0% found this document useful (0 votes)
14 views7 pages

Understanding Computer Viruses and Types

The document provides an overview of computer viruses, defining them as self-replicating programs that can infect computers without user consent. It discusses various types of viruses, their infection strategies, signs of infection, and the importance of antivirus software for detection and prevention. Additionally, it highlights the vulnerabilities of operating systems and emphasizes the need for regular updates and backups to safeguard against malware threats.

Uploaded by

hassanbereir
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
14 views7 pages

Understanding Computer Viruses and Types

The document provides an overview of computer viruses, defining them as self-replicating programs that can infect computers without user consent. It discusses various types of viruses, their infection strategies, signs of infection, and the importance of antivirus software for detection and prevention. Additionally, it highlights the vulnerabilities of operating systems and emphasizes the need for regular updates and backups to safeguard against malware threats.

Uploaded by

hassanbereir
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

KAMPALA Western Campus

INTERNATIONAL P.O Box 71, Bushenyi, Uganda


E-mail: kiu@[Link]
UNIVERSITY

SCHOOL OF ENGINEERING AND APPLIED SCIENCE

DEPARTMENT OF ELECTRICAL, TELECOMMUNICATION


AND COMPUTER ENGINEERING

PROGRAM: ALL

COURSE UNIT: COMPUTER FUNDAMENTALS (UCC1100)

YEAR: ONE

SEMESTER: ONE

MODULE 2: COMPUTER VIRUS


3.1 Computer Virus
A computer virus is a computer program that can copy itself and infect a computer without
the permission or knowledge of the owner. The term "virus" is also commonly but
erroneously used to refer to other types of malware, adware, and spyware programs that do
not have the reproductive ability. A true virus can only spread from one computer to another
(in some form of executable code) when its host is taken to the target computer; for instance
because a user sent it over a network or the Internet, or carried it on a removable medium
such as a floppy disk, CD, DVD, or USB drive. Viruses can increase their chances of
spreading to other computers by infecting files on a network file system or a file system that
is accessed by another computer.

The term "computer virus" is sometimes used as a catch-all phrase to include all types of
malware. Malware includes computer viruses, worms, trojan horses, most rootkits, spyware,
dishonest adware, crimeware, and other malicious and unwanted software), including true
viruses. Viruses are sometimes confused with computer worms and Trojan horses, which are
technically different. A worm can exploit security vulnerabilities to spread itself to other
computers without needing to be transferred as part of a host, and a Trojan horse is a program
that appears harmless but has a hidden agenda. Worms and Trojans, like viruses, may cause
harm to either a computer system's hosted data, functional performance, or networking
throughput, when they are executed. Some viruses and other malware have symptoms
noticeable to the computer user, but many are surreptitious.

Most personal computers are now connected to the Internet and to local area networks,
facilitating the spread of malicious code. Today's viruses may also take advantage of network

Mr. Enerst Edozie, Tel: +256752302619 / +256788897621, email: [Link]@[Link]


KAMPALA Western Campus
INTERNATIONAL P.O Box 71, Bushenyi, Uganda
E-mail: kiu@[Link]
UNIVERSITY
services such as the World Wide Web, e-mail, Instant Messaging, and file sharing systems to
spread.

A computer virus is usually hard to detect if it's disguised as a harmless file, in the case of a
Trojan horse virus. This type of virus doesn't replicate itself like most viruses, but instead
opens your computer up to malicious imposters. Leaving you to wonder, how can you tell if
you're computer is infected?

Luckily, your computer after coming in contact with a virus or worm will display some
symptoms and signs of infection. It is particularly useful to know the signs that indicate an
infection. Because you can unintentionally introduce a virus to your computer at anytime
when you run an infected program or open an email attachment. To guard against this you
need a good anti-virus program

3.1.1. Signs of a Computer Infection

Some signs that may indicate that your computer is infected include:

1. Your computer functions slower than normal


2. Your computer responds slowly and freezes often
3. Your computer restarts itself often
4. You see uncommon error messages, distorted menus, and dialog boxes
5. You notice applications on your computer fail to work correctly
6. You fail to print correctly

3.1.2. Types of Viruses

What are the types of computer viruses and worms that you're computer can come into
contact with? The list of viruses is quiet long and complex. So, we simplified the list by
mentioning few broad categories of viruses that can put your computer and all your personal
data on it, in danger. These computer viruses include:

Boot Sector viruses: A boot sector virus infects diskettes and hard drives. All disks and hard
drives contain smaller sections called sectors. The first sector is called the boot. The boot
carries the Mater Boot Record (MBR). MBR functions to read and load the operating system.
So, if a virus infects the boot or MBR of a disk, such as a floppy disk, your hard drive can
become infected, if you re-boot your computer while the infected disk is in the drive. Once
your hard drive is infected all diskettes that you use in your computer will be infected. Boot
sector viruses often spread to other computers by the use of shared infected disks and pirated
software applications. The best way to disinfect your computer of the boot sector virus is by
using antivirus software.

