Showing posts with label Antivirus Utilities. Show all posts
Showing posts with label Antivirus Utilities. Show all posts

Sunday, December 28, 2014

Why people create computer viruses?


Unlike biological viruses, computer viruses do not simply evolve by themselves computer viruses do not come into existence spontaneously, nor are they likely to be created by bugs in regular programs. They are deliberately created by programmers, or by people who use virus creation software. Computer viruses can only do what the programmers have programmed them to do.


Virus writers can have various reasons for creating and spreading malware. Viruses have been written as research projects, pranks, vandalism, to attack the products of specific companies, to distribute political messages, and financial gain from identify theft, spyware, and cryptoviral extortion. Some virus writers consider their creations to be works of art, and see virus writing as a creative hobby. Additionally, many virus writers oppose deliberately destructive payload routines. Some viruses were intended as “good viruses”. They spread improvements to the programs they infect, or delete other viruses. These viruses are, however, quite rare, still consume system resources, may accidentally damage systems they infect, and, on occasion, have become infected and acted as vectors for malicious viruses. A poorly written “good virus” can also inadvertently become a virus in and of itself (for example, such a ‘good virus’ may misidentify its target file and delete an innocent system file computer owner. Since self-replicating code causes many complications, it is questionable if a well-intentioned virus can ever solve a problem in a way that is superior to a regular program that does not replicate itself.
Releasing computer viruses (as well as worms) is a crime in most jurisdictions.

Effects of computers viruses
Some viruses are programmed to damage the computer by damaging programs, deleting files, or reformatting the hard disk. Others are not designed to do any damage, but simply replicate themselves and make their presence known by presenting text, video, or audio messages. Even these benign viruses can create problems for the computer user. They typically take up computer memory used by legitimate programs. As a result, they often cause erratic behavior and can result in system crashes. In addition, many viruses are bug-ridden, and these bugs may lead to system crashes and data loss.
+

What kind of files can spread viruses?



Viruses have the potential to infect any type of executable code, not just the files that are commonly called ‘program files’. For example, some viruses infect executable code in the boot sector of floppy disks or in system areas of hard drives. Another type of virus, known as a ‘macro’ virus, can infect word processing and spreadsheet documents that use macros. And it’s possible for HTML documents containing JavaScript or other types of executable code to spread viruses or other malicious code.

Since virus code must be executed to have any effect, files that the computer treats as pure data are safe. This includes graphics and sound files such as .gif, .jpg, .mp3, .wav, etc, as well as plain text in .txt files. For example, just viewing picture files won’t infect your computer with a virus. The virus code has to be in a form, such as an .exe program file or a Word .doc file that the computer will actually try to execute.

Virus Behavior:
Viruses come in a great many different forms, but they all potentially have two phases to their execution, the infection phase and the attack phase:

Infection Phase:
Virus writers have to balance how and when their viruses infect against the possibility of being detected. Therefore, the spread of an infection may not be immediate.

Attack Phase:
Viruses need time to infect. Not all viruses attack, but all use system resources and often have bugs.
+

What is Trojan horse program?



A type of program that is often confused with viruses is a ‘Trojan horse’ program. This is not a virus, but simply a program (often harmful) that pretends to be something else.

For example, you might download what you think is a new game; but when you run it, it deletes files on your hard drive. Or the third time you start the game, the program E-mails your saved passwords to another person.

Note: Simply downloading a file to your computer won’t activate a virus or Trojan horse; you have to execute the code in the file to trigger it. This could mean running a program file, or opening a Word/Excel document in a program (such as Word or Excel) that can execute any macros in the document.

List of some computer worms

Badtrans   Bagle      Blaster             Brontok
Code Red           Code Red II       Dabber      Doomjuice
Hybris            Hydra      ILOVEYOU      Klez
Mabutu            Melissa      Morris      Mydoom
Netsky   Nimda      Sadmind             Sasser
Sircam   Sober      Sobig              SQL slammer
Swen            Upering       W32/Bolgimo.worm      Welchia
Witty                   Zotob

+

What can I do to reduce the chance of getting viruses from E-mail?

