Malware is an annoying or dangerous program designed to covertly access a device without the knowledge of its owner. There are several types of malware: spyware, adware, phishing, Trojans, ransomware, viruses, worms, rootkits, and programs aimed at taking control of the browser.

Sources of malware

Malware often enters a device via the Internet or email. However, hacked websites, demo versions of games, music files, toolbars, various software, free subscriptions and everything that you download from the Internet to your device, which does not have protection against malware.

How to recognize malware

Slow operation, pop-up messages, spam or crashes often indicate that the device is infected with malware. To check if this is the case, you can use the malware scanner (it is part of all malware removal tools).

How to remove malware

The best way to get rid of the problem is to use a reliable malware removal tool that can be found in any quality antivirus product. Program Avast Free Antivirus and its Anti-Malware component can protect you from malware by quickly and easily removing it from your devices. It's not just a removal tool dangerous programs. This is also permanent protection from malicious attacks, acting in real time.

How to protect yourself from malware
  • Use powerful antivirus products that can also protect against malware.
  • Do not download files attached to email messages. mail from unknown senders.
Anti-Malware Software

Using a modern antivirus solution is the most effective method prevent, detect and remove malware from your computer. Most effective antivirus solution is Avast.

Malware-- any software, designed to obtain unauthorized access to the computing resources of the computer itself or to information stored on the computer, with the aim of unauthorized use of computer resources or harm to the owner of the information (or the owner of the computer) by copying, distorting, deleting or replacing information.

Malicious software is divided into three main classes: computer viruses, network worms, Trojan horses. Let's consider each of them in more detail.

Computer viruses

This class of malware is the most common among the rest.

A computer virus is a type of computer program distinctive feature which is the ability to reproduce (self-replication). In addition, viruses can damage or completely destroy all files and data controlled by the user on whose behalf the infected program was launched, as well as damage or even destroy the operating system with all files as a whole.

Usually, the user himself, who does not check antivirus program information that enters the computer, as a result of which, in fact, infection occurs. There are quite a few ways to "infect" a computer with a classic virus (external storage media, Internet resources, files distributed over the network)

Viruses are divided into groups according to two main features: by habitat, by the method of infection.

By habitat, viruses are divided into:

  • · File(injected into executable files)
  • · Boot(implemented in boot sector disk or to the sector containing the bootloader of the hard drive)
  • · Network(spread across computer network)
  • · Combined(for example, file-boot viruses that infect both files and the boot sector of the disk. These viruses have an original method of penetration and a complex algorithm of work)

According to the method of infection are divided into:

Network worms

The next big class of malware is called "Worms"

A network worm is malicious programming code, which distributes its copies over local and / or global networks in order to penetrate a computer, launch its copy on this computer and further distribute. To spread, worms use e-mail, irc-networks, lan, data exchange networks between mobile devices etc. Most worms are distributed in files (an attachment to an email, a link to a file). But there are also worms that spread in the form of network packets. Such varieties penetrate directly into the computer's memory and immediately begin to act resident. Several ways are used to penetrate the victim computer: independent (packet worms), user-based (social engineering), as well as various flaws in the security systems of the operating system and applications. Some worms have the properties of other types of malware (most often Trojans).

Classes of network worms:

Mail worms (Email-Worm). This is a malicious system that resides in a file attached to an email. The authors of the mail worm in any way induce to execute the attached file with the virus. He is disguised as new game, update, or popular program. By activating activity on your computer, the mail worm first sends its own copy by e-mail, using your address book, and then harms your computer.

  • · Internet pager worms (IM-Worm). The action of this "worm" almost completely repeats the method of distribution used by mail worms, only the carrier is not an email, but a message implemented in instant messaging programs
  • · Worms for file-sharing networks (P2P-Worm). To infiltrate a P2P network, the worm only needs to copy itself to a file sharing directory, which is usually located on the local machine. The P2P network takes care of the rest of the distribution work - when searching for files on the network, it will inform remote users about given file and provide a service for downloading it from an infected computer.