Program viruses: A program virus becomes active when the program files (usually with
extensions .BIN, .COM, .EXE, .OVL, .DRV) carrying the virus is opened. Once active, the
virus will make copies of it and will infect other programs on the computer.

Mr. Enerst Edozie, Tel: +256752302619 / +256788897621, email: [Link]@[Link]


KAMPALA Western Campus
INTERNATIONAL P.O Box 71, Bushenyi, Uganda
E-mail: kiu@[Link]
UNIVERSITY
Multipartite viruses: A multipartite virus is a hybrid of a Boot Sector and Program viruses.
It infects program files and when the infected program is active it will affect the boot record.
So the next time you start up your computer it'll infect your local drive and other programs on
your computer.

Stealth viruses: A stealth virus can disguise itself by using certain tactics to prevent being
detected by antivirus software. These tactics include altering its file size, concealing itself in
memory, and so on. This type of virus is nothing new, in fact, the first computer virus,
dubbed Brain, was a stealth virus. A good antivirus should be able to detect a stealth virus
lurking on your hard drive by checking the areas the virus infected and evidence in memory.

Polymorphic viruses: A polymorphic virus acts like a chameleon, changing its virus
signature (also known as binary pattern) every time it multiples and infects a new file. By
changing binary patterns, a polymorphic virus becomes hard to detect by an antivirus
program.

Macro Viruses: A macro virus is programmed as a macro embedded in a document. Many


applications, such as Microsoft Word and Excel, support macro languages. Once a macro
virus gets on to your computer, every document you produce will become infected. This type
of virus is relatively new and may slip by your antivirus software if you don't have the most
recent version installed on your computer. .

Active X and Java Control: Some users do not know how to manage and control their web
browser to allow or prohibit certain functions to work, such as enabling or disabling sound,
pop ups, and so on. Leaving your computer in danger of being targeted by unwanted software
or adware floating in cyberspace.

3.1.4. Infection strategies


In order to replicate itself, a virus must be permitted to execute code and write to memory.
For this reason, many viruses attach themselves to executable files that may be part of
legitimate programs. If a user attempts to launch an infected program, the virus' code may be
executed simultaneously. Viruses can be divided into two types based on their behavior when
they are executed. Nonresident viruses immediately search for other hosts that can be
infected, infect those targets, and finally transfer control to the application program they
infected. Resident viruses do not search for hosts when they are started. Instead, a resident
virus loads itself into memory on execution and transfers control to the host program. The
virus stays active in the background and infects new hosts when those files are accessed by
other programs or the operating system itself.

Mr. Enerst Edozie, Tel: +256752302619 / +256788897621, email: [Link]@[Link]


KAMPALA Western Campus
INTERNATIONAL P.O Box 71, Bushenyi, Uganda
E-mail: kiu@[Link]
UNIVERSITY
Nonresident viruses

Nonresident viruses can be thought of as consisting of a finder module and a replication


module. The finder module is responsible for finding new files to infect. For each new
executable file the finder module encounters, it calls the replication module to infect that file

Resident viruses

Resident viruses contain a replication module that is similar to the one that is employed by
nonresident viruses. This module, however, is not called by a finder module. The virus loads
the replication module into memory when it is executed instead and ensures that this module
is executed each time the operating system is called to perform a certain operation. the
replication module can be called, for example, each time the operating system executes a file.
In this case the virus infects every suitable program that is executed on the computer.