Treat any file attachments that might contain executable code as carefully as you would any other new files: save the attachment to disk and then check it with an up-to-date virus scanner before opening the file.
If you E-mail or news software has the ability to automatically execute JaveScript, Word macros, or other executable code contained in or attached to a message, I strongly recommend that you  disable this feature.
My personal feeling is that if an executable file shows up unexpectedly attached to an  E-mail, you should delete it unless you can positively verify what it is, who it came from, and why it was sent to you.
The recent outbreak of the Melissa virus was a vivid demonstration of the need to be extremely carefully when you receive E-mail with attached files or documents. Just because and E-mail appears to come from someone you trust, this does NOT mean the file is safe or that the supposed sender had anything to do with it.
+

Some general tips on avoiding virus infections.

Some general tips on avoiding virus infections:
1.     Install anti-virus software from a well-known, reputable company, UPDATE it   regularly and USE it regularly.

2.     New viruses come out every single day; an antivirus program that hasn’t been updated for several months will not provide much protection against current viruses.

3.     In addition to scanning for viruses on a regular basis, install an ‘on access’ scanner (included in most good antivirus software packages) and configure it to start automatically each time you boot your system. This will protect your system by checking for viruses each time your computer accesses an executable file.

4.     Virus scans any new programs or other files that may contain executable code before you run or open them, no matter where they come from. There have been cases of commercially distributed floppy disks and CD-ROMs spreading virus infections.

5.     Anti-virus programs aren’t very good at detecting Trojan horse programs, so be extremely careful about opening binary files and Word/Excel documents from unknown or ‘dubious’ sources. This includes posts in binary newsgroups, downloads from we/ftp sites that aren’t well-known or don’t have a good reputation, and executable files unexpectedly received as attachments to E-mail or during an on-line chat session.

6.     If your e-mail or news software has the ability to automatically execute JavaScript, Word macros, or other executable code contained in or attached to a message, I strongly recommend that you disable this feature.

7.     Be extremely careful about accepting programs or other files during on-line chat sessions: this seems to be one of the more common means that people wind up with virus or Trojan horse problems. And if any other family members (especially younger ones) use the computer, make sure they know not accept any files while using chat.

8.     Do regular backups. Some viruses and Trojan horse programs will erase or corrupt files on your hard drive and a recent backup may be the only way to recover your data.
Ideally, you should back up your entire system on a regular basis. If this isn’t practical, at least backup files that you can’t afford to lose or that would be difficult to replace: documents, bookmark files, address books, important E-mail, etc.

Precaution:
1.     Before using the floppy disk of others, check the disk whether it is virus free or not.
2.     Do not use the computer unless the viruses are totally removed from the infected computer.
3.     Do not use pirated software.
4.     Do not let anyone to use your computer.
5.     Lock the computer when not in use.
6.     Lock you computer system with psssword.
7.     Never run you anti-virus software, while the memory is infected by the virus, because the virus active in memory transfer that virus into your anti-virus software and your program may not able to work.
8.     Don’t be confirm that all the anti-virus sotware can remove viruses, it depends up on the infected fileor boot sector virus(es), which may be active for long time. If the virus is active and you have been using it for long time then there is less possibility of removing the virus.
9.    Always boot from write protected bootable diskette so that the bootable diskette itself doesn’t catch virus.
10.    Never allow floppy disc brought from outside to be used directly on PC without checking tha floppy for virus presence.
11.    Be careful while checking mail having attached documents.
12.    Keep all original EXE and COM  files in a write-protected floppy.
13.    If COM and EXE files are required to be copied anywhere, copy only from written-protected original floppy.
14.    In case the system is ‘hanging’ (or floating), the reason could be Virus. Check for virus.
15.    Avoid playing computer games on a computer where important data is stored as it is generally noticed that the virus spreads faster through game floppies.
16.    Install any one anti-virus program i.e. NAV, McAfee etc. and update it regularly.

+

Classification of computer Virus.

