours wants to speak with
you for something that is really important. He/she (it's better to be she
in this case) asks "Is there anyone around you? If so,please move somewhere
away from him/her(after knowing it is him or her,of course). I don't want
anyone to listen what I'm going to tell you". The victim is again lured away
from the computer, leaving the attacker to do whatever he/she wants on the
target computer.
- Other approaches like the previous ones might be sudden ring on the bell, as
well as other variations of phone calls and conversations leaving the
attacker alone with the victim's computer. There are so many other possible
approaches; just think for a while and you'll see what I mean and how easily
you could be tricked, and it's because you're not suspicious enough when it
is about your sensitive computer data.
- Another way of infecting while having physical access is the Auto-Starting
CD function. You've probably noticed that when you place a CD in your CDROM,
it automatically starts with some setup interface; here's an example of the
Autorun.inf file that is placed on such CD's:
[autorun]
open=setup.exe
icon=setup.exe
So you can imagine that while running the real setup program a trojan could
be run VERY easily, and as most of you probably don't know about this CD
function they will get infected and won't understand what happened and how
it's been done. Yeah, I know it's convenient to have the setup.exe autostart
but security is what really matters here, that's why you should turn off the
Auto-Start functionality by doing the following:
Start Button->Settings->Control Panel->
System->
Device Manager->CDROM->Properties->Settings
and there you'll see a reference to Auto Insert Notification. Turn it off
and you won't have any problems with that function anymore.
I know MANY other variations of physical access infections but these are the
most common ones so pay attention and try to make up several more by yourself.
When the victim IS connected to the Internet:
Here we have many variations; again, I'll mention the most common ones. While
the attacker is having physical access he/she may download the trojan.exe,
using various ways just by knowing how various Internet protocols work.
- A special IRCbot known only to the attacker is staying in IRC with the only
function to DCC the trojan.exe back to the attacker whenever he/she messages
the bot with a special command. The victim will probably be away from the
computer.
- The attacker wants to download some specific software like new version of
some programs infected with trojan(s), of course, and visit some URL, known
to him/her only, and download the trojan.
- The attacker pretends he/she wants to check his/her (web based) mail (for
example, at Yahoo! or HotMail) but in fact has the trojan.exe stored in his/
her mailbox and just downloads and executes the file, hereby infecting the
computer. The mail service is used as a storage area, in this case.
There are many more ways of infecting the victim while connected to the Net,
as you can imagine. Any of these examples will succeed but it all depends on
the victim's knowledge of the Internet and how advanced his/her skills are,
so the attacker needs to check these things somehow before doing any of these
activities I pointed here. After that, the attacker will be able to choose
the best variant for infecting the victim and doing the job.
6.5 Browser And E-mail Software Bugs
Users do not update their software versions as often as they should be, and a
lot of the attackers are taking advantage of this well known fact. Imagine you
are using an old version of Internet Explorer and you visit a (malicious) site
that will check and automatically infect your machine without you downloading
or executing any programs. The same scenario goes when you check your E-mail
with Outlook Express or some other software with well known problems, again
you will be infected without downloading the attachment. Make sure you always
have the latest version of your Browser and E-mail Software, and reduce the
ways of these variations to minimum. Here are some links about Browser and
E-mail Software bugs, check them out and understand how dangerous these bugs
are, and it's all because of you using an old version of the software.
http://www.guninski.com/browsers.html
http://www.guninski.com/netscape.html
6.6 Netbios(File Sharing)
If port 139 on your machine is opened,you're probably sharing files and this
is another way for someone to access your machine, install trojan.exe and
modify some system file, so it will run the next time you restart your PC.
Sometimes the attacker may use DoS(Denial Of Service Attack) to shut down
your machine and force you to reboot, so the trojan can restart itself
immediately. To block file sharing in WinME version, go to:
Start->Settings->Control Panel->Network->File And Print Sharing
and uncheck the boxes there. That way you won't have any problems related to
Netbios abuse.
7.Fake Programs
-------------
Imagine a Freeware SimpleMail program that's very suitable for your needs, and
very handy with its features like address book, option to check several POP3
accounts and many other functions that make it even better then your E-mail
client and the best thing for you is that it's free. You use ZoneAlarm or any
other similar protection software, and mark the program as a TRUSTED Internet
server so none of your programs will ever bother you about that program as you
are using it probably every day because it's working very well, no problems
ever occurred, you're happy, but a lot of things are going in the background.
Every mail you send and all your passwords for the POP3 accounts are being
mailed directly into the attacker's mailbox without you noticing anything.
Cached passwords and your keystrokes could be also mailed and the idea here is
to gather as much info as possible and send it to the attacker. This info
includes credit card numbers, passwords for various applications and many
other things.
In some cases the attacker may have complete access to your machine but it
depends on his/her ideas about the hidden program's functions. When sending
e-mails and using port 25 or 110 for POP3, these could be used for connections
from the attacker's machine (not at home, of course, but again from another
hacked one) to connect and use the hidden functions he/she implemented in the
Freeware SimpleMail. The attacker's idea here is to offer you a program that
requires a connection to be established with some server; let's say at the top
of the SimpleMail there's a banner that's auto-refreshing every few minutes,
because the programmer "needs to pay the bills too" as he said in the About
section, so nothing seems suspicious to you as it's a normal thing, and your
logical conclusion is completely right as the only way for that guy to keep
offering this cool freeware program for free is to use banners. You've already
marked the program as TRUSTED so the attacker can have complete access to your
machine because he/she fooled you into thinking it's a TRUSTED program. Even
if you notice some connection to your machine on some strange port, you won't
consider this as a suspicions event, as the banners section needs to get these
banners from somewhere, and this is the place your machine is connected all
the time to keep them refreshing.
The only thing the attacker needs is creativity, and most of them do have it.
Think of a fake AudioGalaxy (software for mp3's sharing) but, of course, with
a different name. The attacker would create it, will free 15GB disk space on
his machine and place a large archive of mp3's...then, of course, the same
will be done on several other machines to fool you that you are downloading
from other people located all over the world, but it's not necessary as the
program's interface may never show you where you're actually downloading the
mp3's from. The software will again be backdoored as in the previous example,
and will get thousands of naive users, probably using ADSL connections,
infected.
Fake programs that have hidden functions, often have professional looking web
sites, links to various anti-trojan software mentioned as affiliates, and make
you trust the site; readme.txt is included in the setup and many other things
to fool you it's a trusted one. Pay attention to freeware tools you download,
consider them extremely dangerous and a very useful and easy way for attackers
to infect your machine with a Trojan.
8.Untrusted Sites And Freeware Software
-------------------------------------
A site located at some free web space provider or just offering some programs
for illegal activities can be considered as untrusted one. As you know, there
are thousands of "hacking/security" archives on these free web space providers
like Xoom, Tripod, Geocities and many many others. These sites have archives
full with "hacking" programs, scanners, mail-bombers, flooders and many other
tools. Often several, if not all of these programs are infected by the guy who
created the site. It's highly risky to download any of the programs and the
tools located on such untrusted sites; no matter which software you use are,
you ready to take the risk? There are some untrusted sites, looking REALLY
professional and having huge archives, full with Internet related software,
feedback form, links to other popular sites. I think if you take some time,
look deeper, scan all the files you download you can decide on your own
whether the site you are downloading your software from is a trusted or an
untrusted one.
Software like mIRC, ICQ, PGP or any other popular software MUST be downloaded
from its original (or official dedicated mirror site) and not from any of
these I told you about. Sometimes such sites claim there's a new version of,
let's say, mIRC 7.0, and you know your current version is 6.0 and, yeah, it's
handy to click on the URL and download the .exe in 1 minute and take advantage
of the latest version, but will definitely get yourself infected. A possible
variation of this method will again be claiming for a new version, BUT the
site would include info on nonexistent security bugs, found in the previous
one (which is of course the latest you have), and again it is handy for you to
download it, instead of visiting mIRC's main site, and see if there is really
an updated version or check for any of these security bugs you've read about
on the fake site.
Webmasters of well known Security Portals, that have HUGE archive with various
"hacking" programs, should be responsible for the files they provide and OFTEN
scan them with Anti-Virus and Anti-Trojan software to guarantee their visitors
download "free of trojans and viruses". A known method is that attackers send
some program created by them, let's say a UDP flooder, to the webmaster like a
submission for the archive, but infect the program with some trojan and later
have visitors downloading the program and getting themselves infected. Some
attackers may use the webmaster's irresponsibility and infect their files, and
have the site distribute the trojan. I know of another story regarding this
problem. It's about a Gaming Magazine that used to include a CD with free demo
versions of the latest games in each new edition. The editors made a contest
to find new talents and give the people programming games the chance to
popularise their productions by sending them to the Editors. An attacker
infected his game with a new and private trojan and sent it to the Magazine.
In the next edition the "game" appeared on the CD and you can imagine the
chaos that set in. And it's all because of the Editors, having not so much
knowledge on the topic and as I've told you, in the old days Anti-Virus
software were detecting only a small part of the public trojans (and what
about all the private ones). In this particular case they were using only an
Anti Virus scanner to protect their readers from such attacks. Webmasters and
everyone having some sort of software archive on his/her portal, MUST scan it
very often, and before adding a new file it should be well examined; if it's
suspicious in any way, it must be sent to your software detection labs for
further analysis. Do care about your visitors/readers if you want them to care
about you.
Freeware programs could be considered suspicious and extremely dangerous, due
to the fact that it's a very easy and useful way for the attacker to infect
your machine with some freeware program. No matter how suitable you find the
program, remember that "free is not always the best" and it's very risky to
use any of these programs. My advice is: before using Freeware program, do
search for some reviews on it, check popular search engines, and try to look
up for some info about it. If you find any reviews written by respected sites,
that means they've used and tested it and the chance of infection is hereby,
minimised. If no reviews or comments about the software are found via the
search engines, then it may be highly risky to start using it.
9.How Are They Detecting My Internet Presence?
--------------------------------------------
People new to the Internet often ask this question as they can't understand
why someone will want to attack especially them, because they never did any
harm to anyone and never did something that might get them into trouble.
While reading the previous sections, I hope you understood that sometimes
you only need to visit a web site with your unpatched browser and get yourself
infected.
I will explain several scenarios on how attackers may discover your Internet
presence:
- When visiting a web page,the attacker might have created a script that will
automatically check your Browser for known bugs, and if any are detected,
install a trojan on your machine or notify the attacker to have a deeper
look. Make sure you're always using the latest version of your Browser for
maximal protection. Check for (security) patches and apply these often!
- When joining an IRC channel, an IRC bot might be configured to scan everyone
joining for specific trojan ports opened or FileSharing (Netbios) enabled.
If the attacker is smart, the script will scan you several minutes after you
join the channel and, of course, use an IP number not belonging to anyone in
the channel.
- Attackers often attempt IP blocks scanning, looking default trojan ports and
of course FileSharing(Netbios). After infection, your machine could also be
used for such scans, as well as an IRC bot, scanning those joining some big
and full with people IRC channel.
These are some of the most common ways attackers use to search for new victims,
suitable for their illegal activities. If someone is targeting especially you,
the attacker won't be using any of these methods I reviewed above; instead your
Browser version will be found as well as the Operation System you're using, and
the attacker will make a personal contact with you via IRC, ICQ, etc., and fool
you somehow and get you infected.
10.What Is The Attacker Looking For?
---------------------------------
Some of you may think that trojans are used for damages only. Well, they can
also be used for spying on someone's machine and taking a lot of private and
sensitive information (industrial espionage). The attacker's interests would
include but are not limited to the following:
- Credit Card Information (often used for domain registration, shopping with
your credit card)
- Any accounting data (E-mail passwords, Dial-Up passwords, WebServices
passwords, etc.)
- Email Addresses (Might be used for spamming, as explained above)
- Work Projects (Steal your presentations and work related papers)
- Children's names/pictures, Ages (pedophile attacker?!)
- School work (steal your papers and publish them with his/her name on it)
I'll mention again several scenarios about the attacker's mode of thinking:
- Once infected, your computer might be used as a Warez Archive. No matter how
much or little free disk space you have, you'll probably have enough for the
attacker's needs. He/she won't use all of your bandwidth; there will be some
limit for connections to your computer, so you'll still be able to do your
work without knowing that your computer is used as a pirated software FTP
Server and it is known to people worldwide who keep downloading software
from YOU.
