Pages

Powered by Blogger.
 
Showing posts with label blackworm virus. Show all posts
Showing posts with label blackworm virus. Show all posts
Saturday, June 4, 2011

Some Computer Viruses In History

Computer viruses generally trick hosts or other types of computers into reproducing copies of the invading organism. They spread from computer to computer through electronic bulletin boards, telecommunication systems and shared floppy disks. Viruses are created by human programmers, for fun or malice, but once they begin to spread they take on a life of their own, creating disruption, dismay and paranoia in their wake.

If the virus is found in any of the PC's that PC shoul...


Computer viruses generally trick hosts or other types of computers into reproducing copies of the invading organism. They spread from computer to computer through electronic bulletin boards, telecommunication systems and shared floppy disks. Viruses are created by human programmers, for fun or malice, but once they begin to spread they take on a life of their own, creating disruption, dismay and paranoia in their wake.

If the virus is found in any of the PC's that PC should immediately be isolated. The virus can be removed by giving an antidote by studying the virus. The machine should be put into use only after the virus is eliminated.
Viruses and such

A Virus is defined as a program inserted into another program. It gets activated by its host program. It replicates itself and spreads to others through floppy transfer. A virus infects data or program every time the user runs the infected program and the virus takes advantages and replicates itself.

There are two types of computer viruses 'parasitic' and 'boot' virus.

A Parasitic virus attaches itself to other programs and is activated when the host program is executed. It tries to get attached to more programs so that chances of getting activated is more. It spreads to other computers when the affected programs are copied. 'Jerusalem' and 'Datacrime' are parasitic viruses.

A Boot virus is designed to enter the boot sector of a floppy disc. It works by replacing the first sector on the disc with part of itself. It hides the rest of itself elsewhere on the disc, with a copy of the first sector. The virus is loaded by the computers built-in start-up program when the machine is switched on. The virus loads, installs itself, hides the rest of itself and then loads the original program. On a hard disc, virus can occupy DOS boot sector or master boot sector.
Some Reported Viruses

C-Brain: Amjad and Basit, two pakistani brothers, developed this software in January 1986 to discourage people from buying illegal software at throwaway prices. This was the most famous virus ever found and has a record of damaging few millions of personal computers. This is designed to stay in the boot sector of the disc or near zero sector. The virus enters the machine memory once the PC is booted with the infected floppy.

Macmag: This virus attacked Apple Macintosh computers only. Not much damage is reported because of this virus. This was not noticed on any IBM compatible PCs. It displayed a message of peace on the monitor and killed itself.

Cascade: This virus attacked IBM PCs and compatibles. The letters on the screen could be seen dropping vertically down to the bottom of screen after the virus picked them off in alphabetical order. This is a sort of parasitic virus. It attaches itself to other programs and gets activated when the host program is executed. It gets copied to other PCs when the programs are copied.

Jerusalem: Found in 1987 at Hebrew University, Jerusalem, this virus was designed to activate only on Friday, January 13 and delete all the files executed on that day. This infects the COM and EXE files. This is similar to Cascade virus in that it is parasitic in nature. This virus attaches itself to COM and EXE files to damage the data.

Daracrime/Columbus or October the 13th virus: This virus is similar to Jerusalem and was programmed to attack on October 13, 1989. Track zero of computer hard disk is destroyed and the contents of discs are rendered unreadable. This virus enters COM and EXE files and damages the hard disk. An antidote called 'Vchecker' was developed by the American Computer Society. Fortunately the virus was located in March 1989 itself and the damage reported after October 13 was minimal.

Bomb: This is also know as 'Logic Bomb' and 'Time Bomb'. An event triggered routine in a program that causes a program to crash is defined as a 'bomb'. Generally, 'bomb' is a software inserted in a program by a person working in the company.
Saturday, May 21, 2011

Several Common Ways That Viruses Spread

In addition to the common methods of spreading through email attachments, boot infections and program infectors, there are other ways by which viruses spread to your computer. These include:

Infection by Disk(Floppy, Zip, CD's, Tapes, etc.)

Floppy disks, though not as commonly used as in the past, are still a very common way viruses being spread from machine to machine. Anyone with an infected machine, using a floppy disk to copy and save files, can also copy and transf...


In addition to the common methods of spreading through email attachments, boot infections and program infectors, there are other ways by which viruses spread to your computer. These include:

Infection by Disk(Floppy, Zip, CD's, Tapes, etc.)

Floppy disks, though not as commonly used as in the past, are still a very common way viruses being spread from machine to machine. Anyone with an infected machine, using a floppy disk to copy and save files, can also copy and transfer the virus. Any use of that same removable disk, by any user, at any time in the future, will most likely contaminate, or re-contaminate the any computer it is used with. The only way to properly clean an infected floppy disk is to perform a low-level format. The normal Windows(tm) "format disk" is often not enough.

With CD's, all the above holds true with the exception that an infected CD can never be cleaned. To get rid of an infected CD, you need to put it in the trash and never use it again.

Infection from Networks

Peer-to-Peer network, Local Area Networks (LAN), a Wide Area Network (WAN), Wireless Networks, and the Internet, are all computer networks. They all have the same basic purpose; to share software, and information resources between two or more computers. As with anything else that is shared between computers, networks let users share files, and wherever files are shared, viruses can be shared and spread.

Most network virus/worm/Trojan activity is like what we described earlier, although more and more examples of automatic mass mailing attacks, system resource attacks are being found.

