What Is a Virus, What are Worms and Trojans and Ways to Prevent Them | Total Security
A computer virus is an external program intentionally made to change the properties of the files it infects to carry out some commands either to remove, modify or sabotage and the like. That is, computer viruses are programs that are written by professional programmers to damage another computer, controlling it, or stealing important data, and they are written in a specific way. The rootkit is considered a malicious program, but it is dangerous because it can do it secretly and activate it remotely, and this indicates the professionalism of these virus programmers. This is why the antivirus must be updated to be in the antivirus database the latest information regarding the rootkit to find it when doing the scan on the computer despite the difficulty Find it. A computer virus is characterized as:
A program is capable of replication and propagation.
The virus attaches itself to another program called the host.
Viruses cannot arise on their own.
It can be transmitted from an infected computer to another healthy computer.
: Ok, what is Worms and how it works
Worms
Computer worms are small, stand-alone programs that are not dependent on others, made to carry out destructive actions or to steal some data from some users while surfing the Internet or harming them or their callers.
How do worms work?
The worm infects computers connected to the network automatically, and without human intervention, which makes it spread more widely and faster than viruses. The difference between worms and viruses is that the worms do not delete or change files, but rather they exhaust the device’s resources, especially the memory. The device is also slow in transmitting data over the network.
Worms differ in their work from one type to another, some of them replicate inside the device to huge numbers, while we find some of them rely on e-mail or Skype to send a copy of themselves to everyone in the address book or the contact list on Skype, some of them even send dirty messages For a random number of people registered in the address book using the e-mail of the owner of the affected device, which in addition to consuming the device's resources causes a lot of embarrassment.
: Dangerous
The danger of worms lies in their independence and lack of dependence on other programs that join them, which gives them complete freedom in the rapid spread, and there is no doubt that there are very dangerous types of them so that some of them have become terrifying nightmare that haunts every user of the network,
Types:
Mail worms
And they are attached to the content of the message and most types of these worms require the user to open the attached file to infect the device and other types that contain an external link, and after they infect the device, they send copies of them to all those on the mailing list using the SMTP protocol
Instant messaging worms
And this type of worms uses an instant messaging program to spread by sending messages to all of them.
IRC worms
It propagates by copying itself into channels in the case of chatting using the ERC protocol and sending links to the address infected with the worm
Worms file-sharing software
And it spreads by placing itself in the shared folders until it is spread among other users if files are downloaded via Bitlord.
Internet worms
The transmission is via the TCP / IP protocol directly without the need for a higher level such as e-mail or file-sharing programs, and an example is the Blaster worm that randomly spreads by searching for addresses where port number 135 is open to exploit and infect the victim's device.
: Ways to prevent them
It is known that the most common means of spreading worms is through bombed e-mails, and the addresses of these messages are usually attractive as an invitation to see the pictures of a star or celebrity, so you must be careful even if the messages are from a known source because some worms send themselves from any mail to all E-mails added to the address book, so be careful and do not open any message until you are absolutely sure that it is free of any harm. Also, it is important to update the system versions used in the device to avoid worms.
What are Trojan Horses
Trojan Horses
It is a hidden program that infects the victim's device without his knowledge and allows the attackers to control, spy or exploit the device for illegal purposes without the knowledge of the owner of the device.
It was called by this name for the method used by the Greeks to conquer the city of Troy, which remained fortified in front of them and were unable to storm it by traditional methods, so they built a very large model in the form of a wooden horse hollow from the inside and placed soldiers inside it and left it as a gift at the fortresses of the city and withdrew from it. So the people of the city entered the model and considered it a symbol of victory over the enemies, and at midnight, the soldiers left the model and opened the city walls to the army that entered and then occupied the city.
So the Trojan is a very dangerous program and its danger lies in the fact that it is present on the victim's device without the knowledge of the owner, which may expose the owner of the device to the dangers of espionage and theft of personal information, photos or confidential files or corrupting them or disrupting the device or collecting his passwords that he uses on the Internet (mail sites Electronic or commercial websites) and who has been changed and used as a means of extortion ... and other terrifying risks.
: The way it works
Trojan software consists of two versions: a server and a user. The attacker publishes the server copy on the Internet after linking it with any other file or program (for example a game or an operational presentation), and when the user (the victim) runs that file, the server copy is downloaded to his computer without his knowledge (he only sees the main program and does not know That there is a Trojan program attached to it), and the server copy opens a port (vulnerability) on the victim's machine to be ready to receive commands from the attacker who uses the beneficiary copy and sends the commands through the network to the victim's machine. The server copy may send an email to the attacker informing him about the victim's device information (name and address on the network) on which the server copy has been downloaded so that he can identify it. Also, the server copy has the ability to run itself even with restarting the device and protecting access to it with a password so that no other attacker can control the victim's device.