- Kiddie-Porn traders will also use your computer for storing their archives
and again turning your machine into a well known place for traders of nasty
and above all illegal pictures. You'll again do your work and have no clue
there are illegal activities going in your computer.
- The attacker might just want to have fun with you, open/close the CD tray,
play with your mouse, annoy you somehow; that's stupid and useless but a lot
of people do it.
- Your computer might be used for other illegal purposes like the attacker's
usage of your IP address to hack, scan, flood, infiltrate other machines on
the Internet; so the victims will see your machine is doing it, and this
will definitely get you in trouble.
11.Intelligence With Trojans
-------------------------
Think for a while about how much your life depends on your computer, your ICQ,
your chat program, your e-mail address and think how vulnerable your life is
just because you're infected with a Trojan Horse. They can, and they have been
used for intelligence for a very long time. Just by reading your e-mails,
keeping track of your contacts, reading your private conversations, the web
sites you visit, ICQ history, mIRC log files with your private conversations
and a log of everything you do online, a psychological profile could be
created in several hours (depends of the skills of course) and your life, mode
of thinking, reactions on specific future situations and needs will be
revealed to some geek, wanting to recruit and/or manipulate you. This is food
for thought and another topic, but just think how a combination of psychology,
social engineering and computer security knowledge makes you a really powerful
guy. And remember that people reveal their REAL personalities, wishes, mode of
thinking, interests only when they think nobody is watching them...
12.Trojan Ports
------------
Trojans use specific ports to communicate with the client. In the old days the
well known trojan ports were mostly used, but today it's possible to change
the port every time the trojan is restarted. Here is a link to the best and
probably including all of the public trojans Ports List I've come across.
http://www.simovits.com/trojans/trojans.html
13.How Do I Know I'm Infected?
---------------------------
Sometimes you think it's normal Windows behaviour when there are 500 MB or so
missing on your HDD, because some software is using it, or you have installed
a game you forgot about and many other reasons but not the real one. Here are
some things which are very suspicious, and no matter how much your Anti-Virus
software tells you that you aren't infected, dig a little deeper and see what
really happened. One thing that will help you is to know the main features of
the public trojans, so you'll be able to react if you notice such activity on
your PC. I have included links to various Trojan Databases that you should
visit if you want to know the main features of the public ones.
- Its normal to visit a web site and several more pop-ups to appear with the
one you've visited. But when you do completely nothing and suddenly your
browser directs you to some page unknown to you, take that serious.
- A strange and unknown Windows Message Box appears on your screen, asking
you some personal questions.
- Your Windows settings change by themselves like a new screensaver text,
date/time, sound volume changes by itself, your mouse moves by itself,
CD-ROM drawer opens and closes.
Please note that most advanced attackers will just spy on you and use your
infected machine for some specific reason, and not perform any of the above
"tricks" so as not to cause any suspicious activity on the target system (as
this would probably mean they could get easily detected). Someone that just
wants to have fun with you is more likely to perform these actions.
14.Anti-Virus (AV) Scanners
-------------------
In the old days Virus Scanners used to detect only viruses and just a small
part of the public trojans on the Internet. Realising how dangerous and
popular Trojans are becoming today most, if not all of these scanners detect
probably all of the public ones out there. As always people, think they are
safe and secure when using Virus Scanner but it's a false sense of security.
This type of software relies mainly on "signatures" of each trojan's server
executable and also its common auto-starting methods, but that is not the
perfect solution by far for protection yourself against trojans, as they use
many other methods to hide inside the machine, most of which are undetected
by Anti-Virus Software. When trojans became a big security breach, specific
Anti-Trojan packages were released to the public and it was necessary for the
AVs to start detecting not only viruses, but also trojans if they wanted new
users. As a result, most of them became really advanced trojan scanning and
detection systems, but for your maximal protection it's recommended to use
both Anti-Virus and Anti-Trojans software.
Public trojans appear online almost every day and the detection software is
updated every day for maximal protection of its customers. One very big
problem is that the users do not update their signature files as often as they
should be, thus having detection software that's not detecting several more
trojans or viruses. Users MUST update their software's signature files every
day, and it will take them only several minutes. Each and every time a new
file is downloaded, it MUST be scanned BEFORE being opened with Anti-Virus and
Anti-Trojan software. If you think the file is suspicious due to some reasons,
do NOT run it, but send it to your detection software labs for analysis.
15.Anti-Trojan Software
--------------------
Here are reviews of the most popular Anti-Trojan packages. The list also
includes various applications (freeware) to help you monitor your computer for
ongoing Trojan activities. I suggest you visit the site of every product and
decide which one best fits to your needs. Check the links section at the end
of the paper to see various sites, providing reviews of the software below.
-- TDS-3 --
Trojan Defence Suite (TDS) is a indispensable, must-have software package for
protection against trojans. It has many unique functions never seen in other
Anti-Trojan packages. The program has really advanced features and if you're a
newbie, it will probably take some time before you are able to use the software
at its full capacity (read the excellent help files).
You can get TDS from http://tds.diamondcs.com.au/
-- LockDown2000 --
This is really good Anti-Trojan package that detects a LOT of trojans and other
known as "hacking tools" programs. It will help you monitor your system files
for changes, processes and registry modification. More info at its home page.
You can get LockDown2000 from http://www.lockdown2000.com
-- TFAK5 --
Trojans First Aid Kit is a trojan-scanner developed by SnakeByte. It has many
other unique features; it could be used as a Client for various public trojans
as well.
Download TFAK5 from http://www.snake-basket.de/tfak/TFAK5.zip
-- Trojan Remover --
Anti-Trojan software detecting 5468 trojans/worms (including variants) as at
15th August 2002. Systems files and registry monitoring functions are also
implemented. More info at its home page:
http://www.simplysup.com/tremover/details.html
-- Pest Patrol --
A tool that scans for trojans as well as programs known as "hacking tools" and
spyware. More info at its official page:
http://www.safersite.com/
-- Anti-Trojan 5.5 --
Trojans detection package that is able to remove most of the public trojans out
there. More info at its official page:
http://www.anti-trojan.net
-- Tauscan --
Trojan scanner that has unique features and is a must have. It's also able to
detect new and never released to the public trojans. More info at its official
page:
http://www.agnitum.com/products/tauscan/
-- The Cleaner --
Very popular Anti-Trojan software, known by everyone. Check its home page at:
http://www.moosoft.com/
-- PC Door Guard --
Trojan detection software, detecting a lot of trojans, and a monitor of files
and directories is also included. More info at:
http://www.trojanclinic.com/pdg.html
-- Trojan Hunter --
Trojan detection package with a lot of functions. It's very handy.
More info at http://www.mischel.dhs.org/trojanhunter.jsp
-- LogMonitor --
Log Monitor is a file and directory monitoring tool. The program periodically
checks a selected file's modification time and executes an external program if
file's time was changed or not changed. For directories it handles such events
as files change, addition or removal. I recommend this tool as it's vary handy
and will help you a lot.
Home page: http://logmon.bitrix.ru/logmon/eng/
-- PrcView --
PrcView is a freeware process viewer utility that shows detailed information
about running processes. This information includes such details as the create
date/time, the version and full path for each DLL used by a selected process,
a list of all threads, memory blocks and heaps. PrcView also allows you to
kill and attach a debugger to a selected process. PrcView runs on both Windows
95/98 and Windows NT platforms and includes Windows and command-line versions
of the program.
Get PrcView from http://www.xmlsp.com/pview/prcview.htm
-- XNetStat --
GUI based netstat tool for Windows. It will help you monitor you machine for
open ports. Download it from:
http://packetstormsecurity.org/Win/netstat.zip
-- ConSeal PC FIREWALL --
A really good firewall for advanced users using Windows having basic knowledge
of TCP/IP and other protocols; this software will help you to secure your PC a
lot. It has some major advantages over other Win based firewalls. For the full
range of specifications, check its official web page at:
http://www.consealfirewall.com/
16.After You Clean Yourself
------------------------
Your machine has been compromised and probably a lot of sensitive data stolen,
files have been modified and illegal activities have been preformed on your
computer. Here I'll give you recommendations about what to do after you are
100% clean of trojans.
- Accounting Data such as ISP passwords, ICQ, mIRC, FTP, web site passwords,
e-mail address passwords are definitely known to the attacker. Contact your
ISP about changing your dial-up password if you're using such connection.
Immediately change your ICQ, mIRC passwords of course if they're still the
same. (Often attackers won't change any of your accounting data to fool you
everything is OK so there is a big chance you will still be able to recover
from the compromise). Change your web based e-mail passwords and do check
your information stored there, as password retrieval services for various
e-mail providers such as Yahoo and Hotmail use this info combined with a
"Secret Question" for password retrieval. Attackers often change the info,
the answer to the secret question and many other things that will get them
easily back into your mailbox, whether you've changed your pass or not.
- If you're taking advantage of the handy Address Book feature in your e-mail
service, and have a list full of e-mails of friends, colleagues, etc. there
is a real possibility that the attacker has sent them a trojan and possibly
infected them too. Mail all of these people and ask them about receiving any
files from your mailbox, inform them someone else might know your e-mail
password so they'll be able to take appropriate actions like checking their
machines for Trojans. Do the same with the people from your ICQ contact list
as they might be targeted too.
- Check your HDD for abnormal activities like a lot of free space missing etc.
Search for warez software and, as I mentioned, kiddie-porn archives.
- Think for a while about the sensitive information you had on your machine
before the compromise, and if you are absolutely sure the attacker may know
it too, then take appropriate action, like informing the any institutions
the sensitive data belong to.
- Scan your machine with Anti-Virus scanner, as the attacker could have placed
some virus or infected macro documents on your machine to do destructive
things even there's no access for him/her to your machine.
- Monitor your processes BEFORE and AFTER connecting to the Internet, as some
trojans start when they detect Internet connection. Don't get fooled again,
be very suspicious.
17.Online Scanning Services
------------------------
These services are very popular these days and they are very handy for users
who haven't got much knowledge on all of the holes they're checking for, but
wanting to ensure they are protected from all of them. This section is placed
at the end of the paper with a specific reason. If you have read the paper,
you should know a LOT about trojans by now, their principles of working and
detection techniques, therefore you can decide whether these online scanners
are useful or if they give a false sense of safety.
There are several types of Online Scanners: Trojan Scanner, Port Scanner and
Bugs Checker.
- Trojan Scanner
It's using a list with predefined ports, associated with the name of the
trojan responding to its default port, like Girl Friend=21544, and if this
port is in "listening" state on your machine it will inform you that you've
been infected with the GirlFriend Trojan. As you already know, trojans have
functions like changing their default port to ANY of the attacker's choice.
That makes these Trojan Scanners kind of useless, because serious attackers
do change the default port for sure.
- Port Scanner
This service has two options like well-known ports scan and all ports scan.
The first feature is scanning for well known ports, again associated with
the appropriate service related to the port like port 21-FTP, 23-Telnet,
25-SMTP. The second feature is rarely seen on a free one, because of the
bandwidth it would generate to scan all of the 65,535 ports. It will again
associate ports with services like I mentioned above, and if it finds any
unknown ports not associated with any service, it will also report it, like
Port 34525 State:Listening, which means this port is waiting for connections
from the outside.
- Bugs Checker
Its purpose is to check your Browser or your E-mail Software for well known
bugs and security related problems. If any are detected, it will point you
to a site containing the patches for these bugs or a site with the latest
updated versions of the software.
It's strongly recommended to close any other Internet related application on
your machine before being scanned by Online Trojan Scanner and Port Scanner.
You decide which service is best for you, which one will be able to detect
trojan infections on your machine, and which won't; you now know the main
principles and the answers too, I hope. Links to several online scanning
services I know of are included in the Links Section.
18.Advice
------
This is a very useful section, full of tips and advice on how to protect
yourself from trojans using various ways you've already read about, but
summarised here for faster reading and hopefully better understanding.
