• Hail Guest!
    We're looking for Community Content Contribuitors to Stratics. If you would like to write articles, fan fiction, do guild or shard event recaps, it's simple. Find out how in this thread: Community Contributions
  • Greetings Guest, Having Login Issues? Check this thread!
  • Hail Guest!,
    Please take a moment to read this post reminding you all of the importance of Account Security.
  • Hail Guest!
    Please read the new announcement concerning the upcoming addition to Stratics. You can find the announcement Here!

OT: How do you get Trojans?

H

HaHa

Guest
Did an update on my anti virus and found more trojans on my computer than the backwall of a sex shop. How do these get on the computer? I havent been to any new or different sites in the past few months.
 

Petra Fyde

Peerless Chatterbox
Alumni
Stratics Veteran
Stratics Legend
Let's see.
The most popular site types for hackers to place trojan droppers are:
Code crack sites, game cheat sites, porn sites.
Other methods
emails with links that don't go to where they claim to go
emails with downloads
icq file transfers

I hope you don't do internet banking or shopping online with a credit card.
I'm not particularly technically adept so others can probably tell you a few more.
oh, the fact that none of the sites you've visited lately are new could mean one of the sites you do visit has been feeding you trojans regularly for months :D
 
H

HaHa

Guest
Thats whats so weird. I havent accepted any downloads and I only open work related emails on a city email account. I do the internet banking much change the password often since I can never remember what I changed it to the last time.
 

Petra Fyde

Peerless Chatterbox
Alumni
Stratics Veteran
Stratics Legend
A trojan dropper can be hidden in an advert and download itself with no input from you. One of our sons got one on my pc years ago trying to get a 'crack' for a game he wanted to play. He was forbidden to ever visit that site again! He had assured me it was safe because there was no download involved, just copy/paste the code from the page. He didn't download anything, but the advert at the top of the page did, in the background with no notification.
I didn't know I'd got it till AVG ran its daily check the next morning.
 

Touzoko

Certifiable
Stratics Veteran
Stratics Legend
a friend does a lot of music downloads- he warns that those are bad too.
I use McAfee. What are the better security suites on the market?
 

Skylark SP

Available Storage: 0
Stratics Veteran
Stratics Legend
HaHa, a lot of trojans are now being installed via banner ads or code injected by hackers via exploits, on legitimate web sites.

Recently, I spent most of a day removing a trojan from a good percentage of the workstations on the corporate network I administer. We have a good multi-level enterprise anti-malware product in place, and the systems are kept patched, and it still got in. One thing I found interesting, is that 2 computers (my own workstation was one of them) which did not get the trojan, were those on which I had installed a manual hosts file. The hosts file contains a list of websites that are mapped to the loopback IP address (which can't resolve) on the computer. MVPS.org maintains a hosts file of known advertising and malicious sites, that you can download. You can sign up for email notification when they update the list.

Go to this article for more info & exact instructions:
http://www.mvps.org/winhelp2002/hosts.htm

-Skylark
 

Wulf2k

Stratics Legend
Stratics Veteran
Stratics Legend
If you absolutely must visit sites of questionable virtue, do it in a sandbox.

http://www.sandboxie.com/

Delete the contents of the sandbox whenever you're done, and it's like you never did anything at all. Any downloads that you're sure of, you can move out of the sandbox before deleting. Anything that gets installed in the background gets put into the sandbox instead of into your actual files. You can also see if anything in the sandbox is still running after you 'think' everything should be exited.

I'll often run a virus inside of a sandbox (inside of a virtual machine, off of the network) to see what changes it makes, making it easier to remove. There are still theoretical ways to get out of the sandbox, but viruses are programmed to hit the widest range of machines, and they probably didn't waste time finding a vulnerability in a sandbox that 0.01% of people may use.
 

AEowynSP

Certifiable
Stratics Veteran
Stratics Legend
a friend does a lot of music downloads- he warns that those are bad too.
I use McAfee. What are the better security suites on the market?
My neighbor just turned me on to Avast I like it allot prior to that I was using AVG.
For anti malwaere malwearbytes, spybot SD and spyweare blaster.
 

Vortex

Slightly Crazed
Stratics Veteran
Stratics Legend
*Looks at title*

*Looks at who posted it*

Wow, not what I was expecting...
 

Wulf2k

Stratics Legend
Stratics Veteran
Stratics Legend
Even Magnums?

Only asking because that is all I use...

:-}
They always burst in my stomach halfway through the flight, then these bastards start crawling all over me...

http://i49.***********/iop7ux.jpg
 
Top