 |
Trojan Classes
As known, Trojan horse is a virus, that usually distributed over Internet as small utilities, screen-savers, wallpaper pictures etc. Once run on your system Trojan infects the computer and opens "virtual gates" to your machine.
Most Trojans have two parts: server and client. The server part is a program or file that is installed on the perspective but unknowing victim's machine to infect it. The client part is on the attacker's system. This combination of software establishes a connection between the victim's machine and the attacker via the Internet.
However, not all Trojans act this way. Considering the variety of existing Trojans they can be divided into groups or classes. Right now there're seven classes of Trojans: Remote access Trojans, Mail Trojans, FTP Trojans, Telnet Trojans, Keylogger Trojans, Key Trojans, Form Trojans.
Remote Access Trojans
Most widespread and, obviously the most dangerous class of Trojans. Trojans of that class have two parts: server and client. After infecting computer of victim Remote Access Trojans allow an attacker to perform almost the same actions on an infected computer as does its owner: copy, view and delete information from the hard drive, run applications, change configuration settings, control the infected computer's hardware and much more.
Mail Trojans
Another popular class of Trojans, but unlike remote access Trojans Mail Trojans work in server mode only. The main goal of Mail Trojans is recording of certain data such as passwords and logins user enters to connect to Internet or during web-surfing. After Mail Trojan have collected enough data it sends it to cracker like a common mail client. That's why such Trojans called Mail. Its very hard to spot any signs of these Trojans because Mail Trojan use its own engine to send its messages to cracker.
FTP Trojans
Trojans of this class work in server mode only. FTP Trojans open to cracker FTP access to infected system. Using FTP Trojans cracker can download and upload any files on infected machine.
Telnet Trojan
This class of Trojans works in server mode only and allows Telnet access to infected computer. Telnet Trojan allows execute DOS command on infected machine.
Keylogger Trojans
This class of Trojans "remembers" all input keyboard's data (commands) and stores it in special log file. The intruder can access that file and get the info about passwords and other data that were typed in by user.
Fake Trojans
Trojans of this class use fake dialog windows and other pop-up windows to trick the user and make him type in his user name and password. Then this data is stored in a file that intruder can access and view.
Form Trojans
After being installed on a victim's computer Form Trojans get certain personal data such as IP-address, passwords and other valuable information, stored on infected machine. Then during internet connection Form Trojan establishes a connection with intruder's web site and sends a form with all obtained data. The user of infected system will see no signs of Trojan's work and will know nothing about stealing info from his computer.
|
 |