Mar

15

2010

Conditionally Malware In Our PC.

Published by Author in category Computers | Leave a Comment

I wish to tell you about such programs as Riskware and Pornware which are conditionally malware.
The class of programs Riskware are legitimate programs (some of them are freely available and widely used for lawful purposes), which, nevertheless, in the hands of an attacker able to cause harm to the user and his data.

In the list of programs of class Riskware can find legitimate remote administration tool, a client program IRC, dialer-daylery, -daunloaders, monitors any activity, utilities for working with passwords, as well as numerous Internet Services servers FTP, Web, Proxy, and Telnet.

All these programs are not malicious by themselves but have a functional, which could be used by attackers to cause harm to users.

Take, for example, a program for remote administration WinVNC. This program allows accessing to the interface of the remote computer and is used to remotely control and monitor a remote machine.

Thus, this program is legal, freely available and necessary in the work of well-behaved system administrators or other technical specialists.

As another example, utility mIRC. This is a legal program, which is the IRC-client is given.

The criminals can benefit by extended functional of utility mIRC – Trojans regularly appear (in particular, backdoors), using mIRC functions in their work.

Thus, any IRC-backdoor is capable of without the user’s knowledge to finish in the configuration file mIRC own scripts and successfully execute its payload on the affected machine. The user of mIRC will not even suspect the operation on his computer malicious Trojan horse program.

Often, malicious programs install themselves mIRC client on a user’s computer for later use it for their own purposes. As the location mIRC in this case, is usually the Windows folder and its subfolders. Detection mIRC in these locations almost certainly indicates the fact infecting your computer with some malware.

Pornware.
Program class Pornware includes utilities one way or another connected with the display information to users of a pornographic nature.

At this point in the class three behaviors are allocated: Porn-Dialer, Porn-Downloader and Porn-Tool. Daylery dials to pornographic telephone services, and they download pornography on the user’s computer. The last class of behavior Pornware includes all sorts of tools, one way or another connected with the search and display of pornographic materials (eg, special toolbar for Internet browser and special video players).

Program of class Pornware can be installed by the user on his computer deliberately in order to seek and obtain pornographic information. In this case, they are not malicious.

On the other hand, these same programs can be installed on the user’s computer by hackers – through the use of operating system vulnerabilities and your Internet browser or by malicious Trojans classes Trojan-Downloader and Trojan-Dropper. This is done usually to advertising paid pornographic websites and online services for which the user never paid attention to.

If you need to get a nice free adware block or any helpful information about the topic of spyware blockers, please visit the hyperlinked site.

And it is very important that you follow a final piece of advice – today the online technologies give you a really unique chance to choose what you need for the best price on the market. Strange, but most of the people don’t use this opportunity. In real life it means that you must use all the tools of today to get any information that you need.

Search Google and other search engines. Visit social networks and have a look on the accounts that are relevant to your topic. Go to the niche forums and join the online discussion. All this will help you to build up a true vision of this market. Thus, giving you a real chance to make a smart and nicely balanced decision.

And also sign up to the RSS feed on this blog, because we will do the best to keep updating this blog with new publications about the market of spyware blockers and any changes on it.

Comments are closed