 Classification of Virus

1.     Boot sector viruses
2.     Companion viruses
3.     Email viruses
4.     Logic bombs and time bombs
5.     Macro viruses
6.     Cross-site scripting virus
7.     File virus
Two other types of malware are often classified as viruses, but are actually forms of distributing malware:
8.     Trojan horses
9.     Worms.

Boot sector viruses
A book sector viruses alters or hides in the boot sector, usually the 1st sector, of a bootable disk or hard drive. Boot sector viruses were prevalent in the 1980s.

Boot sector Infectors: Also sometimes called boot record infectors, system viruses, or boot viruses, these programs attack the vulnerable boot program that is stored on every bootable floppy disk or hard disk. This code id executed by the system when the PC is started up, making it a juicy target for virus writers: by installing themselves here thy guarantee that their code will be executed whenever the system is started up, giving them full control over the system to do what they wish. They are spread most commonly through infected bootable floppy disks.

Companion viruses
A companion viruses doe not have host files per se, but exploits MS-DOS. A companion virus creates new files (typically.COM but can also use other extensions such as “.EXD”) that have the same file names as legitimate .EXE files. When a user types in the name of a desired program, if a user does not type in “.EXE” but instead does not specify a file extension, DOS will assume he meant the file with the extension that comes first in alphabetical order and run the virus. For instance, if a user had “(filename).COM” (the virus) and “(filename).EXE” and the user typed “filename”, he will run “(filename).COM” and run the virus. The virus will spread and do other tasks before redirecting to the legitimate file, which operates normally. Some companion viruses are known to run under Windows 95 and on DOS emulators on Windows NT systems. Path companion viruses create files that have the same name as the legitimate file and place new virus copies earlier in the directory paths. These viruses have become increasingly rare with the introduction of Windows XP, which does not use the MS-DOS command prompt.

Email viruses
An E-mail virus is a virus which uses e-mail messages as a mode of transport. These viruses often copy themselves by automatically mailing copies to hundreds of people in the victim’s address book.

Logic bombs and time bombs
A logic bomb employs  code that lies inert until specific conditions are met. The resolution of the conditions will trigger a certain function (such as printing a message to the user under/or deleting files). An example of a logic bomb would be a virus that waits to execute until it has infected a certain number of hosts. A time bomb is a subset of logic bomb, which is set to trigger on a particular date and/or time.

Macro viruses
The newest types of virus, these clever programs make use of the built-in programming languages in popular programs such as Microsoft Word and Microsoft excel. These programs allow users to create programs that automate tasks, called macros. As the macros languages have become more powerful, virus writers have created malevolent macros that, when opened unwittingly, duplicate themselves into other documents and spread just like a conventional virus would. These programs can cause just as much damage as regular viruses, despite the fact that they are very different: regular viruses are low-level machine language programs, while macro viruses are actually high-level interpreted BASIC programs.

A macro virus, often written in the scripting languages for Microsoft programs such as Word and Excel, is spread in Microsoft Office by infecting documents and spreadsheets.

Cross-site scripting virus
A cross-site scripting virus (XSSV) is a type of virus that utilizes cross-site scripting vulnerabilities to replicate.  A XSSV is spread between vulnerable web applications and web browser creating a symbiotic relationship.

File virus
These viruses directly attack and modify program files, which are usually .EXE or .COM files. When the program is run, the virus executes and does whatever it wants to do. Usually it loads itself into memory and waits for a trigger  to find and infect other programs files. These viruses are commonly spread through infected floppy disks, over networks, and over the internet.

Trojan horses
Trojan Horses are imposter files that claim to be something desirable but, in fact, are malicious. Rather insert code into existing files, a Trojan horse appears to do one thing (install a screen saver, or show a picture inside an e-mail for example) when in fact it does something entirely different, and potentially malicious, such as erase files. Trojans can also open back doors so that computer hackers can gain access to passwords, and other personal information stored on a computer.
Although often referred to as such, Trojan horses are not viruses in the strict sense because they cannot replicate automatically. For a Trojan horse to spread, it must be invited onto a computer by the user opening an email attachment or downloading and running a file from the Internet, for example.
A Trojan horse is any program that, once run, does something that the user doesn’t want or request. The program doesn’t necessarily infect other files or spread to other something other than what it is supposed to. Some people think of viruses as a special form of Trojan horse: one that can infect other files 9thus turning them into Trojan horses) and duplicate itself. Trojan horses are sometimes just called “Trojans” for short.