[01] Never accept a file even it is from some friend. You're never sure who's
on the other side of the computer at the moment. If you really need this
file, let's say some presentation or a work paper, find other ways, like
the phone, and verify the file is from your friend. Yeah it will take you
some time and slow you a bit, but be paranoid about attachments you may
receive and don't ge
extent permitted by applicable law, in no event shall Frame4 Security Systems
be liable for any damages whatsoever, (including, without limitation, damages
for loss of any business profits, business interruption, loss of any business
information, or other pecuniary loss) arising out of the use, or inability to
use any software, and/or procedures outlined in this document, even if Frame4
Security Systems has been advised of the possibility of such damage(s). There
are NO warranties with regard to this information, but the paper may help you
improve your Windows security a lot.
This paper is the property of Frame4 Security Systems, all rights reserved.
Copyright © 1999-2002 Frame4 Security Systems -- http://www.frame4.com/
-------------------------------------------------------------------------------
Author's Notes:
This is the updated version of my paper written a long while ago. During that
time I have seen it on every security/hacking site I came across and I'm glad
you're all placing it in your archives as recommended reading. Now, many more
sections and updates have been added so be sure that you will reading new and
interesting aspects regarding the topic. The paper will answer many questions
people keep asking in general about trojans like "how are attackers infecting
me" and "how to protect from trojans".
If you have any other questions about the topic including ideas, suggestions,
comments, etc., please do not hesitate to express your opinion. If you have a
lot to say on the topic and/or I have missed some aspects then please contact
me and contribute to the next update, and of course full credit will be given
to you and your ideas.
-------------------------------------------------------------------------------
Table of Contents
-----------------
01.What Is This Paper About
02.What Is A Trojan Horse
03.How Do Trojans Work
04.Trojans Variations
-Remote Access Trojans
-Password Sending Trojans
-Keylogging Trojans
-Destructive Trojans
-Denial Of Service (DoS) Attack Trojans
-Proxy/Wingate Trojans
-FTP Trojans
-Detection Software Killers
05.The Future Of Windows Trojans
06.How Can I Get Infected
-Via ICQ
-Via IRC
-Via Attachments
-Via Physical Access
-Via Browser And E-mail Software Bugs
-Via Netbios(File Sharing)
07.Fake Programs
08.Untrusted Sites And FreeWare Software
09.How Are They Detecting My Internet Presence
10.What Is The Attacker Looking For
11.Intelligence With Trojans
12.Trojan Ports
13.How Do I Know I'm Infected
14.Anti-Virus (AV) Scanners
15.Anti-Trojan Software
16.After You Clean Yourself
17.Online Scanning Services
18.Advice
19.Links Section
20.Final Words
-------------------------------------------------------------------------------
1.What is this paper about?
-------------------------
The Complete Trojans Text is a paper about Windows Trojans, how they work,
their variations and, of course, strategies to minimise the risk of infection.
Links to special detection software are included as well as many other topics
never discussed before. This paper is not only intended to be for the average
Internet/Windows user who wants to know how to protect his/her machine from
Trojan Horses or just want to know about their usage, variations, prevention
and future, but will also be interesting for the advanced user, to read
another point of view.
Windows Trojans are just a small aspect of Windows Security but you will soon
realise how dangerous and destructive they could be while reading the paper.
2.What Is A Trojan Horse?
-----------------------
A Trojan horse is:
- An unauthorised program contained within a legitimate program. This
unauthorised program performs functions unknown (and probably unwanted) by
the user.
- A legitimate program that has been altered by the placement of unauthorised
code within it; this code performs functions unknown (and probably unwanted)
by the user.
- Any program that appears to perform a desirable and necessary function but
that (because of unauthorised code within it that is unknown to the user)
performs functions unknown (and definitely unwanted) by the user.
The Trojan Horse got its name from the old mythical story about how the
Greeks gave their enemy a huge wooden horse as a gift during the war. The
enemy accepted this gift and they brought it into their kingdom, and during
the night, Greek soldiers crept out of the horse and attacked the city,
completely overcoming it.
3.How Do Trojans Work?
--------------------
Trojans come in two parts, a Client part and a Server part. When the victim
(unknowingly) runs the server on its machine, the attacker will then use the
Client to connect to the Server and start using the trojan. TCP/IP protocol
is the usual protocol type used for communications, but some functions of the
trojans use the UDP protocol as well. When the Server is being run on the
victim's computer, it will (usually) try to hide somewhere on the computer,
start listening on some port(s) for incoming connections from the attacker,
modify the registry and/or use some other autostarting method.
It's necessary for the attacker to know the victim's IP address to connect to
his/her machine. Many trojans have features like mailing the victim's IP, as
well as messaging the attacker via ICQ or IRC. This is used when the victim
has dynamic IP which means every time you connect to the Internet you get a
different IP (most of the dial-up users have this). ADSL users have static
IPs so the infected IP is always known to the attacker and this makes it
considerably easier to connect to your machine.
Most of the trojans use Auto-Starting methods so even when you shut down your
computer they're able to restart and again give the attacker access to your
machine. New auto-starting methods and other tricks are discovered all the
time. The variety starts from "joining" the trojan into some executable file
you use very often like explorer.exe, for example, and goes to the known
methods like modifying the system files or the Windows Registry. System files
are located in the Windows directory and here are short explanations of their
abuse by the attackers:
- Autostart Folder
The Autostart folder is located in C:\Windows\Start Menu\Programs\startup
and as its name suggests, automatically starts everything placed there.
- Win.ini
Windows system file using load=Trojan.exe and run=Trojan.exe to execute
the Trojan
- System.ini
Using Shell=Explorer.exe trojan.exe results in execution of every file
after Explorer.exe
- Wininit.ini
Setup-Programs use it mostly; once run, it's being auto-deleted, which is
very handy for trojans to restart
- Winstart.bat
Acting as a normal bat file trojan is added as @trojan.exe to hide its
execution from the user
- Autoexec.bat
It's a DOS auto-starting file and it's used as auto-starting method like
this -> c:\Trojan.exe
- Config.sys
Could also be used as an auto-starting method for trojans
- Explorer Startup
Is an auto-starting method for Windows95, 98, ME and if c:\explorer.exe
exists, it will be started instead of the usual c:\Windows\Explorer.exe,
which is the common path to the file.
Registry is often used in various auto-starting methods. Here are some known
ways:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Info"="c:\directory\Trojan.exe"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Info"="c:\directory\Trojan.exe"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
"Info"="c:\directory\Trojan.exe"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce]
"Info="c:\directory\Trojan.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Info"="c:\directory\Trojan.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Info"="c:\directory\Trojan.exe"
- Registry Shell Open
[HKEY_CLASSES_ROOT\exefile\shell\open\command]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
A key with the value "%1 %*" should be placed there and if there is some
executable file placed there, it will be executed each time you open a
binary file. It's used like this: trojan.exe "%1 %*"; this would restart
the trojan.
- ICQ Net Detect Method
[HKEY_CURRENT_USER\Software\Mirabilis\ICQ\Agent\Apps\]
This key includes all the files that will be executed if ICQ detects Internet
connection. As you can understand,this feature of ICQ is very handy but it's
frequently abused by attackers as well.
- ActiveX Component
[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\KeyName]
StubPath=C:\directory\Trojan.exe
These are the most common Auto-Starting methods using Windows system files, and
the Windows registry.
4.Trojans Variations
------------------
There are so many variations out there, it will be hard to list and describe
each and every one of them, but most are a combination of all the trojan
features you will read about below, or have many other functions still not,
and probably will never be known to the public.
Remote Access Trojans
These are probably the most publicly used trojans,just because they give the
attackers the power to do more things on the victim's machine than the victim
itself, while standing in front of the machine. Most of these trojans are
often a combination of the other variations you'll read below. The idea of
these trojans is to give the attacker a COMPLETE access to someone's machine,
and therefore access to files, private conversations, accounting data, etc.
Password Sending Trojans
The purpose of these trojans is to rip all the cached passwords and also look
for other passwords you're entering then send them to a specific mail address,
without the user noticing anything. Passwords for ICQ, IRC, FTP, HTTP or any
other application that require a user to enter a login+password are being sent
back to the attacker's e-mail address, which in most cases is located at some
free web based e-mail provider. Most of them do not restart when Windows is
loaded, as the idea is to gather as much info about the victim's machine as
passwords, mIRC logs, ICQ conversations and mail them; but it depends on the
needs of the attacker and the specific situation.
Keyloggers
These trojans are very simple.The only one thing they do is to log the
keystrokes of the victim and then let the attacker search for passwords or
other sensitive data in the log file. Most of them come with two functions
like online and offline recording. Of course they could be configured to
send the log file to a specific e-mail address on a daily basis.
Destructive
The only function of these trojans is to destroy and delete files. This makes
them very simple and easy to use. They can automatically delete all your core
system files (for example: .dll, .ini or .exe files, possibly others) on your
machine. The trojan is being activated by the attacker or sometimes works like
a logic bomb and starts on a specific day and at specific hour.
Denial Of Service (DoS) Attack Trojans
These trojans are getting very popular these days, giving the attacker power
to start DDoS if having enough victims of course. The main idea is that if you
have 200 ADSL users infected and start attacking the victim simultaneously,
this will generate a LOT of traffic (more then the victim's bandwidth, in most
cases) and its the access to the Internet will be shut down. WinTrinoo is a
DDoS tool that has become really popular recently, and if the attacker has
infected many ADSL users, major Internet sites could be shut down as a result,
as we've seen it happen in the past few months.
Another variation of a DoS trojan is the mail-bomb trojan, whose main aim is
to infect as many machines as possible and simultaneously attack specific
e-mail address/addresses with random subjects and contents which cannot be
filtered.
Proxy/Wingate Trojans
Interesting feature implemented in many trojans is turning the victim's
computer into a proxy/wingate server available to the whole world or to the
attacker only. It's used for anonymous Telnet, ICQ, IRC, etc., and also to
register domains with stolen credit cards and for many other illegal
activities. This gives the attacker complete anonymity and the chance to do
everything from YOUR computer and if he/she gets caught the trace leads back
to you.
FTP Trojans
These trojans are probably the most simple ones and are kind of outdated as
the only thing they do is to open port 21(the port for FTP transfers) and
let EVERYONE connect to your machine or just the attacker. Newer versions
are password protected so only the one that infected you may connect to your
computer.
Software Detection Killers
There are such functionalities built into some trojans, but there are also
separate programs that will kill ZoneAlarm, Norton Anti-Virus and many other
(popular anti-virus/firewall) programs, that protect your machine. When they
are disabled, the attacker will have full access to your machine, to perform
some illegal activity, use your computer to attack others and often disappear.
Even though you may notice that these programs are not working or functioning
properly, it will take you some time to remove the trojan, install the new
software, configure it and get back online with some sense of security.
I would like you to look at a list created by SnakeByte (nice work dude!):
http://www.snake-basket.de/e/AV.txt
Check it out and you will get my point how easily these programs could be
disabled. It's a list of Anti-Virus detection software with its Window Names,
associated files and many more things that attackers found as a way to disable
certain protection software. I've seen only several anti-trojan packages that
let the user specify another location of the program (installation) files,
different from the default one, also Window names and many other features that
will make it harder for the attacker to disable the software.
5.The Future Of Windows Trojans
-----------------------------
Windows users will always be targets of malicious attackers because most of
them don't know the real meaning of the word security, and think that some
firewall is the only solution they need for protection but they actually don't
have a clue how it works, or how to configure it properly. Windows Trojans
will be a big security problem in the future and I'm sure attackers realise
that, and many more unique functions will be implemented into their trojans
but will mostly be used for the attacker's private purposes. Programmable or
scriptable "automated hacking" functions will be used to solve various
attacker's problems starting from anonymous port scanning and going up to
Distributed Denial Of Service Attacks(DDoS). A recommended resource related to
the subject is
http://staff.washington.edu/dittrich/misc/ddos/
How about distributed cracking of password files like on all of these contests
around the world but in that case a network created by attacker/attackers for
their own purposes? Has anyone ever thought of "spamming" function, built into
trojans, similar to all of these spam programs out there, crawling around the
Internet, searching for e-mails? And these are just small examples, but trust
me, there are much more advanced features, built into Windows Trojans, that
probably will never be released to the public.
At this year's Defcon the security company SensePost made a demonstration with
a trojan, called Setiri, bypassing all the firewalls and IDS's giving access
to the attacker even the machine was in a restricted environment. More info is
available at:
http://www.computercops.biz/modules.php ... e&sid=1321
6.How Can I Get Infected?
