How Trojan Works ?
Trojans typically consist of two parts, a client part and a server part. When a victim (unknowingly) runs a Trojan server on his machine, the attacker then uses the client part of that Trojan to connect to the server module and start using the Trojan. The protocol usually used for communications is TCP, but some Trojans' functions use other protocols, such as UDP, as well. When a Trojan server runs on a victim\92s computer, it (usually) tries to hide somewhere on the computer; it then starts listening for incoming connections from the attacker on one or more ports, and attempts to modify the registry and/or use some other auto-starting method.
It is necessary for the attacker to know the victim\92s IP address to connect to his/her machine. Many Trojans include the ability to mail the victim\92s IP and/or message the attacker via ICQ or IRC. This system is used when the victim has a dynamic IP, that is, every time he connects to the Internet, he is assigned a different IP (most dial-up users have this). ADSL users have static IPs, meaning that in this case, the infected IP is always known to the attacker; this makes it considerably easier for an attacker to connect to your machine.
Most Trojans use an auto-starting method that allows them to restart and grant an attacker access to your machine even when you shut down your computer.
How Trojan Horses Are Installed ?
Infection from Trojans is alarmingly simple. Following are very common ways to become infected that most computer users perform on a very regular basis.
The Removal :-
Antivirus software is designed to detect and delete Trojan horses ideally preventing them from ever being installed.
1) NetBus :-
2) Back Orifice XP :-
3) SubSeven / Sub7 :-
4) Beast :-
Trojans typically consist of two parts, a client part and a server part. When a victim (unknowingly) runs a Trojan server on his machine, the attacker then uses the client part of that Trojan to connect to the server module and start using the Trojan. The protocol usually used for communications is TCP, but some Trojans' functions use other protocols, such as UDP, as well. When a Trojan server runs on a victim\92s computer, it (usually) tries to hide somewhere on the computer; it then starts listening for incoming connections from the attacker on one or more ports, and attempts to modify the registry and/or use some other auto-starting method.
It is necessary for the attacker to know the victim\92s IP address to connect to his/her machine. Many Trojans include the ability to mail the victim\92s IP and/or message the attacker via ICQ or IRC. This system is used when the victim has a dynamic IP, that is, every time he connects to the Internet, he is assigned a different IP (most dial-up users have this). ADSL users have static IPs, meaning that in this case, the infected IP is always known to the attacker; this makes it considerably easier for an attacker to connect to your machine.
Most Trojans use an auto-starting method that allows them to restart and grant an attacker access to your machine even when you shut down your computer.
How Trojan Horses Are Installed ?
Infection from Trojans is alarmingly simple. Following are very common ways to become infected that most computer users perform on a very regular basis.
- Software Downloads
- Websites containing executable content (ActiveX control)
- Email Attachments
- Application Exploits (Flaws in a web applications)
- Social Engineering Attacks
The Removal :-
Antivirus software is designed to detect and delete Trojan horses ideally preventing them from ever being installed.
-: Popular Trojans :-
1) NetBus :-
- Latest Version: NetBus 2.10 Pro
- Developer: Carl-Fredrik Neikter
- Default Port: 20034 (variable)
- Language: Delphi
- Operating System: Windows 95/98, NT4 or later
- Type: Remote Access
- Download: NB2ProBeta.zip => CONTACT OUR CUSTOMER CARE HELPLINES
2) Back Orifice XP :-
- Latest Version: BOXP Beta 7
- Developer: Javier Aroche
- Default Port: 15380
- Language: Microsoft Visual C++ 6.0
- Operating System: Windows 95/98/ME/NT/2000/XP
- Type: Remote Access
- Download: boxp_beta7_bin.zip => CONTACT OUR CUSTOMER CARE HELPLINES
3) SubSeven / Sub7 :-
- Latest Version: SubSeven 2.2
- Developer: Mobman
- Default Port: 1080, 1369, 5873, 27374 (variable)
- Language: Delphi
- Operating System: Windows 95/98/ME/NT/2000
- Type: Remote Access, Keylogger, Eavesdropper, Sniffer, Proxy server, FTP server
- Download: Subseven.2.2.zip => CONTACT OUR CUSTOMER CARE HELPLINES
4) Beast :-
- Latest Version: Beast 2.07
- Developer: Tataye
- Default Port: 6666
- Language: Delphi
- Operating System: Windows 95/98/ME/NT/2000/XP
- Type: Remote Access, Keylogger
- Download: Beast_2.07.rar => CONTACT OUR CUSTOMER CARE HELPLINES