There are more complex worms of this type that mimic the network protocol of a particular file-sharing system and respond positively to search terms. At the same time, the worm offers its copy for download.

Using the first method, the "worm" searches the network for machines with resources open for writing and copies them. However, it can randomly find computers and try to open access to resources. To penetrate the second method, the "worm" looks for computers with installed software that has critical vulnerabilities. Thus, the worm sends a specially crafted packet (request), and part of the "worm" penetrates the computer, after which it downloads the full body file and launches it for execution.


Trojans or programs of the "Trojan horse" class are written with the aim of causing damage to the target computer by performing actions not authorized by the user: data theft, damage or deletion of confidential data, disruption of the PC or use of its resources for unseemly purposes.

Some Trojans are capable of independently overcoming the protection systems of a computer system in order to penetrate it. However, in most cases, they enter the PC along with another virus. Trojans can be considered as additional malware. Often, users themselves download Trojans from the Internet.

The cycle of activity of Trojans can be defined by the following stages:

  • - penetration into the system.
  • - activation.
  • - performing malicious activities.

Trojans differ among themselves in the actions they perform on an infected PC.

  • · Trojan-PSW. Purpose - Theft of passwords. This type Trojans can be used to search system files that store various confidential information (for example, passwords), "steal" registration information for various software.
  • · Trojan Downloader. Purpose - Delivery of other malicious programs. Activates programs downloaded from the Internet (run for execution, registration for autoload)
  • · Trojan-Dropper. Installation of other malicious files on the disk, their launch and execution
  • · Trojan-proxy. Provide anonymous access from the victim's PC to various Internet resources. Used to send spam.
  • · Trojan Spy. They are spyware. They carry out electronic spying on the user of an infected PC: the information entered, screenshots, a list of active applications, user actions are saved in a file and periodically sent to the attacker.
  • · Trojan(Other Trojans). They carry out other actions that fall under the definition of Trojans, for example, the destruction or modification of data, disruption of the PC.
  • · backdoor. Are utilities remote administration. Can be used to detect and transmit to an attacker confidential information, data destruction, etc.
  • · ArcBomb ("Bombs" in the archives). Cause abnormal behavior of archivers when trying to unpack data
  • Rootkit. Purpose - Hiding the presence in the operating system. With the help of program code, the presence of certain objects in the system is hidden: processes, files, registry data, etc.

Of these, spyware is the most widely used - Trojan Spy and RootKit (rootkits). Let's consider them in more detail.

Rootkits. AT Windows system Under RootKit it is customary to consider a program that is illegally introduced into the system, intercepts calls to system functions (API), and modifies system libraries. Interception of low-level APIs allows such a program to mask its presence in the system, protecting it from detection by the user and antivirus software.

Conventionally, all rootkit technologies can be divided into two categories:

  • Rootkits running in user mode (user-mode)
  • Rootkits running in kernel mode (kernel-mode)

Sometimes rootkits come in email attachments, masquerading as documents of various formats (for example, PDF). In fact, such a "imaginary document" is an executable file. Trying to open, the user activates the rootkit.

The second way of distribution is the sites subjected to hacker manipulation. The user opens a web page - and the rootkit gets into his computer. This is possible due to flaws in the security system of browsers. computer file program

Rootkits can be planted not only by intruders. There is a well-known case when the Sony Corporation built a kind of rootkit into its licensed audio CDs. Rootkits are essentially the majority software tools copy protection (and means to bypass these protections - for example, emulators of CD and DVD drives). They differ from "illegal" ones only in that they are not set secretly from the user.

Spyware. Such programs can perform a wide range of tasks, for example:

  • · Collect information about Internet usage habits and most frequently visited sites (tracking program);
  • · Memorize keystrokes on the keyboard (keyloggers) and record screenshots of the screen (screen scraper) and send information to the creator in the future;
  • · Be used for unauthorized analysis of the state of security systems - scanners of ports and vulnerabilities and crackers of passwords;
  • · Change the parameters of the operating system - rootkits, control interceptors, etc. - resulting in a decrease in the speed of the Internet connection or loss of connection as such, opening other home pages or deleting certain programs;
  • · Redirect browser activity, which entails visiting websites blindly with the risk of viruses.