-----------------------
A lot of people out there can't differ various ways of infection just because
in their minds the only way of getting infected is by downloading and running
server.exe and they will never do it as they say. As you'll read here, there
are many more ways for malicious attackers to infect your machine and start
using it for illegal activities. Please take all of these topics I'm reviewing
here really seriously; read them carefully and remember that prevention is way
better than the cure!
6.1 ICQ
6.2 IRC
6.3 Attachments
6.4 Physical Access
6.5 Browser And E-mail Software Bugs
6.6 Netbios(FileSharing)
6.1 Via ICQ
People don't understand that they can also get infected while talking via ICQ
or any other Instant Messenger Application. It's all risky when it's about
receiving files no matter from who, and no matter from where.
Believe it or not, there are still guys out there, using really old versions
of ICQ and it's all because they can see the IP of the person they're talking
to. The older versions of ICQ had such functionality and it was useful for
everyone capable of using winnuke and other DoS tools, but really how hard it
is to click with the mouse? These people are often potential victims of
someone that is more knowledgeable on Windows Trojans and takes advantage of
their old ICQ versions.
Let's review various ways of getting infected via ICQ:
- You can never be 100% sure who's on the other side of the computer at the
particular moment. It could be someone that hacked your friend's ICQ UIN
(Unique Identification Number)and wants to spread some trojans over his/her
friends. You'll definitely trust your best dude Bob if he offers you
something interesting, but is it really Bob on the other side?
- Old versions of ICQ had bugs in the WebServer feature, that creates a site
on your computer, with your info from the ICQ database. The bug consists in
that the attacker can have access to EVERY file on your machine and if you
read the previous sections carefully and know the auto-start methods, you'll
probably realise what could happen if someone has access to your win.ini or
other system file, namely a trojan installed in a few minutes.
- Trojan.exe is renamed like Trojan....(150 spaces).txt.exe, icon changed to a
real .txt file and this will definitely get you infected. This bug must be
fixed in the newer versions for sure.
No matter which Instant Messenger Application you're using, you could always
get yourself infected by certain program bug you never had the chance to hear
about, and never took care of checking for newer versions of the application,
also when it's about receiving files no matter where, and no matter from who,
take that very seriously and realise the dangers of your naivety.
6.2 Via IRC
So many people LIVE on IRC and this is another place where you can get
yourself infected. Trust is vital no matter what you're doing. No matter who
is sending you files, pretending to be free porn archive, software for "free
internet", hacking Hotmail program, DO NOT get any of these files. Newbies are
often targets of these fakes, and believe me, many people are still newbies
about their security. Users get infected from porn-trade channels, and, of
course, warez channels, as they don't think about the risk, but how to get
free porn and free programs instead.
Here are several scenarios of you getting infected while using IRC:
- You're talking with someone, a "girl" probably, have great time and, of
course, you want to see the person you're talking to. You ask for a picture
or the "girl" offers you her pictures and I'm sure you'll definitely want to
see them. The "girl" says that she has just created her first screensaver,
using some known free or commercial software to do this, and offers it to
you, but how about if "she" mentions several pictures are naked ones?! You
have been talking to "her" for a week or so, you get this screensaver.exe,
you run it and, yeah, VERY nice pics, some are naked and she didn't lie to
you so nothing bad or suspicious has happened BUT think again what really
has happened!
- Trojan.exe could also be renamed into Trojan.scr like a screensaver
extension and will again run properly when you execute it so pay attention
about these file extensions.
- Trojan.exe is being renamed like Trojan....(150 spaces).txt.exe you'll get
the file over IRC in the DCC it will appear as .TXT and you won't get
worried about anything, run it and get yourself infected again. In all of
these examples the icon of the file is changed, of course, because it needs
to be the same icon as a normal .TXT and this fools victims very often.
Most people don't notice in their Explorer that the Type of the file is
Application BUT with a .TXT icon. So BEFORE you run something, even if it's
with a .TXT icon, check its extension and make sure it's really a text file.
6.3 Via Attachments
I'm always amazed how many people got themselves infected by an attachment,
sent into their mailboxes. Most of these users are new to the Internet and are
pretty naive. When they receive a mail,containing an attachment, saying they
will get free porn, free Internet access etc., they run it without completely
understanding the risks for their machines. Check the following scenario: you
know your friend Alex is a very skilled Visual Basic programmer. You also know
he's coding his latest program but you're curious what it is all about, and
you wait for an e-mail from him with the attachment when he finishes coding
the application. Yeah, but the person targeting YOU also knows that. The
attacker also knows your friend's e-mail address. Then the attacker will
simply code some program or get some freeware one, use some relaying mail
server to fake the e-mail's FROM field and make it look like your friend's
one; Alex's e-mail address is alex@example.com so the attacker's FROM field
will be changed to alex@example.com and, of course, it will include the
TROJANED attachment... You'll check your mail, see that Alex finally got his
program ready and sent it, you'll download and run it without thinking that it
might be a trojan or something else, because, hey, Alex wouldn't do something
like that to me, he's my friend, and you'll get yourself infected.
Information Is Power! Just because the attacker knew you were waiting for some
particular file, he found Alex's e-mail address and got you infected... the
right moment assumes importance here. And it all happened just because you
were naive, just because you saw alex@example.com in the FROM field, and just
because you didn't check the mail headers to see that the mail came from some
.jp mail server relaying e-mails and, has been used from spammers for several
months.
Many people got themselves infected by the famous "Microsoft Internet Explorer
Update" sent directly to their mailboxes, by the nonexistent Microsoft Updates
Staff. I understand you felt great because Microsoft are paying attention
especially to you, and sent you the latest updates, but these "updates" are
definitely trojans. Microsoft will NEVER send you updates of their software
via e-mail no matter you see the FROM field is updates@microsoft.com and as
you've noticed in the previous example the FROM field could and IS faked. If
you ever notice some mail in your mailbox with subjects like "Microsoft IE
Update" and such, delete WITHOUT viewing or reading the e-mail, because some
E-Mail clients like Outlook Express and others, have bugs that automatically
execute the file being attached in the e-mail WITHOUT you even touching it. As
you can imagine this is a extremely dangerous problem that requires you to be
always up to date with the latest version of any software you're using.
6.4 Physical Access
Physical access is vital for your computer's security. Imagine what can an
attacker do while having physical access on your machine, and let's not
mention if you're always connected to the Internet and leave the room for
several minutes... long enough to get you infected. Here I'll point you
several scenarios, often used by attackers to infect your computer while
they're having physical access to your machine. There are some very smart
people out there that keep thinking of new ways of getting physical access
to someone's computer. Here are some tricks that are interesting:
- Your "friend" wants to infect you with a trojan and he/she has physical
access to your machine. Let's say you were at home surfing the net,
chatting or whatever. Suddenly your "friend" asks you for a glass of
water, knowing that you'll go in another room and will be away for 1 or
2 minutes. While you do that he/she takes out a diskette of the pocket
and infects your unprotected PC. You came back and everything is OK
because your "friend" is doing exactly the same thing before you left
...surfing the net.
- The next example is when 2 guys want to take revenge on you cause of
something and are supporting each other to accomplish the task. Again you
are at home with your "friend", surfing, chatting, whatever you're doing;
suddenly the telephone rings and a "friend" of yours wants to speak with
you for something that is really important. He/she (it's better to be she
in this case) asks "Is there anyone around you? If so,please move somewhere
away from him/her(after knowing it is him or her,of course). I don't want
anyone to listen what I'm going to tell you". The victim is again lured away
from the computer, leaving the attacker to do whatever he/she wants on the
target computer.
- Other approaches like the previous ones might be sudden ring on the bell, as
well as other variations of phone calls and conversations leaving the
attacker alone with the victim's computer. There are so many other possible
approaches; just think for a while and you'll see what I mean and how easily
you could be tricked, and it's because you're not suspicious enough when it
is about your sensitive computer data.
- Another way of infecting while having physical access is the Auto-Starting
CD function. You've probably noticed that when you place a CD in your CDROM,
it automatically starts with some setup interface; here's an example of the
Autorun.inf file that is placed on such CD's:
[autorun]
open=setup.exe
icon=setup.exe
So you can imagine that while running the real setup program a trojan could
be run VERY easily, and as most of you probably don't know about this CD
function they will get infected and won't understand what happened and how
it's been done. Yeah, I know it's convenient to have the setup.exe autostart
but security is what really matters here, that's why you should turn off the
Auto-Start functionality by doing the following:
Start Button->Settings->Control Panel->
System->
Device Manager->CDROM->Properties->Settings
and there you'll see a reference to Auto Insert Notification. Turn it off
and you won't have any problems with that function anymore.
I know MANY other variations of physical access infections but these are the
most common ones so pay attention and try to make up several more by yourself.
When the victim IS connected to the Internet:
Here we have many variations; again, I'll mention the most common ones. While
the attacker is having physical access he/she may download the trojan.exe,
using various ways just by knowing how various Internet protocols work.
- A special IRCbot known only to the attacker is staying in IRC with the only
function to DCC the trojan.exe back to the attacker whenever he/she messages
the bot with a special command. The victim will probably be away from the
computer.
- The attacker wants to download some specific software like new version of
some programs infected with trojan(s), of course, and visit some URL, known
to him/her only, and download the trojan.
- The attacker pretends he/she wants to check his/her (web based) mail (for
example, at Yahoo! or HotMail) but in fact has the trojan.exe stored in his/
her mailbox and just downloads and executes the file, hereby infecting the
computer. The mail service is used as a storage area, in this case.
There are many more ways of infecting the victim while connected to the Net,
as you can imagine. Any of these examples will succeed but it all depends on
the victim's knowledge of the Internet and how advanced his/her skills are,
so the attacker needs to check these things somehow before doing any of these
activities I pointed here. After that, the attacker will be able to choose
the best variant for infecting the victim and doing the job.
6.5 Browser And E-mail Software Bugs
Users do not update their software versions as often as they should be, and a
lot of the attackers are taking advantage of this well known fact. Imagine you
are using an old version of Internet Explorer and you visit a (malicious) site
that will check and automatically infect your machine without you downloading
or executing any programs. The same scenario goes when you check your E-mail
with Outlook Express or some other software with well known problems, again
you will be infected without downloading the attachment. Make sure you always
have the latest version of your Browser and E-mail Software, and reduce the
ways of these variations to minimum. Here are some links about Browser and
E-mail Software bugs, check them out and understand how dangerous these bugs
are, and it's all because of you using an old version of the software.
http://www.guninski.com/browsers.html
http://www.guninski.com/netscape.html
6.6 Netbios(File Sharing)
If port 139 on your machine is opened,you're probably sharing files and this
is another way for someone to access your machine, install trojan.exe and
modify some system file, so it will run the next time you restart your PC.
Sometimes the attacker may use DoS(Denial Of Service Attack) to shut down
your machine and force you to reboot, so the trojan can restart itself
immediately. To block file sharing in WinME version, go to:
Start->Settings->Control Panel->Network->File And Print Sharing
and uncheck the boxes there. That way you won't have any problems related to
Netbios abuse.
7.Fake Programs
-------------
Imagine a Freeware SimpleMail program that's very suitable for your needs, and
very handy with its features like address book, option to check several POP3
accounts and many other functions that make it even better then your E-mail
client and the best thing for you is that it's free. You use ZoneAlarm or any
other similar protection software, and mark the program as a TRUSTED Internet
server so none of your programs will ever bother you about that program as you
are using it probably every day because it's working very well, no problems
ever occurred, you're happy, but a lot of things are going in the background.
Every mail you send and all your passwords for the POP3 accounts are being
mailed directly into the attacker's mailbox without you noticing anything.
Cached passwords and your keystrokes could be also mailed and the idea here is
to gather as much info as possible and send it to the attacker. This info
includes credit card numbers, passwords for various applications and many
other things.