Worms
A worm is a piece of software that uses compute networks and security flaws to create copies of itself. A copy of the worm will scan the network for any other machine that has a specific security flaw. It replicates itself to the new machine using the security flaw, and then begins scanning and replicating anew.
Worms are programs that replicate themselves from system to system without the use of a host file. This is in contrast to viruses, which requires the spreading of an infected host file . although worms generally exist inside of other files, often word or excel documents, there is a difference between how worms and viruses use the host file. Usually the worm will release a document that already has the “worm” macro inside the document. The entire document will travel from computer to computer, so the entire document should be considered the worm. Mydoom is an example of a worm.
A worm is a program that is self-contained and when run, has the ability to spread itself to other systems. In essence, a worm is a virus that doesn’t infect other programs. Instead, it acts independently, seeking to spread to other computers connected to its current host. Since they do not infect programs or boot sectors, they are much less frequently encountered than viruses. They tend to spread over network connections. They can have other undesirable effects when run.
Note: The acronym “WORM” is also used as a short form for “write once, read many”, a storage technology that is used by devices such as CD-R drives. The concepts are totally unrelated.



+

A complete guide information about Norton Antivirus.

Norton Antivirus:


Norton Antivirus is the #1 anti-virus software in the world. Enjoy the security of automatic protection against viruses, malicious ActiveX controls and Java applets, and other dangerous code. Norton antivirus for Windows 95/98/Me/NT/2000 protects you while you’re surfing the Internet or getting information from floppy disks, CDs, or a network. it also automatically scans incoming attachments in the most popular email programs. And Norton Antivirus is extremely easy to keep updated, with automatic retrieval of new anti-virus definitions from Symantec as soon as they are available.


To install Norton Antivirus:

1. Turn on you computer and let Windows start normally.
Insert the installation CD in your CD-ROM drive. The installation procedure begins automatically. Follow the on-screen instructions.
Note: if the installation procedure does not begin automatically, click Start, choose settings, and then click Control Panel. Double-click the Add/Remove Programs icon. Click install and follow the on-screen instructions.


Checking system for viruses:

Click on Start button.
Choose Program.
Choose Norton Anti-Virus and again choose Norton Anti-Virus and click on it.
Choose the drive (A: or C:), which you want to scan (check).
Check on Scan Now button.
Then, the Scan dialog box reports on the progress of the scan i.e. it shows the affected virus name.


Removing viruses (cleaning)

If Norton Antivirus found any viruses on your system while scanning, it displays the message, and you should have to take decision either remove it or not.

Select eliminate types either Automatic or Manual. The easiest way to eliminate viruses is to let Norton Anti Virus does it automatically. You can , however, choose to do it manually, one infected item at a time.
Click on Next button.
Again, Click on Next button.
Then the Norton Antivirus Repair Wizard dialog box with “Congratulation! You have eliminated the viruses” message appears.
Click on Finish button.
Then, Scan Results dialog box appear.


        NAV Rescue Dist Set:

When you set up Norton Antivirus, you were advised to create a NAV Rescue Disk Set. If you did not do so then, you should create the disks now. If you did create the NAV Rescue Disk Set, be sure you have stored the disks in a safe place.
If a virus damages boot records (files containing information necessary to start up your computer), you will be prompted to reboot you computer with the disk you made, labeled Norton Antivirus Emergency Boot Disk. These disks contain a backup copy of all information necessary to restore you computer to an uninfected state. If you do not have NAVE Rescue Disk Set you may not be able to restart you computer without risk of spreading a serious virus infection and causing damage to other files on your disk.