Remote control and management programs can be used for remote technical support or access to your own resources that are located on a remote computer.

Passive tracking technologies can be useful for personalizing the web pages a user visits.

These programs are not viruses in themselves, but for one reason or another they are included in anti-virus databases. As a rule, this small programs, which have a small area of ​​​​influence and are ineffective as viruses.

  • · Adware is a generic name for software that forces ads to appear.
  • · Bad-Joke - bad jokes. Programs that frighten the user with unexpected and non-standard opening or use graphics. It can also be programs that give false messages about formatting a disk or stopping the program, etc.
  • · Sniffer - a program designed to intercept and then analyze network traffic.
  • · SpamTool - a program designed to send spam (as a rule, the program turns the computer into a spam machine).
  • · IM-Flooder - a program that allows you to send various messages in large quantities to a given IM-messenger number.
  • · VirTool - utilities designed to facilitate writing computer viruses and to study them for hacker purposes.
  • · DoS (Denial of service) - a malicious program designed to carry out a Denial of Service attack on a remote server.
  • FileCryptor, PolyCryptor - hacker tools, which are used to encrypt other malicious programs in order to hide their contents from anti-virus scanning.

Malware(in the jargon of anti-virus services " malware", English. malware, malicious software- "malicious software") - any software designed to gain unauthorized access to the computing resources of the computer itself or to information stored on the computer, with the aim of using the computer resources unauthorized by the owner or causing harm (damage) to the owner of the information, and / or to the owner of the computer, and / or the owner of the computer network, by copying, distorting, deleting or replacing information.


  • badware (bad- bad and (soft) ware- software) - bad software.
  • computer contaminant (computer- computer and contaminant contaminant) is a term for malicious software that is used in the laws of some US states, such as California and West Virginia.
  • crimeware (crime- crime and (soft ware- software) - a class of malicious programs specially designed to automate financial crimes. It is not synonymous with the term malware (the meaning of the term malware is broader), but all programs related to crimeware are malicious.


By its basic definition, malware is designed to gain unauthorized access to information, bypassing existing access control rules. Federal Service on Technical and Export Control (FSTEC of Russia) defines these concepts as follows:

  • Authorized access to information(English authorized access to information) - access to information that does not violate the rules of access control.
  • Unauthorized access to information(eng. unauthorized access to information) - access to information that violates the rules of access control using standard tools provided by computer technology or automated systems. Regular means is understood as a set of software, firmware and technical support for computer equipment or automated systems.
  • Access control rules(eng. access mediation rules) - a set of rules governing the access rights of access subjects to access objects

Other definitions of the term "malware"

According to Article 273 of the Criminal Code Russian Federation(“Creating, using and distributing malware for computers”), the definition of malware is as follows: “…computer programs or modifications to existing programs, knowingly leading to unauthorized destruction, blocking, modification or copying of information, disruption of the computer, computer system or their network ... "

It should be noted that the current wording of Article 273 interprets the concept of harmfulness extremely broadly. When the introduction of this article into the Criminal Code was discussed, it was understood that “unauthorized” would be considered actions of the program that were not explicitly approved. user this program. However, the current court practice also classifies as malicious programs that modify (with the user's permission) executable files and / or databases of other programs, if such modification is not allowed by their copyright holders. At the same time, in a number of cases, in the presence of a principled position of the defense and a competently conducted examination, a broad interpretation of Article 273 was declared illegal by the court.

Microsoft defines the term "malicious software" as follows: "Malware is short for 'malicious software', commonly used as a generic term for any software that is specifically designed to cause damage. a separate computer, server, or computer network, whether it's a virus, spyware, etc."

Malware classification

Each antivirus software company has its own corporate classification and nomenclature of malware. The classification given in this article is based on the nomenclature of Kaspersky Lab.

By malicious load