In some cases the attacker may have complete access to your machine but it
depends on his/her ideas about the hidden program's functions. When sending
e-mails and using port 25 or 110 for POP3, these could be used for connections
from the attacker's machine (not at home, of course, but again from another
hacked one) to connect and use the hidden functions he/she implemented in the
Freeware SimpleMail. The attacker's idea here is to offer you a program that
requires a connection to be established with some server; let's say at the top
of the SimpleMail there's a banner that's auto-refreshing every few minutes,
because the programmer "needs to pay the bills too" as he said in the About
section, so nothing seems suspicious to you as it's a normal thing, and your
logical conclusion is completely right as the only way for that guy to keep
offering this cool freeware program for free is to use banners. You've already
marked the program as TRUSTED so the attacker can have complete access to your
machine because he/she fooled you into thinking it's a TRUSTED program. Even
if you notice some connection to your machine on some strange port, you won't
consider this as a suspicions event, as the banners section needs to get these
banners from somewhere, and this is the place your machine is connected all
the time to keep them refreshing.
The only thing the attacker needs is creativity, and most of them do have it.
Think of a fake AudioGalaxy (software for mp3's sharing) but, of course, with
a different name. The attacker would create it, will free 15GB disk space on
his machine and place a large archive of mp3's...then, of course, the same
will be done on several other machines to fool you that you are downloading
from other people located all over the world, but it's not necessary as the
program's interface may never show you where you're actually downloading the
mp3's from. The software will again be backdoored as in the previous example,
and will get thousands of naive users, probably using ADSL connections,
infected.
Fake programs that have hidden functions, often have professional looking web
sites, links to various anti-trojan software mentioned as affiliates, and make
you trust the site; readme.txt is included in the setup and many other things
to fool you it's a trusted one. Pay attention to freeware tools you download,
consider them extremely dangerous and a very useful and easy way for attackers
to infect your machine with a Trojan.
8.Untrusted Sites And Freeware Software
-------------------------------------
A site located at some free web space provider or just offering some programs
for illegal activities can be considered as untrusted one. As you know, there
are thousands of "hacking/security" archives on these free web space providers
like Xoom, Tripod, Geocities and many many others. These sites have archives
full with "hacking" programs, scanners, mail-bombers, flooders and many other
tools. Often several, if not all of these programs are infected by the guy who
created the site. It's highly risky to download any of the programs and the
tools located on such untrusted sites; no matter which software you use are,
you ready to take the risk? There are some untrusted sites, looking REALLY
professional and having huge archives, full with Internet related software,
feedback form, links to other popular sites. I think if you take some time,
look deeper, scan all the files you download you can decide on your own
whether the site you are downloading your software from is a trusted or an
untrusted one.
Software like mIRC, ICQ, PGP or any other popular software MUST be downloaded
from its original (or official dedicated mirror site) and not from any of
these I told you about. Sometimes such sites claim there's a new version of,
let's say, mIRC 7.0, and you know your current version is 6.0 and, yeah, it's
handy to click on the URL and download the .exe in 1 minute and take advantage
of the latest version, but will definitely get yourself infected. A possible
variation of this method will again be claiming for a new version, BUT the
site would include info on nonexistent security bugs, found in the previous
one (which is of course the latest you have), and again it is handy for you to
download it, instead of visiting mIRC's main site, and see if there is really
an updated version or check for any of these security bugs you've read about
on the fake site.
Webmasters of well known Security Portals, that have HUGE archive with various
"hacking" programs, should be responsible for the files they provide and OFTEN
scan them with Anti-Virus and Anti-Trojan software to guarantee their visitors
download "free of trojans and viruses". A known method is that attackers send
some program created by them, let's say a UDP flooder, to the webmaster like a
submission for the archive, but infect the program with some trojan and later
have visitors downloading the program and getting themselves infected. Some
attackers may use the webmaster's irresponsibility and infect their files, and
have the site distribute the trojan. I know of another story regarding this
problem. It's about a Gaming Magazine that used to include a CD with free demo
versions of the latest games in each new edition. The editors made a contest
to find new talents and give the people programming games the chance to
popularise their productions by sending them to the Editors. An attacker
infected his game with a new and private trojan and sent it to the Magazine.
In the next edition the "game" appeared on the CD and you can imagine the
chaos that set in. And it's all because of the Editors, having not so much
knowledge on the topic and as I've told you, in the old days Anti-Virus
software were detecting only a small part of the public trojans (and what
about all the private ones). In this particular case they were using only an
Anti Virus scanner to protect their readers from such attacks. Webmasters and
everyone having some sort of software archive on his/her portal, MUST scan it
very often, and before adding a new file it should be well examined; if it's
suspicious in any way, it must be sent to your software detection labs for
further analysis. Do care about your visitors/readers if you want them to care
about you.
Freeware programs could be considered suspicious and extremely dangerous, due
to the fact that it's a very easy and useful way for the attacker to infect
your machine with some freeware program. No matter how suitable you find the
program, remember that "free is not always the best" and it's very risky to
use any of these programs. My advice is: before using Freeware program, do
search for some reviews on it, check popular search engines, and try to look
up for some info about it. If you find any reviews written by respected sites,
that means they've used and tested it and the chance of infection is hereby,
minimised. If no reviews or comments about the software are found via the
search engines, then it may be highly risky to start using it.
9.How Are They Detecting My Internet Presence?
--------------------------------------------
People new to the Internet often ask this question as they can't understand
why someone will want to attack especially them, because they never did any
harm to anyone and never did something that might get them into trouble.
While reading the previous sections, I hope you understood that sometimes
you only need to visit a web site with your unpatched browser and get yourself
infected.
I will explain several scenarios on how attackers may discover your Internet
presence:
- When visiting a web page,the attacker might have created a script that will
automatically check your Browser for known bugs, and if any are detected,
install a trojan on your machine or notify the attacker to have a deeper
look. Make sure you're always using the latest version of your Browser for
maximal protection. Check for (security) patches and apply these often!
- When joining an IRC channel, an IRC bot might be configured to scan everyone
joining for specific trojan ports opened or FileSharing (Netbios) enabled.
If the attacker is smart, the script will scan you several minutes after you
join the channel and, of course, use an IP number not belonging to anyone in
the channel.
- Attackers often attempt IP blocks scanning, looking default trojan ports and
of course FileSharing(Netbios). After infection, your machine could also be
used for such scans, as well as an IRC bot, scanning those joining some big
and full with people IRC channel.
These are some of the most common ways attackers use to search for new victims,
suitable for their illegal activities. If someone is targeting especially you,
the attacker won't be using any of these methods I reviewed above; instead your
Browser version will be found as well as the Operation System you're using, and
the attacker will make a personal contact with you via IRC, ICQ, etc., and fool
you somehow and get you infected.
10.What Is The Attacker Looking For?
---------------------------------
Some of you may think that trojans are used for damages only. Well, they can
also be used for spying on someone's machine and taking a lot of private and
sensitive information (industrial espionage). The attacker's interests would
include but are not limited to the following:
- Credit Card Information (often used for domain registration, shopping with
your credit card)
- Any accounting data (E-mail passwords, Dial-Up passwords, WebServices
passwords, etc.)
- Email Addresses (Might be used for spamming, as explained above)
- Work Projects (Steal your presentations and work related papers)
- Children's names/pictures, Ages (pedophile attacker?!)
- School work (steal your papers and publish them with his/her name on it)
I'll mention again several scenarios about the attacker's mode of thinking:
- Once infected, your computer might be used as a Warez Archive. No matter how
much or little free disk space you have, you'll probably have enough for the
attacker's needs. He/she won't use all of your bandwidth; there will be some
limit for connections to your computer, so you'll still be able to do your
work without knowing that your computer is used as a pirated software FTP
Server and it is known to people worldwide who keep downloading software
from YOU.
- Kiddie-Porn traders will also use your computer for storing their archives
and again turning your machine into a well known place for traders of nasty
and above all illegal pictures. You'll again do your work and have no clue
there are illegal activities going in your computer.
- The attacker might just want to have fun with you, open/close the CD tray,
play with your mouse, annoy you somehow; that's stupid and useless but a lot
of people do it.
- Your computer might be used for other illegal purposes like the attacker's
usage of your IP address to hack, scan, flood, infiltrate other machines on
the Internet; so the victims will see your machine is doing it, and this
will definitely get you in trouble.
11.Intelligence With Trojans
-------------------------
Think for a while about how much your life depends on your computer, your ICQ,
your chat program, your e-mail address and think how vulnerable your life is
just because you're infected with a Trojan Horse. They can, and they have been
used for intelligence for a very long time. Just by reading your e-mails,
keeping track of your contacts, reading your private conversations, the web
sites you visit, ICQ history, mIRC log files with your private conversations
and a log of everything you do online, a psychological profile could be
created in several hours (depends of the skills of course) and your life, mode
of thinking, reactions on specific future situations and needs will be
revealed to some geek, wanting to recruit and/or manipulate you. This is food
for thought and another topic, but just think how a combination of psychology,
social engineering and computer security knowledge makes you a really powerful
guy. And remember that people reveal their REAL personalities, wishes, mode of
thinking, interests only when they think nobody is watching them...
12.Trojan Ports
------------
Trojans use specific ports to communicate with the client. In the old days the
well known trojan ports were mostly used, but today it's possible to change
the port every time the trojan is restarted. Here is a link to the best and
probably including all of the public trojans Ports List I've come across.
http://www.simovits.com/trojans/trojans.html
13.How Do I Know I'm Infected?
---------------------------
Sometimes you think it's normal Windows behaviour when there are 500 MB or so
missing on your HDD, because some software is using it, or you have installed
a game you forgot about and many other reasons but not the real one. Here are
some things which are very suspicious, and no matter how much your Anti-Virus
software tells you that you aren't infected, dig a little deeper and see what
really happened. One thing that will help you is to know the main features of
the public trojans, so you'll be able to react if you notice such activity on
your PC. I have included links to various Trojan Databases that you should
visit if you want to know the main features of the public ones.
- Its normal to visit a web site and several more pop-ups to appear with the
one you've visited. But when you do completely nothing and suddenly your
browser directs you to some page unknown to you, take that serious.
- A strange and unknown Windows Message Box appears on your screen, asking
you some personal questions.
- Your Windows settings change by themselves like a new screensaver text,
date/time, sound volume changes by itself, your mouse moves by itself,
CD-ROM drawer opens and closes.
Please note that most advanced attackers will just spy on you and use your
infected machine for some specific reason, and not perform any of the above
"tricks" so as not to cause any suspicious activity on the target system (as
this would probably mean they could get easily detected). Someone that just
wants to have fun with you is more likely to perform these actions.
14.Anti-Virus (AV) Scanners
-------------------
In the old days Virus Scanners used to detect only viruses and just a small
part of the public trojans on the Internet. Realising how dangerous and
popular Trojans are becoming today most, if not all of these scanners detect
probably all of the public ones out there. As always people, think they are
safe and secure when using Virus Scanner but it's a false sense of security.
This type of software relies mainly on "signatures" of each trojan's server
executable and also its common auto-starting methods, but that is not the
perfect solution by far for protection yourself against trojans, as they use
many other methods to hide inside the machine, most of which are undetected
by Anti-Virus Software. When trojans became a big security breach, specific
Anti-Trojan packages were released to the public and it was necessary for the
AVs to start detecting not only viruses, but also trojans if they wanted new
users. As a result, most of them became really advanced trojan scanning and
detection systems, but for your maximal protection it's recommended to use
both Anti-Virus and Anti-Trojans software.
Public trojans appear online almost every day and the detection software is
updated every day for maximal protection of its customers. One very big
problem is that the users do not update their signature files as often as they
should be, thus having detection software that's not detecting several more
trojans or viruses. Users MUST update their software's signature files every
day, and it will take them only several minutes. Each and every time a new
file is downloaded, it MUST be scanned BEFORE being opened with Anti-Virus and
Anti-Trojan software. If you think the file is suspicious due to some reasons,
do NOT run it, but send it to your detection software labs for analysis.
15.Anti-Trojan Software
--------------------
Here are reviews of the most popular Anti-Trojan packages. The list also
includes various applications (freeware) to help you monitor your computer for
ongoing Trojan activities. I suggest you visit the site of every product and
decide which one best fits to your needs. Check the links section at the end
of the paper to see various sites, providing reviews of the software below.
-- TDS-3 --
Trojan Defence Suite (TDS) is a indispensable, must-have software package for
protection against trojans. It has many unique functions never seen in other
Anti-Trojan packages. The program has really advanced features and if you're a
newbie, it will probably take some time before you are able to use the software
at its full capacity (read the excellent help files).
