Tuesday, April 8, 2008

How Does A Virus Work

Executable Virus
As the name suggests, this virus works by infecting executable files. Executables generally included files with extensions of .vbs, .exe, .com, .sys, .dll, .bat, .reg, and others. DO NOT OPEN ANY OF THESE FILES UNLESS YOU KNOW THE PERSON AND HAVE VIRUS SCANNED THE FILE! Another area that the executable virus looks to infect is the boot sector of either a hard disk or a floppy disk.In order for an executable virus to do any damage, it must first be loaded into the computer's memory. It accomplishes this as follows:

Attaches itself to an executable file, thereby infecting it.Sits on that executable file, going unnoticed, while waiting for you to execute that file.Once the infected file is executed, the virus is executed itself. That is, the virus is loaded into the computer's memory.Once in memory, the virus program can operate, carrying out the instructions of the progammer.

An executable virus may attach to the boot sector of a hard disk or floppy disk. This boot sector virus is much more serious than other viruses since it loads automatically into memory and can begin working each time you start your computer. Macro VirusA macro virus is a virus that needs another computer program before it can operate. Generally, you will only find Macro viruses infecting Microsoft Word and Excel. This is because these programs use a Visual Basic module for running their macros.When the virus attacks the Word or Excel document, it sits in the document and waits until you open the document with Word or Excel. Once you open the document, the macro runs, and the virus is now loaded into the computer's memory and can begin doing it's work.

Macro viruses,
such as the Word Macro Virus, often infect more than the document. Word has a set of templates, (.dot files), that it uses. The most common file is normal.dot. A Word Macro Virus will often not only infect the document you are working on, but will try to infect Word's Normal template as well. This insures two things:

Any document created within that template will be infected.Any infected documents that are opened on other (non-infected) computers will infect those computers as well.If your computer ever asks you to save change to the Normal.dot template say No and stop using that file!!!

No comments:

Post a Comment