As for the way it spreads, it is not like viruses that are transmitted automatically and without human intervention, but the Trojan spreads by exchanging files and running them by users without their knowledge that these files contain Trojan programs.
What the attacker is looking for
The attacker uses the Trojan software on the victim's machine to obtain several things, including:
- Credit card numbers (Visa or MasterCard), whether they are stored on the device or when the user uses them on the Internet.
- Account numbers and passwords, whether a bank account, an email, or an e-commerce site.
Confidential or important documents, files, or information.
Email addresses are stored in the device.
Private or family photos or videos, and he may use them to blackmail the owner of the device.
Using the victim's device for illegal purposes such as hacking into websites or disabling other devices.
Disrupting or sabotaging and corrupting the victim's apparatus.
Types of Trojan
Trojans have many types, but they can be categorized metaphorically into six main types:
Remote Administration Trojan or Remote Administration Tool: It is the most famous, most widespread, and dangerous type of Trojan, and one of the most famous examples of it (Poison Ivy. Bifrost. SPT-Net. Lost Door).
This type of Trojan gives the attacker complete control over the victim's device and many advantages that were not originally available to the victim, such as collecting passwords, collecting keystrokes, reversing the direction of the mouse movement, or running programs remotely.
File Server Trojan: This type makes the victim's machine a file server (FTP Server), allowing the attacker to place files (remote control Trojan files) or download them using the victim's machine.
Password Sending Trojan: This type has only one goal, which is to steal and collect all the passwords that the victim uses on his device and then send them by e-mail to the attacker.
Key Logger Trojan: This type only collects all the keystrokes the victim makes on the keyboard and then sends it to the attacker in an email or compiles it into a file for later downloading by the attacker.
Distributed Denial of Service Trojan: It is the latest type of Trojan, where the attacker exploits this type to carry out distributed attacks to disable important services or famous sites or other devices on the network so that the source of these attacks is the victims' devices and not the attacker himself. The attacker triggers the attack on the victims' devices one by one or uses a specific device that addresses all devices automatically.
Spam Relaying Trojan: This type exploits the victim's device and his mail account by sending annoying messages through the victim's device using his name and identity without his knowledge.
Ways of infection
There are several ways to infect Trojan programs, and I would like to note that the user may never feel that his device has been infected in the first place, but some methods and sources of infection with Trojan programs can be summarized through the following points:
Files spread on the Internet or by e-mail: This is the main source of the spread of the Trojan so that the Trojan program is attached to any other operating program, so the result is one program in the form of a game, a screenshot, a screen saver, or a popular program, and then it is sent to a mailing list or forum to be traded. Among users, these are some of the popular file extensions Trojans use to disguise (.exe, .com, .bat, .src).
Copied or unlocked programs: The attacker may remove the protection of one of the most popular and frequently requested programs and attach the Trojans to it, and then place it on a file server or site to be downloaded later by users.
Popular chat programs such as (ICQ) or (IRC): The use of non-updated versions of chat programs that allow the exchange of files may allow the attacker to send a file and run it on the victim's device without his knowledge, and receiving files from unknown persons poses a great danger to the recipient.
Direct access to the device: If the device is shared or not protected with a password, then anyone can enter the device physically and then download the Trojan program on your device without your knowledge.
The existence of problems or gaps in the Internet browser programs or e-mail programs: which allows the owners of the sites or e-mail senders to exploit these loopholes and download files without the knowledge of the owner of the device.
How to protect them
Network users must have security awareness and know the danger of these programs and not give excessive confidence in the network to anyone or any site so that they do not fall easy prey for attackers, and the user can protect his device from Trojan programs by following the following steps:
1- Using anti-Trojans and viruses.
2- Using the firewall program to control the programs that use the network.
3- Update anti-Trojans and viruses continuously and automatically.
4- Update the operating system and applications continuously and automatically.
5- Checking the device regularly and periodically against Trojan programs.
6- Not to download or open programs from unreliable or unknown websites or persons.
7- Not to use copied or unknown source programs.
8- Not to play the files spread on the Internet except after making sure of the file type and that it does not contain Trojans even if it is from a friend.
9- Download files and programs from the official website and not from alternative sites.
10- Beware of completely wary of protection decoding programs or generating codes or passwords.
11- Protect your device with a secret word so that others do not intrude on it or download programs without your knowledge.
I hope that I have succeeded in communicating the information.
Protegent360 Antivirus
Although Protegent360 Total Security is considered a relatively recent software in the protection and anti-virus sector, it is one of the fastest-growing antiviruses in the world. The free version of the program provides complete protection for your devices from viruses, ransomware threats, hackers, and malware, and blocking even the most sophisticated cyber attacks, all thanks to the comprehensive security suite that the program includes, from real-time malware detection and daily virus database updates to anti-ransomware and safe browsing And the default firewall.

Comments
Post a Comment