You can get TDS from http://tds.diamondcs.com.au/
-- LockDown2000 --
This is really good Anti-Trojan package that detects a LOT of trojans and other
known as "hacking tools" programs. It will help you monitor your system files
for changes, processes and registry modification. More info at its home page.
You can get LockDown2000 from http://www.lockdown2000.com
-- TFAK5 --
Trojans First Aid Kit is a trojan-scanner developed by SnakeByte. It has many
other unique features; it could be used as a Client for various public trojans
as well.
Download TFAK5 from http://www.snake-basket.de/tfak/TFAK5.zip
-- Trojan Remover --
Anti-Trojan software detecting 5468 trojans/worms (including variants) as at
15th August 2002. Systems files and registry monitoring functions are also
implemented. More info at its home page:
http://www.simplysup.com/tremover/details.html
-- Pest Patrol --
A tool that scans for trojans as well as programs known as "hacking tools" and
spyware. More info at its official page:
http://www.safersite.com/
-- Anti-Trojan 5.5 --
Trojans detection package that is able to remove most of the public trojans out
there. More info at its official page:
http://www.anti-trojan.net
-- Tauscan --
Trojan scanner that has unique features and is a must have. It's also able to
detect new and never released to the public trojans. More info at its official
page:
http://www.agnitum.com/products/tauscan/
-- The Cleaner --
Very popular Anti-Trojan software, known by everyone. Check its home page at:
http://www.moosoft.com/
-- PC Door Guard --
Trojan detection software, detecting a lot of trojans, and a monitor of files
and directories is also included. More info at:
http://www.trojanclinic.com/pdg.html
-- Trojan Hunter --
Trojan detection package with a lot of functions. It's very handy.
More info at http://www.mischel.dhs.org/trojanhunter.jsp
-- LogMonitor --
Log Monitor is a file and directory monitoring tool. The program periodically
checks a selected file's modification time and executes an external program if
file's time was changed or not changed. For directories it handles such events
as files change, addition or removal. I recommend this tool as it's vary handy
and will help you a lot.
Home page: http://logmon.bitrix.ru/logmon/eng/
-- PrcView --
PrcView is a freeware process viewer utility that shows detailed information
about running processes. This information includes such details as the create
date/time, the version and full path for each DLL used by a selected process,
a list of all threads, memory blocks and heaps. PrcView also allows you to
kill and attach a debugger to a selected process. PrcView runs on both Windows
95/98 and Windows NT platforms and includes Windows and command-line versions
of the program.
Get PrcView from http://www.xmlsp.com/pview/prcview.htm
-- XNetStat --
GUI based netstat tool for Windows. It will help you monitor you machine for
open ports. Download it from:
http://packetstormsecurity.org/Win/netstat.zip
-- ConSeal PC FIREWALL --
A really good firewall for advanced users using Windows having basic knowledge
of TCP/IP and other protocols; this software will help you to secure your PC a
lot. It has some major advantages over other Win based firewalls. For the full
range of specifications, check its official web page at:
http://www.consealfirewall.com/
16.After You Clean Yourself
------------------------
Your machine has been compromised and probably a lot of sensitive data stolen,
files have been modified and illegal activities have been preformed on your
computer. Here I'll give you recommendations about what to do after you are
100% clean of trojans.
- Accounting Data such as ISP passwords, ICQ, mIRC, FTP, web site passwords,
e-mail address passwords are definitely known to the attacker. Contact your
ISP about changing your dial-up password if you're using such connection.
Immediately change your ICQ, mIRC passwords of course if they're still the
same. (Often attackers won't change any of your accounting data to fool you
everything is OK so there is a big chance you will still be able to recover
from the compromise). Change your web based e-mail passwords and do check
your information stored there, as password retrieval services for various
e-mail providers such as Yahoo and Hotmail use this info combined with a
"Secret Question" for password retrieval. Attackers often change the info,
the answer to the secret question and many other things that will get them
easily back into your mailbox, whether you've changed your pass or not.
- If you're taking advantage of the handy Address Book feature in your e-mail
service, and have a list full of e-mails of friends, colleagues, etc. there
is a real possibility that the attacker has sent them a trojan and possibly
infected them too. Mail all of these people and ask them about receiving any
files from your mailbox, inform them someone else might know your e-mail
password so they'll be able to take appropriate actions like checking their
machines for Trojans. Do the same with the people from your ICQ contact list
as they might be targeted too.
- Check your HDD for abnormal activities like a lot of free space missing etc.
Search for warez software and, as I mentioned, kiddie-porn archives.
- Think for a while about the sensitive information you had on your machine
before the compromise, and if you are absolutely sure the attacker may know
it too, then take appropriate action, like informing the any institutions
the sensitive data belong to.
- Scan your machine with Anti-Virus scanner, as the attacker could have placed
some virus or infected macro documents on your machine to do destructive
things even there's no access for him/her to your machine.
- Monitor your processes BEFORE and AFTER connecting to the Internet, as some
trojans start when they detect Internet connection. Don't get fooled again,
be very suspicious.
17.Online Scanning Services
------------------------
These services are very popular these days and they are very handy for users
who haven't got much knowledge on all of the holes they're checking for, but
wanting to ensure they are protected from all of them. This section is placed
at the end of the paper with a specific reason. If you have read the paper,
you should know a LOT about trojans by now, their principles of working and
detection techniques, therefore you can decide whether these online scanners
are useful or if they give a false sense of safety.
There are several types of Online Scanners: Trojan Scanner, Port Scanner and
Bugs Checker.
- Trojan Scanner
It's using a list with predefined ports, associated with the name of the
trojan responding to its default port, like Girl Friend=21544, and if this
port is in "listening" state on your machine it will inform you that you've
been infected with the GirlFriend Trojan. As you already know, trojans have
functions like changing their default port to ANY of the attacker's choice.
That makes these Trojan Scanners kind of useless, because serious attackers
do change the default port for sure.
- Port Scanner
This service has two options like well-known ports scan and all ports scan.
The first feature is scanning for well known ports, again associated with
the appropriate service related to the port like port 21-FTP, 23-Telnet,
25-SMTP. The second feature is rarely seen on a free one, because of the
bandwidth it would generate to scan all of the 65,535 ports. It will again
associate ports with services like I mentioned above, and if it finds any
unknown ports not associated with any service, it will also report it, like
Port 34525 State:Listening, which means this port is waiting for connections
from the outside.
- Bugs Checker
Its purpose is to check your Browser or your E-mail Software for well known
bugs and security related problems. If any are detected, it will point you
to a site containing the patches for these bugs or a site with the latest
updated versions of the software.
It's strongly recommended to close any other Internet related application on
your machine before being scanned by Online Trojan Scanner and Port Scanner.
You decide which service is best for you, which one will be able to detect
trojan infections on your machine, and which won't; you now know the main
principles and the answers too, I hope. Links to several online scanning
services I know of are included in the Links Section.
18.Advice
------
This is a very useful section, full of tips and advice on how to protect
yourself from trojans using various ways you've already read about, but
summarised here for faster reading and hopefully better understanding.
[01] Never accept a file even it is from some friend. You're never sure who's
on the other side of the computer at the moment. If you really need this
file, let's say some presentation or a work paper, find other ways, like
the phone, and verify the file is from your friend. Yeah it will take you
some time and slow you a bit, but be paranoid about attachments you may
receive and don't ge

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Trojans - Information & Port Listings
Quickstudy by Jan Matlis
DEFINITION: Remote administration Trojans are pieces of malicious software, or malware, that let intruders remotely control computers across a network or through the Internet.
JULY 25, 2005 (COMPUTERWORLD) - The world of malicious software is often divided into two types: viral and nonviral. Viruses are little bits of code that are buried in other codes. When the "host" codes are executed, the viruses replicate themselves and may attempt to do something destructive. In this, they behave much like biological viruses.
Worms are a kind of computer parasite considered to be part of the viral camp because they replicate and spread from computer to computer.
As with viruses, a worm's malicious act is often the very act of replication; they can overwhelm computer infrastructures by generating massive numbers of e-mails or requests for connections that servers can't handle.
Worms differ from viruses, though, in that they aren't just bits of code that exist in other files. They could be whole files—an entire Excel spreadsheet, for example. They replicate without the need for another program to be run.
Remote administration types are an example of another kind of nonviral malicious software, the Trojan horse, or more simply Trojan. The purpose of these programs isn't replication, but to penetrate and control. Named after the wooden creature that the citizens of ancient Troy were tricked into taking into their fortified city, they are programs that masquerade as one thing when in fact they are something else, usually something destructive.
There are a number of kinds of Trojans, including spybots, which report on the Web sites a computer user visits, and keybots or keyloggers, which record and report the user's keystrokes in order to discover passwords and other confidential information.
Read the full article at ComputerWorld
DEFINITION: Remote administration Trojans are pieces of malicious software, or malware, that let intruders remotely control computers across a network or through the Internet.
JULY 25, 2005 (COMPUTERWORLD) - The world of malicious software is often divided into two types: viral and nonviral. Viruses are little bits of code that are buried in other codes. When the "host" codes are executed, the viruses replicate themselves and may attempt to do something destructive. In this, they behave much like biological viruses.
Worms are a kind of computer parasite considered to be part of the viral camp because they replicate and spread from computer to computer.
As with viruses, a worm's malicious act is often the very act of replication; they can overwhelm computer infrastructures by generating massive numbers of e-mails or requests for connections that servers can't handle.
Worms differ from viruses, though, in that they aren't just bits of code that exist in other files. They could be whole files—an entire Excel spreadsheet, for example. They replicate without the need for another program to be run.
Remote administration types are an example of another kind of nonviral malicious software, the Trojan horse, or more simply Trojan. The purpose of these programs isn't replication, but to penetrate and control. Named after the wooden creature that the citizens of ancient Troy were tricked into taking into their fortified city, they are programs that masquerade as one thing when in fact they are something else, usually something destructive.
There are a number of kinds of Trojans, including spybots, which report on the Web sites a computer user visits, and keybots or keyloggers, which record and report the user's keystrokes in order to discover passwords and other confidential information.
Read the full article at ComputerWorld

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Trojans - Information & Port Listings
Trojans And Backdoors
By Suhas A Desai
The Trojan Horse got its name from the old mythical story about how the Greeks gave their enemy a huge wooden horse as a gift during the war.
The enemy accepted this gift and they brought it into their kingdom, and during the night, Greek soldiers crept out of the horse and attacked the city, completely overcoming it.
A Trojan horse is an unauthorised program contained within a legitimate program. This unauthorised program performs functions unknown by the user. A legitimate program that has been altered by the placement of unauthorized code within it; this code performs functions unknown by the user.
Working:
Trojans come in two parts, a Client part and a Server part. When the victim runs the server on its machine, the attacker will then use the Client to connect to the Server and start using the trojan. TCP/IP protocol is the usual protocol type used for communications, but some functions of the trojans use the UDP protocol as well. When the Server is being run on the victim's computer, it will (usually) try to hide somewhere on the computer,start listening on some port(s) for incoming connections from the attacker,modify the registry and/or use some other autostarting method.
It's necessary for the attacker to know the victim's IP address to connect to his/her machine. Many trojans have features like mailing the victim's IP, as well as messaging the attacker via ICQ or IRC. This is used when the victim has dynamic IP which means every time you connect to the Internet you get a different IP (most of the dial-up users have this).
Most of the trojans use Auto-Starting methods so even when you shut down your computer they're able to restart and again give the attacker access to your machine. New auto-starting methods and other tricks are discovered all the time. The variety starts from "joining" the trojan into some executable file you use very often like explorer.exe, for example, and goes to the known methods like modifying the system files or the Windows Registry. System files are located in the Windows directory and here are short explanations of their abuse by the attackers:
- Autostart Folder - The Autostart folder is located in C:\Windows\Start Menu\Programs\startup and as its name suggests, automatically starts everything placed there.
- Win.ini - Windows system file using load=Trojan.exe and run=Trojan.exe to execute the Trojan
- System.ini - Using Shell=Explorer.exe trojan.exe results in execution of every file after Explorer.exe
- Wininit.ini - Setup-Programs use it mostly; once run, it's being auto-deleted, which is very handy for trojans to restart
- Winstart.bat - Acting as a normal bat file trojan is added as @trojan.exe to hide its execution from the user
- Autoexec.bat - It's a DOS auto-starting file and it's used as auto-starting method like this -> c:\Trojan.exe
- Config.sys - Could also be used as an auto-starting method for trojans
- Explorer Startup - Is an auto-starting method for Windows95, 98, ME and if c:\explorer.exe exists, it will be started instead of the usual c:\Windows\Explorer.exe, which is the common path to the file.