Resident viruses are sometimes subdivided into a category of fast infectors and a category of
slow infectors. Fast infectors are designed to infect as many files as possible. A fast infector,
for instance, can infect every potential host file that is accessed. This poses a special problem
when using anti-virus software, since a virus scanner will access every potential host file on a
computer when it performs a system-wide scan. If the virus scanner fails to notice that such a
virus is present in memory the virus can "piggy-back" on the virus scanner and in this way
infect all files that are scanned. Fast infectors rely on their fast infection rate to spread. The
disadvantage of this method is that infecting many files may make detection more likely,
because the virus may slow down a computer or perform many suspicious actions that can be
noticed by anti-virus software. Slow infectors, on the other hand, are designed to infect hosts
infrequently. Some slow infectors, for instance, only infect files when they are copied. Slow
infectors are designed to avoid detection by limiting their actions: they are less likely to slow
down a computer noticeably and will, at most, infrequently trigger anti-virus software that
detects suspicious behavior by programs. The slow infector approach, however, does not
seem very successful.

3.1.5. Methods to avoid detection


In order to avoid detection by users, some viruses employ different kinds of deception. Some
old viruses, especially on the MS-DOS platform, make sure that the "last modified" date of a
host file stays the same when the file is infected by the virus. This approach does not fool
anti-virus software; however, especially those which maintain and date cyclic redundancy
checks on file changes.

Some viruses can infect files without increasing their sizes or damaging the files. They
accomplish this by overwriting unused areas of executable files. These are called cavity
viruses. For example the CIH virus, or Chernobyl Virus, infects Portable Executable files.
Because those files have many empty gaps, the virus, which was 1 KB in length, did not add
to the size of the file.

Mr. Enerst Edozie, Tel: +256752302619 / +256788897621, email: [Link]@[Link]


KAMPALA Western Campus
INTERNATIONAL P.O Box 71, Bushenyi, Uganda
E-mail: kiu@[Link]
UNIVERSITY

Some viruses try to avoid detection by killing the tasks associated with antivirus software
before it can detect them.

As computers and operating systems grow larger and more complex, old hiding techniques
need to be updated or replaced. Defending a computer against viruses may demand that a file
system migrate towards detailed and explicit permission for every kind of file access.

3.1.6 Vulnerability and countermeasures


The vulnerability of operating systems to viruses

Just as genetic diversity in a population decreases the chance of a single disease wiping out a
population, the diversity of software systems on a network similarly limits the destructive
potential of viruses.

This became a particular concern in the 1990s, when Microsoft gained market dominance in
desktop operating systems and office suites. The users of Microsoft software (especially
networking software such as Microsoft Outlook and Internet Explorer) are especially
vulnerable to the spread of viruses. Microsoft software is targeted by virus writers due to their
desktop dominance, and is often criticized for including many errors and holes for virus
writers to exploit. Integrated and non-integrated Microsoft applications (such as Microsoft
Office) and applications with scripting languages with access to the file system (for example
Visual Basic Script (VBS), and applications with networking features) are also particularly
vulnerable.

Although Windows is by far the most popular operating system for virus writers, some
viruses also exist on other platforms. Any operating system that allows third-party programs
to run can theoretically run viruses. Some operating systems are less secure than others.
Unix-based OS's (and NTFS-aware applications on Windows NT based platforms) only allow
their users to run executables within their own protected memory space.

An Internet based research revealed that there were cases when people willingly pressed a
particular button to download a virus. Security analyst Didier Stevens ran a half year
advertising campaign on Google AdWords which said "Is your PC virus-free? Get it infected
here!". The result was 409 clicks

As of 2006, there are relatively few security exploits targeting Mac OS X (with a Unix-based
file system and kernel). The number of viruses for the older Apple operating systems, known
as Mac OS Classic, varies greatly from source to source, with Apple stating that there are
only four known viruses, and independent sources stating there are as many as 63 viruses.
Virus vulnerability between Macs and Windows is a chief selling point, one that Apple uses
in their Get a Mac advertising. In January 2009, Symantec announced discovery of a trojan

Mr. Enerst Edozie, Tel: +256752302619 / +256788897621, email: [Link]@[Link]


KAMPALA Western Campus
INTERNATIONAL P.O Box 71, Bushenyi, Uganda
E-mail: kiu@[Link]
UNIVERSITY
that targets [Link] discovery did not gain much coverage until April 2009. Windows and
Unix have similar scripting abilities, but while Unix natively blocks normal users from
having access to make changes to the operating system environment, older copies of
Windows such as Windows 95 and 98 do not. In 1997, when a virus for Linux was released –
known as "Bliss" – leading antivirus vendors issued warnings that Unix-like systems could
fall prey to viruses just like Windows. The Bliss virus may be considered characteristic of
viruses – as opposed to worms – on Unix systems. Bliss requires that the user run it explicitly
(so it is a trojan), and it can only infect programs that the user has the access to modify.
Unlike Windows users, most Unix users do not log in as an administrator user except to
install or configure software; as a result, even if a user ran the virus, it could not harm their
operating system. The Bliss virus never became widespread, and remains chiefly a research
curiosity. Its creator later posted the source code to Usenet, allowing researchers to see how it
worked.

