Greetings Viewers,
You may have read my popular blog post What do these terms mean?
But I do not think I did a few pieces of malware on that list justice, so this is going to be the first in what I hope to be a series of posts on some kinds of malware that I think deserve a better description. And I can think of no better place to start then on my favorite kind of malware: Rogue Antivirus Software.
Rogue Antivirus Software, also called Rogues, or Rogue AVs, are pieces of malware that download and install themselves to your computer without your knowledge or consent. Once the rogue is activated or turned on, it starts a simulated scan of your hard drive. Most rogues detect false infections, that is, infections that are not actually on your computer. So the most important thing to know is that none of the malware it reports as being on your PC is actually on your PC, the program is just messing with you.
The rogue often tells you that you have a large amount of "infections," (100 or more is not uncommon) and demands payment for the "removal" of the "infections." Most rogues disable program execution in some way, such as blocking task manager, web browsers, regedit, (A internal registry editor in Windows) and more. The license for the rogue often varies in price, anywhere from $39.95 to $85.95. Some rogues also open your internet browser and take you to some rather.... unsavory websites to reinforce the lie that your system is infected. Rogues often block you from going to specific websites, claiming that they are infected.
Rogues often have misspellings, bad grammar, and the like. This is often the first clue that the program is a rogue, not a real antivirus software. Rogues often attempt to impersonate real antivirus software in an attempt to make you believe that the rogue is actual antivirus software that you need to pay for to get rid of that malware on your computer. Rogues are often installed along with a rootkit or Trojan, and removal can be tricky depending on how many programs the rogue blocks.
"Education is the most powerful weapon which you can use to change the world" Nelson Mandela
Showing posts with label What's in a name?. Show all posts
Showing posts with label What's in a name?. Show all posts
Sunday, May 26, 2013
Friday, March 22, 2013
What's In A Name: Rootkits
For the second part of my What's In A Name series, we take a look at the cornerstone of malware: Rootkits.
First, what is a rootkit?
A rootkit is a piece of malware that operates somewhat like an elite Special Forces unit. It gets in, communicates with headquarters, recons defenses, and messes stuff up so that the main strike force coming in later will have an easy time.
Rootkits are like Special Forces units in another way as well: Try to remove them, and they go wild. This is why every rootkit remover worth his or her salt warns that removing a rootkit could lead to problems with the operating system, to the point where it will not boot.
This is because the rootkit gets into the system and replaces critical system files with those under the control of the rootkit. And when these replaced files are removed along with the rootkit, the system can be rendered inoperable.
This is why rootkits are some of the most difficult malware to remove. Do one thing wrong, and you could break the computer you are trying to fix.
Hope this clears the issue of what a rootkit is up.
To look at Part One of What's In A Name, go here.
To look at my definition post which contains a brief summery of some of the terms used when talking about malware, go here.
If you have a question or just want to tell me how awesome I am, feel free to comment in the space below. It's FREE!
First, what is a rootkit?
A rootkit is a piece of malware that operates somewhat like an elite Special Forces unit. It gets in, communicates with headquarters, recons defenses, and messes stuff up so that the main strike force coming in later will have an easy time.
Rootkits are like Special Forces units in another way as well: Try to remove them, and they go wild. This is why every rootkit remover worth his or her salt warns that removing a rootkit could lead to problems with the operating system, to the point where it will not boot.
This is because the rootkit gets into the system and replaces critical system files with those under the control of the rootkit. And when these replaced files are removed along with the rootkit, the system can be rendered inoperable.
This is why rootkits are some of the most difficult malware to remove. Do one thing wrong, and you could break the computer you are trying to fix.
Hope this clears the issue of what a rootkit is up.
To look at Part One of What's In A Name, go here.
To look at my definition post which contains a brief summery of some of the terms used when talking about malware, go here.
If you have a question or just want to tell me how awesome I am, feel free to comment in the space below. It's FREE!
Subscribe to:
Posts (Atom)