Registry is often used in various auto-starting methods. Here are some known ways:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Info"="c:\directory\Trojan.exe"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Info"="c:\directory\Trojan.exe"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
"Info"="c:\directory\Trojan.exe"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce]
"Info="c:\directory\Trojan.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Info"="c:\directory\Trojan.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Info"="c:\directory\Trojan.exe"
- Registry Shell Open
[HKEY_CLASSES_ROOT\exefile\shell\open\command]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
A key with the value "%1 %*" should be placed there and if there is some executable file placed there, it will be executed each time you open a binary file. It's used like this: trojan.exe "%1 %*"; this would restart the trojan.
- ICQ Net Detect Method
[HKEY_CURRENT_USER\Software\Mirabilis\ICQ\Agent\Apps\]
This key includes all the files that will be executed if ICQ detects Internet connection. As you can understand,this feature of ICQ is very handy but it's frequently abused by attackers as well.
- ActiveX Component
[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\KeyName]
StubPath=C:\directory\Trojan.exe
These are the most common Auto-Starting methods using Windows system files, and the Windows registry.
Trojans Variations
1.Remote Access Trojans
These are probably the most publicly used trojans,just because they give the attackers the power to do more things on the victim's machine than the victim itself, while standing in front of the machine. Most of these trojans are often a combination of the other variations you'll read below. The idea of these trojans is to give the attacker a COMPLETE access to someone's machine, and therefore access to files, private conversations, accounting data, etc.
2.Password Sending Trojans
The purpose of these trojans is to rip all the cached passwords and also look for other passwords you're entering then send them to a specific mail address, without the user noticing anything. Passwords for ICQ, IRC, FTP, HTTP or any other application that require a user to enter a login+password are being sent back to the attacker's e-mail address, which in most cases is located at some free web based e-mail provider. Most of them do not restart when Windows is loaded, as the idea is to gather as much info about the victim's machine as passwords, mIRC logs, ICQ conversations and mail them; but it depends on the needs of the attacker and the specific situation.
3.Keyloggers
These Trojans are to log the keystrokes of the victim and then let the attacker search for passwords or other sensitive data in the log file. Most of them come with two functions like online and offline recording. Of course they could be configured to
send the log file to a specific e-mail address on a daily basis.
4.Destructive
The only function of these Trojans is to destroy and delete files. This makes them very simple and easy to use. They can automatically delete all your core system files (for example: .dll, .ini or .exe files, possibly others) on your machine. The Trojan is being activated by the attacker or sometimes works like A logic bomb and starts on a specific day and at specific hour.
5.Denial Of Service (DoS) Attack Trojans
These Trojans are getting very popular these days, giving the attacker power to start DDoS if having enough victims of course. The main idea is that if you have 200 ADSL users infected and start attacking the victim simultaneously, this will generate a LOT of traffic (more then the victim's bandwidth, in most cases) and its the access to the Internet will be shut down. WinTrinoo is a DDoS tool that has become really popular recently, and if the attacker has infected many ADSL users, major Internet sites could be shut down as a result, as we've seen it happen in the past few months.
Another variation of a DoS trojan is the mail-bomb trojan, whose main aim is to infect as many machines as possible and simultaneously attack specific e-mail address/addresses with random subjects and contents which cannot be filtered.
6.Proxy/Wingate Trojans
Interesting feature implemented in many trojans is turning the victim's computer into a proxy/wingate server available to the whole world or to the attacker only. It's used for anonymous Telnet, ICQ, IRC, etc., and also to register domains with stolen credit cards and for many other illegal activities. This gives the attacker complete anonymity and the chance to do everything from YOUR computer and if he/she gets caught the trace leads back to you.
7.FTP Trojans
These trojans are probably the most simple ones and are kind of outdated as the only thing they do is to open port 21(the port for FTP transfers) and let EVERYONE connect to your machine or just the attacker. Newer versions are password protected so only the one that infected you may connect to your computer.
8.Software Detection Killers
There are such functionalities built into some trojans, but there are also separate programs that will kill ZoneAlarm, Norton Anti-Virus and many other (popular anti-virus/firewall) programs, that protect your machine. When they are disabled, the attacker will have full access to your machine, to perform some illegal activity, use your computer to attack others and often disappear. Even though you may notice that these programs are not working or functioning properly, it will take you some time to remove the trojan, install the new software, configure it and get back online with some sense of security.
How Can I Get Infected:
Following are ways to get infected with Trojans,
1 ICQ
2 IRC
3 Attachments
4 Physical Access
5 Browser And E-mail Software Bugs
6 Netbios(FileSharing)
Trojan Programs:
Trojans can be classified as :
1.Backdoors
2.General Trojans
3.PSW Trojans
4.Trojan Clickers
5.Trojan Downloaders
6.Trojan Droppers
7.Trojan Proxies
8.Trojan Spies
9.Trojan Notifiers
10.ArcBombs
Backdoors
Today backdoors are the most dangerous type of Trojans and the most widespread. These Trojans are remote administration utilities that open infected machines to external control via a LAN or the Internet. They function in the same way as legal remote administration programs used by system administrators. This makes them difficult to detect.The only difference between a legal administration tool and a backdoor is that backdoors are installed and launched without the knowledge or consent of the user of the victim machine. Once the backdoor is launched, it monitors the local system without the user's knowledge; often the backdoor will not be visible in the log of active programs.
Once a remote administration utilitiy has been successfully installed and launched, the victim machine is wide open.
Backdoor functions can include:
1.Sending/ receiving files
2.Launching/ deleting files
3.Executing files
4.Displaying notification
5.Deleting data
6.Rebooting the machine
In other words, backdoors are used by virus writers to detect and download confidential information, execute malicious code, destroy data, include the machine in bot networks and so forth. In short, backdoors combine the functionality of most other types of Trojans in one package.
Backdoors have one especially dangerous sub-class: variants that can propagate like worms. The only difference is that worms are programmed to propagate constantly, whereas these 'mobile' backdoors spread only after a specific command from the 'master'.
General Trojans
This loose category includes a variety of Trojans that damage victim machines or threaten data integrity, or impair the functioning of the victim machine.
Multi-purpose Trojans are also included in this group, as some virus writers create multi-functional Trojans rather than Trojan packs.
PSW Trojans
This family of Trojans steals passwords, normally system passwords from victim machines. They search for system files, which contain confidential information such as passwords and Internet access telephone numbers and then send this information to an email address coded into the body of the Trojan. It will then be retrieved by the 'master' or user of the illegal program.
Some PSW Trojans steal other types of information such as:
System details (memory, disk space, operating system details)
Local email client
IP-address
Registration details
Passwords for on-line games
Trojan-AOL are PSW Trojans that steal passwords for aol (American Online) They are contained in a sub-groups because they are so numerous.
Trojan Clickers
This family of Trojans redirects victim machines to specified websites or other Internet resources. Clickers either send the necessary commands to the browser or replace system files where standard Internet urls are stored (e.g. the 'hosts' file in MS Windows).
Clickers are used:
1.To raise the hit-count of a specific site for advertising purposes
2.To organize a DoS attack on a specified server or site
3.To lead the victim to an infected resource where the machine will be attacked by other malware (viruses or Trojans)
Trojan Downloaders
This family of Trojans downloads and installs new malware or adware on the victim machine. The downloader then either launches the new malware or registers it to enable autorun according to the local operating system requirements. All of this is done without the knowledge or consent of the user.
The names and locations of malware to be downloaded are either coded into the Trojan or downloaded from a specified website or other Internet location.
Trojan Droppers
These Trojans are used to install other malware on victim machines without the knowledge of the user. Droppers install their payload either without displaying any notification, or displaying a false message about an error in an archived file or in the operating system. The new malware is dropped to a specified location on a local disk and then launched.
Droppers are normally structured in the following way:
[attachment=1292]attachment[/attachment]
The dropper functionality contains code to install and execute all of the payload files.
In most cases, the payload contains other Trojans and at least one hoax: jokes, games, graphics and so forth. The hoax is meant to distract the user or to prove that the activity caused by the dropper is harmless, whereas it actually serves to mask the installation of the dangerous payload.
Hackers using such programs achieve two objectives:
Hidden or masked installation of other Trojans or viruses
Tricking antivirus solutions, which are unable to analyse all components
Trojan Proxies
These Trojans function as a proxy server and provide anonymous access to the Internet from victim machines. Today these Trojans are very popular with spammers who always need additional machines for mass mailings. Virus coders will often include Trojan-proxies in Trojan packs and sell networks of infected machines to spammers.
Trojan Spies
This family includes a variety of spy programs and key loggers, all of which track and save user activity on the victim machine and then forward this information to the master.
Trojan-spies collect a range of information including:
1.Keystrokes
2.Screenshots
3.Logs of active applications
4.Other user actions
These Trojans are most often used to steal banking and other financial information to support online fraud.
Trojan Notifiers
These Trojans inform the 'master' about an infected machine. Notifiers confirm that a machine has been successfully infected, and send information about IP-address, open port numbers, the email address etc. of the victim machine. This information may be sent by email, to the master's website, or by ICQ.
Notifiers are usually included in a Trojan 'pack' and used only to inform the master that a Trojan has been successfully installed on the victim machine.
ArcBombs
These Trojans are archived files coded to sabotage the de-compressor when it attempts to open the infected archived file. The victim machine will slow or crash when the Trojan bomb explodes, or the disk will be filled with nonsense data. ArcBombs are especially dangerous for servers, particularly when incoming data is initially processed automatically: in such cases, an ArcBomb can crash the server.
There are three types of ArcBombs:
1.incorrect header in the archive,
2.repeating data
3.a series of identical files in the archive.
An incorrect archive header or corrupted data can both cause the de-compressor to crash when opening and unpacking the infected archive.
A large file containing repeating data can be packed into a very small archive: 5 gigabytes will be 200 KB when packed using RAR and 480 KB in ZIP format.
Moreover, special technologies exist to pack an enormous number of identical files in one archive without significantly affecting the size of the archive itself: for instance, it is possible to pack 10100 identical files into a 30 KB RAR file or a 230 KB ZIP file.
Spyware and adware:
Spyware and adware are forms of a trojan horse.
Spyware programs perform a useful function, and also install a program that monitors usage of the victim's computer for the purpose of marketing to the user.
Adware programs are similiar to spyware programs, except the additional software they install shows advertising messages directly to the user.
~~~~~~~~~~~~~~~~~~~~~
About the Author:
Suhas A Desai
*Undergraduate Computer Engineering Student,Walchand CE,Sangli,INDIA.
*Previous Publications in area "Linux Based Biometrics Security with Smart Card" are include:ISA EXPO 2004,InTech Journal,TX,USA,IEEE Real Time and Embedded System symposium 2005,CA,USA.,e-Smart 2005,France.
*Writes security newsletters and features for many security sites.
source: Enterprise Security News
By Suhas A Desai
The Trojan Horse got its name from the old mythical story about how the Greeks gave their enemy a huge wooden horse as a gift during the war.
The enemy accepted this gift and they brought it into their kingdom, and during the night, Greek soldiers crept out of the horse and attacked the city, completely overcoming it.
A Trojan horse is an unauthorised program contained within a legitimate program. This unauthorised program performs functions unknown by the user. A legitimate program that has been altered by the placement of unauthorized code within it; this code performs functions unknown by the user.
Working:
Trojans come in two parts, a Client part and a Server part. When the victim runs the server on its machine, the attacker will then use the Client to connect to the Server and start using the trojan. TCP/IP protocol is the usual protocol type used for communications, but some functions of the trojans use the UDP protocol as well. When the Server is being run on the victim's computer, it will (usually) try to hide somewhere on the computer,start listening on some port(s) for incoming connections from the attacker,modify the registry and/or use some other autostarting method.
It's necessary for the attacker to know the victim's IP address to connect to his/her machine. Many trojans have features like mailing the victim's IP, as well as messaging the attacker via ICQ or IRC. This is used when the victim has dynamic IP which means every time you connect to the Internet you get a different IP (most of the dial-up users have this).