To create a NAV Rescue Disk Set:

Click on Start button.
Choose program.
Choose Norton Antivirus.
Choose Rescue Disk and click on it.
Follow the instruction given by the computer.


To remove the memory virus using rescue disk:

Shut down your computer, once your computer is turned off, the virus is removed from memory and is no longer spreading.
Restart your computer by placing the disk, labeled Norton Antivirus Emergency Boot Disk in drive A:, turning on your computer.
Type- NAVBOOT or GO at DOS Prompt and press Enter key.
Select your hard drive (C:) for scan.
Select scan Now and press Enter key.
Follow up the other given instructions.
Note: Once all viruses have been eliminated, remove any floppy disks and reboot your computer by switching the power off and then on to return to windows.
+

comparision of computer virus with biological virus.

                      A computer virus behaves in a way similar to a biological virus, which spreads by inserting itself into living cells . Extending the analogy, the insertion of a virus into the program is termed as an "infection", and the infected file, or executable code that is not part of a file, is called a "host".

                 A computer virus will pass from one computer to another like a real life biological virus passes from person to person. For example , it is estimated by experts that the Mydoom worm infected a quarter-million computers in a single day in January 2004. In marsh 1999, the Melissa virus spread so rapidly that it forced Microsoft and a number of other very larger companies to completely turn off their e-mail systems untill the virus could be dealt with. Another examples is the ILOVEYOU virus, which occurred in 2000 and had a similar effect. It stole most of its operating style from Melissa.
+

Defination of computer viruses.

             
A dangerous computer program with the characteristic feature of being able to generate copies of itself, and thereby spreading. Additionally most computer viruses have a destructive payload that is activated under certain conditions.

                  A computer program with the ability to modify other programs usually to the determent of the computer system.

                 A computer virus is a self-replicating program contain code that explicitly copies itself and can "infect" other programs by modifying them or their environment such that a call to an infected program implies a call to a (possibly evolved) copy of the virus. More one viruses.

                Virus ia a software program capable of reproducing itself and usually capable of causing great harm to files or other programs on the same computer: "a true virus cannot spread to another computer without human assistance'.

                       In computer security technology, a virus is a self-replicating program that spreads by inserting copies of itself into other executable code or documents (for a complete definition: see below. Thus a computer virus behaves in a way similar to a biological virus, which spreads by inserting itself into living cells. Extending the analogy, the insertion of the virus into a program is termed infection, and the infected file (or executable code that is not part of a file) is called a host....

              A computer virus is a self-replicating computer program written to alter the way a computer operates, without the permission or knowledge of the user. Though the term is commonly used to refer to a range of malware, a true virus must replicate itself, and must execute itself. The latter criteria are often met by a virus which replaces existing executable files with virus-infected copy. While viruses can be intentionally destructive - destroying data, for example-some viruses are benign or merely annoying.

          A computer virus is a program or software with a set of coded instructions to carry out the desired disorder and destruction, as also to replicate it. Though non-living and artificially created, the computer virus has marked similarities with its biological counterpart, and hence the name. Both forms of viruses contain coded instructions to carry out a set of activities, when certain specified conditions are met. Each computer virus has it specific signature. Both of them invade and replicate only in a host. Both of the can be detected and "vaccines" can be prepared.
+

What is computer viruses?

       



    Keep in mind that not everything that goes wrong with a computer is caused by a computer virus or worm. Both hardware and software failure is still a leading cause of computer problems.

                A virus is a program that reproduces its own code by attaching itself to other executable flies in such a way that the virus code is executed when the infected executable file is executed.

                 You can't get a virus just by reading a plain-text E-mail message or Usenet post. What you have to watch out for are encoded messages containing embedded executable code (i.e., JavaScript in an HTML message ) or messages that include an executable file attachment (i.e., an encoded program file or a Word document containing macros).

               In order to activate a virus or Trojan horse program, your computer has to execute some type of code. This could be a program attached to an E-mail, a Word document you downloaded from the Internet, or something received on a floppy disk. There's no special hazard in files attached to Usenet posts or E-mail messages: they're no more dangerous than any other file.
+