Recently many attacks are designed to specifically target major corporate interests (Microsoft, eBay, Amazon, major Banks etc.) in an attempt to disrupt their online services. Very generally these are called DOS (denial of service) attacks. The way they most commonly work is by secretly infecting thousands of local user computers (like the one you are using right now), and then at a specific time, launching a combined attack from all the infected machines against the primary target.

As you can see, your computer can be hijacked without your knowledge and then used in a major attack against an unsuspecting company. However with up-to-date virus/firewall protection, your computer will be immune to such hijacking.

Other ways by which virus spreads

Other sources of viruses have been found to be the result of software downloads available over the Internet. Software patches, drivers, demonstration software, from reputable companies, generally carries little risk. However, the Internet is also filled with "unofficial" software, pirated programs, and low-budget software from questionable sources that may be intentionally or unintentionally infected with viruses. Files downloaded directly from the Internet (either through file-sharing programs or direct download from websites), are among the fastest growing sources of computer virus infections.

Email, with its nearly universal availability and ease of use; chat rooms and messenger systems, not only make communication simple and quick, also make the transmission and re-transmission of infection simple and alarmingly fast. Creators of newer viruses, and internet worms specifically target these systems because they are widely used, and are often built right into the operating system and used with default settings making them much easier to attack and exploit.

As a point of reference, Internet Explorer, and Outlook/Outlook express email clients are two of the applications most targeted by Internet viruses and worms. Why? Because they are installed on more computers around the world than any other software, and they are installed 99% of the time with default settings (which means virus programmers have an easy blueprint to follow).

If you use an email system or instant message system that is installed automatically with your computer's operating system you need to install and use current antivirus software. You also need to learn how to turn off certain default settings that can leave your system open to very easy attack.
Tuesday, February 1, 2011

Computer Virus And Internet Worms Explained

Is your computer sluggish? It won't open programs and you can't get into anything? Well, maybe you have a sick computer. Just as people get ill from viruses, so do computers. When this happens, you need to have a computer technician look at the computer to re-format and get rid of the virus. If you know something about computers, you might be able to do this yourself.

What is a Virus?

A virus is a parasitic program written to intentionally enter a computer without the u...

Is your computer sluggish? It won't open programs and you can't get into anything? Well, maybe you have a sick computer. Just as people get ill from viruses, so do computers. When this happens, you need to have a computer technician look at the computer to re-format and get rid of the virus. If you know something about computers, you might be able to do this yourself.

What is a Virus?

A virus is a parasitic program written to intentionally enter a computer without the user's  permission or knowledge. The word parasitic is used because a virus attaches to files or boot sectors and replicates itself, which allows it to spread. Though some viruses do little more than copy themselves, others can cause serious damage or affect program and system performance. A virus should never be assumed harmless or left on a system.

Types of viruses

Viruses are classified by the ways they infect computer systems:

1) Program: Executable program files such as those ending with the extensions .Com, .Exe, .Ovl, .Drv, .Sys, .Bin
2) Boot: Boot Record, Master Boot, FAT and Partition Table.
3) Multipartite: Both program and boot infector.

What is Trojan Horse?

Besides being a large wooden horse used in the Trojan war 2500 years ago (and more  recently by Brad Pitt), a Trojan Horse or Trojan is a computer program that seems innocuous or harmless, but conceals another more nasty function. Generally a Trojan is contained in a part of program brought into your computer from an outside source - (e.g. floppy disk, CD, internet download, infected email). Trojans can be dangerous sometimes. For example a program may appear to be a computer game demo, but while you enjoy the game, it may be happily formatting your hard disk or emailing porn sites to everyone in your email address book.

Trojans are also used as a 'back door' or 'trap door' to sneak into a computer's operating system's information. An example is a program that pretends to be the system log-in program (such as you find in Windows NT/XP or Linux). When an unsuspecting user tries to log-in, the Trojan program captures the user-name & password. Then it may indicate a failed log-in attempt and exit to the real log-in program. The user may successfully log into the system next time, but by that time Trojan has also got enough details to log into the system.

Example Trojans

Notroj. This Trojan horse pretends to be a program that guards against Trojans. It's actually a time bomb that wipes out the hard disk after it's more than 70 percent full.

PWSteal.Refest A Trojan Horse that installs itself as a BHO (Browser Helper Object) for  Internet Explorer and steals online banking information when it is submitted in web forms.

PWSteal.Likmet.A A Trojan horse that displays a fake MSN Messenger logon window and steals the password provided.

Run.me. This is a graphics program, which plays the Star Spangled Banner and displays the American Flag while it worms its way into the hard disk and erases the data on it.

What is Worm?

A Worm is a self-propagating program that works its way through a system or network (like the Internet), often causing damage. It does not require a host program to activate it. Someone has to insert a worm directly into network of interconnected computers where messages can be sent from one to another and data files and programs exchanged. An example is a local area network where each computer has its own files, programs operating systems and hard discs such as would be found in a university or corporate setting.

Example Worms

Alarm Clock Worm. A worm that reaches out through the network to an outgoing terminal (one equipped with a modem), and places wake-up calls to a list of users.

Worm Watcher. A special program which automatically takes steps to limit the size of a worm, or shut it down, it grows beyond a certain limit. The worm watcher also maintains a running log recording changes in the


Updates Via E-Mail

Labels