Most of the trojans use Auto-Starting methods so even when you shut down your computer they're able to restart and again give the attacker access to your machine. New auto-starting methods and other tricks are discovered all the time. The variety starts from "joining" the trojan into some executable file you use very often like explorer.exe, for example, and goes to the known methods like modifying the system files or the Windows Registry. System files are located in the Windows directory and here are short explanations of their abuse by the attackers:
- Autostart Folder - The Autostart folder is located in C:\Windows\Start Menu\Programs\startup and as its name suggests, automatically starts everything placed there.
- Win.ini - Windows system file using load=Trojan.exe and run=Trojan.exe to execute the Trojan
- System.ini - Using Shell=Explorer.exe trojan.exe results in execution of every file after Explorer.exe
- Wininit.ini - Setup-Programs use it mostly; once run, it's being auto-deleted, which is very handy for trojans to restart
- Winstart.bat - Acting as a normal bat file trojan is added as @trojan.exe to hide its execution from the user
- Autoexec.bat - It's a DOS auto-starting file and it's used as auto-starting method like this -> c:\Trojan.exe
- Config.sys - Could also be used as an auto-starting method for trojans
- Explorer Startup - Is an auto-starting method for Windows95, 98, ME and if c:\explorer.exe exists, it will be started instead of the usual c:\Windows\Explorer.exe, which is the common path to the file.
Registry is often used in various auto-starting methods. Here are some known ways:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Info"="c:\directory\Trojan.exe"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Info"="c:\directory\Trojan.exe"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
"Info"="c:\directory\Trojan.exe"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce]
"Info="c:\directory\Trojan.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Info"="c:\directory\Trojan.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Info"="c:\directory\Trojan.exe"
- Registry Shell Open
[HKEY_CLASSES_ROOT\exefile\shell\open\command]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
A key with the value "%1 %*" should be placed there and if there is some executable file placed there, it will be executed each time you open a binary file. It's used like this: trojan.exe "%1 %*"; this would restart the trojan.
- ICQ Net Detect Method
[HKEY_CURRENT_USER\Software\Mirabilis\ICQ\Agent\Apps\]
This key includes all the files that will be executed if ICQ detects Internet connection. As you can understand,this feature of ICQ is very handy but it's frequently abused by attackers as well.
- ActiveX Component
[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\KeyName]
StubPath=C:\directory\Trojan.exe
These are the most common Auto-Starting methods using Windows system files, and the Windows registry.
Trojans Variations
1.Remote Access Trojans
These are probably the most publicly used trojans,just because they give the attackers the power to do more things on the victim's machine than the victim itself, while standing in front of the machine. Most of these trojans are often a combination of the other variations you'll read below. The idea of these trojans is to give the attacker a COMPLETE access to someone's machine, and therefore access to files, private conversations, accounting data, etc.
2.Password Sending Trojans
The purpose of these trojans is to rip all the cached passwords and also look for other passwords you're entering then send them to a specific mail address, without the user noticing anything. Passwords for ICQ, IRC, FTP, HTTP or any other application that require a user to enter a login+password are being sent back to the attacker's e-mail address, which in most cases is located at some free web based e-mail provider. Most of them do not restart when Windows is loaded, as the idea is to gather as much info about the victim's machine as passwords, mIRC logs, ICQ conversations and mail them; but it depends on the needs of the attacker and the specific situation.
3.Keyloggers
These Trojans are to log the keystrokes of the victim and then let the attacker search for passwords or other sensitive data in the log file. Most of them come with two functions like online and offline recording. Of course they could be configured to
send the log file to a specific e-mail address on a daily basis.
4.Destructive
The only function of these Trojans is to destroy and delete files. This makes them very simple and easy to use. They can automatically delete all your core system files (for example: .dll, .ini or .exe files, possibly others) on your machine. The Trojan is being activated by the attacker or sometimes works like A logic bomb and starts on a specific day and at specific hour.
5.Denial Of Service (DoS) Attack Trojans
These Trojans are getting very popular these days, giving the attacker power to start DDoS if having enough victims of course. The main idea is that if you have 200 ADSL users infected and start attacking the victim simultaneously, this will generate a LOT of traffic (more then the victim's bandwidth, in most cases) and its the access to the Internet will be shut down. WinTrinoo is a DDoS tool that has become really popular recently, and if the attacker has infected many ADSL users, major Internet sites could be shut down as a result, as we've seen it happen in the past few months.
Another variation of a DoS trojan is the mail-bomb trojan, whose main aim is to infect as many machines as possible and simultaneously attack specific e-mail address/addresses with random subjects and contents which cannot be filtered.
6.Proxy/Wingate Trojans
Interesting feature implemented in many trojans is turning the victim's computer into a proxy/wingate server available to the whole world or to the attacker only. It's used for anonymous Telnet, ICQ, IRC, etc., and also to register domains with stolen credit cards and for many other illegal activities. This gives the attacker complete anonymity and the chance to do everything from YOUR computer and if he/she gets caught the trace leads back to you.
7.FTP Trojans
These trojans are probably the most simple ones and are kind of outdated as the only thing they do is to open port 21(the port for FTP transfers) and let EVERYONE connect to your machine or just the attacker. Newer versions are password protected so only the one that infected you may connect to your computer.
8.Software Detection Killers
There are such functionalities built into some trojans, but there are also separate programs that will kill ZoneAlarm, Norton Anti-Virus and many other (popular anti-virus/firewall) programs, that protect your machine. When they are disabled, the attacker will have full access to your machine, to perform some illegal activity, use your computer to attack others and often disappear. Even though you may notice that these programs are not working or functioning properly, it will take you some time to remove the trojan, install the new software, configure it and get back online with some sense of security.
How Can I Get Infected:
Following are ways to get infected with Trojans,
1 ICQ
2 IRC
3 Attachments
4 Physical Access
5 Browser And E-mail Software Bugs
6 Netbios(FileSharing)
Trojan Programs:
Trojans can be classified as :
1.Backdoors
2.General Trojans
3.PSW Trojans
4.Trojan Clickers
5.Trojan Downloaders
6.Trojan Droppers
7.Trojan Proxies
8.Trojan Spies
9.Trojan Notifiers
10.ArcBombs
Backdoors
Today backdoors are the most dangerous type of Trojans and the most widespread. These Trojans are remote administration utilities that open infected machines to external control via a LAN or the Internet. They function in the same way as legal remote administration programs used by system administrators. This makes them difficult to detect.The only difference between a legal administration tool and a backdoor is that backdoors are installed and launched without the knowledge or consent of the user of the victim machine. Once the backdoor is launched, it monitors the local system without the user's knowledge; often the backdoor will not be visible in the log of active programs.
Once a remote administration utilitiy has been successfully installed and launched, the victim machine is wide open.
Backdoor functions can include:
1.Sending/ receiving files
2.Launching/ deleting files
3.Executing files
4.Displaying notification
5.Deleting data
6.Rebooting the machine
In other words, backdoors are used by virus writers to detect and download confidential information, execute malicious code, destroy data, include the machine in bot networks and so forth. In short, backdoors combine the functionality of most other types of Trojans in one package.
Backdoors have one especially dangerous sub-class: variants that can propagate like worms. The only difference is that worms are programmed to propagate constantly, whereas these 'mobile' backdoors spread only after a specific command from the 'master'.
General Trojans
This loose category includes a variety of Trojans that damage victim machines or threaten data integrity, or impair the functioning of the victim machine.
Multi-purpose Trojans are also included in this group, as some virus writers create multi-functional Trojans rather than Trojan packs.
PSW Trojans
This family of Trojans steals passwords, normally system passwords from victim machines. They search for system files, which contain confidential information such as passwords and Internet access telephone numbers and then send this information to an email address coded into the body of the Trojan. It will then be retrieved by the 'master' or user of the illegal program.
Some PSW Trojans steal other types of information such as:
System details (memory, disk space, operating system details)
Local email client
IP-address
Registration details
Passwords for on-line games
Trojan-AOL are PSW Trojans that steal passwords for aol (American Online) They are contained in a sub-groups because they are so numerous.
Trojan Clickers
This family of Trojans redirects victim machines to specified websites or other Internet resources. Clickers either send the necessary commands to the browser or replace system files where standard Internet urls are stored (e.g. the 'hosts' file in MS Windows).
Clickers are used:
1.To raise the hit-count of a specific site for advertising purposes
2.To organize a DoS attack on a specified server or site
3.To lead the victim to an infected resource where the machine will be attacked by other malware (viruses or Trojans)
Trojan Downloaders
This family of Trojans downloads and installs new malware or adware on the victim machine. The downloader then either launches the new malware or registers it to enable autorun according to the local operating system requirements. All of this is done without the knowledge or consent of the user.
The names and locations of malware to be downloaded are either coded into the Trojan or downloaded from a specified website or other Internet location.
Trojan Droppers
These Trojans are used to install other malware on victim machines without the knowledge of the user. Droppers install their payload either without displaying any notification, or displaying a false message about an error in an archived file or in the operating system. The new malware is dropped to a specified location on a local disk and then launched.
Droppers are normally structured in the following way:
[attachment=1292]attachment[/attachment]
The dropper functionality contains code to install and execute all of the payload files.
In most cases, the payload contains other Trojans and at least one hoax: jokes, games, graphics and so forth. The hoax is meant to distract the user or to prove that the activity caused by the dropper is harmless, whereas it actually serves to mask the installation of the dangerous payload.
Hackers using such programs achieve two objectives:
Hidden or masked installation of other Trojans or viruses
Tricking antivirus solutions, which are unable to analyse all components
Trojan Proxies
These Trojans function as a proxy server and provide anonymous access to the Internet from victim machines. Today these Trojans are very popular with spammers who always need additional machines for mass mailings. Virus coders will often include Trojan-proxies in Trojan packs and sell networks of infected machines to spammers.
Trojan Spies
This family includes a variety of spy programs and key loggers, all of which track and save user activity on the victim machine and then forward this information to the master.
Trojan-spies collect a range of information including:
1.Keystrokes
2.Screenshots
3.Logs of active applications
4.Other user actions
These Trojans are most often used to steal banking and other financial information to support online fraud.
Trojan Notifiers
These Trojans inform the 'master' about an infected machine. Notifiers confirm that a machine has been successfully infected, and send information about IP-address, open port numbers, the email address etc. of the victim machine. This information may be sent by email, to the master's website, or by ICQ.
Notifiers are usually included in a Trojan 'pack' and used only to inform the master that a Trojan has been successfully installed on the victim machine.
ArcBombs
These Trojans are archived files coded to sabotage the de-compressor when it attempts to open the infected archived file. The victim machine will slow or crash when the Trojan bomb explodes, or the disk will be filled with nonsense data. ArcBombs are especially dangerous for servers, particularly when incoming data is initially processed automatically: in such cases, an ArcBomb can crash the server.
There are three types of ArcBombs:
1.incorrect header in the archive,
2.repeating data
3.a series of identical files in the archive.
An incorrect archive header or corrupted data can both cause the de-compressor to crash when opening and unpacking the infected archive.
A large file containing repeating data can be packed into a very small archive: 5 gigabytes will be 200 KB when packed using RAR and 480 KB in ZIP format.
Moreover, special technologies exist to pack an enormous number of identical files in one archive without significantly affecting the size of the archive itself: for instance, it is possible to pack 10100 identical files into a 30 KB RAR file or a 230 KB ZIP file.
Spyware and adware:
Spyware and adware are forms of a trojan horse.
Spyware programs perform a useful function, and also install a program that monitors usage of the victim's computer for the purpose of marketing to the user.
Adware programs are similiar to spyware programs, except the additional software they install shows advertising messages directly to the user.
~~~~~~~~~~~~~~~~~~~~~
About the Author:
Suhas A Desai
*Undergraduate Computer Engineering Student,Walchand CE,Sangli,INDIA.
*Previous Publications in area "Linux Based Biometrics Security with Smart Card" are include:ISA EXPO 2004,InTech Journal,TX,USA,IEEE Real Time and Embedded System symposium 2005,CA,USA.,e-Smart 2005,France.
*Writes security newsletters and features for many security sites.
source: Enterprise Security News

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