The role of software development

Because software is often designed with security features to prevent unauthorized use of
system resources, many viruses must exploit software bugs in a system or application to
spread. Software development strategies that produce large numbers of bugs will generally
also produce potential exploits.

3.1.7 Anti-virus software and other preventive measures


Many users install anti-virus software such as Macfee , AVG, Avast, Kaspersky e.t.c that can
detect and eliminate known viruses after the computer downloads or runs the executable.
There are two common methods that an anti-virus software application uses to detect viruses.
The first, and by far the most common method of virus detection is using a list of virus
signature definitions. This works by examining the content of the computer's memory (its
RAM, and boot sectors) and the files stored on fixed or removable drives (hard drives, floppy
drives), and comparing those files against a database of known virus "signatures". The
disadvantage of this detection method is that users are only protected from viruses that pre-
date their last virus definition update. The second method is to use a heuristic algorithm to
find viruses based on common behaviors. This method has the ability to detect viruses that
anti-virus security firms have yet to create a signature for.

Some anti-virus programs are able to scan opened files in addition to sent and received e-
mails 'on the fly' in a similar manner. This practice is known as "on-access scanning." Anti-
virus software does not change the underlying capability of host software to transmit viruses.
Users must update their software regularly to patch security holes. Anti-virus software also
needs to be regularly updated in order to prevent the latest threats.

One may also minimise the damage done by viruses by making regular backups of data (and
the operating systems) on different media, that are either kept unconnected to the system
(most of the time), read-only or not accessible for other reasons, such as using different file

Mr. Enerst Edozie, Tel: +256752302619 / +256788897621, email: [Link]@[Link]


KAMPALA Western Campus
INTERNATIONAL P.O Box 71, Bushenyi, Uganda
E-mail: kiu@[Link]
UNIVERSITY
systems. This way, if data is lost through a virus, one can start again using the backup (which
should preferably be recent).

If a backup session on optical media like CD and DVD is closed, it becomes read-only and
can no longer be affected by a virus (so long as a virus or infected file was not copied onto
the CD/DVD). Likewise, an operating system on a bootable CD can be used to start the
computer if the installed operating systems become unusable. Backups on removable media
must be carefully inspected before restoration. The Gammima virus, for example, propagates
via removable flash drives.

Another method is to use different operating systems on different file systems. A virus is not
likely to affect both. Data backups can also be put on different file systems. For example,
Linux requires specific software to write to NTFS partitions, so if one does not install such
software and uses a separate installation of MS Windows to make the backups on an NTFS
partition, the backup should remain safe from any Linux viruses (unless they are written to
specifically provide this capability). Likewise, MS Windows can not read file systems like
ext3, so if one normally uses MS Windows, the backups can be made on an ext3 partition
using a Linux installation.

3.1.8. Recovery methods


Once a computer has been compromised by a virus, it is usually unsafe to continue using the
same computer without completely reinstalling the operating system. However, there are a
number of recovery options that exist after a computer has a virus. These actions depend on
severity of the type of virus.

3.1.9. Virus removal


One possibility on Windows Me, Windows XP and Windows Vista is a tool known as
System Restore, which restores the registry and critical system files to a previous checkpoint.
Often a virus will cause a system to hang, and a subsequent hard reboot will render a system
restore point from the same day corrupt. Restore points from previous days should work
provided the virus is not designed to corrupt the restore files or also exists in previous restore
points. Some viruses, however, disable system restore and other important tools such as Task
Manager and Command Prompt. An example of a virus that does this is CiaDoor.

Administrators have the option to disable such tools from limited users for various reasons
(for example, to reduce potential damage from and the spread of viruses). The virus modifies
the registry to do the same, except, when the Administrator is controlling the computer, it
blocks all users from accessing the tools. When an infected tool activates it gives the message
"Task Manager has been disabled by your administrator.", even if the user trying to open the
program is the administrator. Users running a Microsoft operating system can access
Microsoft's website to run a free scan, provided they have their 20-digit registration number.

Mr. Enerst Edozie, Tel: +256752302619 / +256788897621, email: [Link]@[Link]

You might also like