106
2 Computer Viruses, Malicious Logic, and Spyware
code, which can perform any specific actions set by the creator. After performing
its actions, this virus delegates control to the original program, which is executed
further in a normal way. Obviously, if special software has not been installed on the
user’s computer, it may take a long time to get aware of the infection.
File viruses are among the most common types of computer viruses. Their characteristic feature is that they are initiated when an infected program is started. The
virus code is usually contained in the executable file of this program (a file with the
extension of.exe or .bat) or in the dynamic library (extensionˆ) used by the program.
At present, such viruses, as a rule, are scripts written using a scripting programming
language (e.g., JavaScript) and can be included in web pages. They are embedded
in executable files, create duplicate files, or use file system organization features to
perform unauthorized actions.
Consider now the operation scheme of a simple file virus.
Unlike boot viruses, which are almost always resident, file viruses are not necessarily resident. Let’s consider the operation scheme of a non-resident file virus.
Suppose we have an infected executable file. When you run such a file, the virus
gains control, performs some actions, and delegates control to the “host.”
What does the virus do? It is looking for a new target object—a file suitable by
the type that is not yet infected. By infecting a file, a virus is embedded in its code
in order to gain control when launching this file. In addition to its main function—
reproduction, the virus may well do something intricate (say, ask, play)—this already
depends on the imagination of the virus creator. If a file virus is resident, it will be
installed in memory and will be able to infect files and show other abilities not only
while the infected file is running. By infecting an executable file, the virus always
changes its code; therefore, infection of the executable file can always be detected.
But, changing the file code, the virus does not necessarily make other changes:
• It is not required to change the length of the file;
• It is not required to change unused sections of the code;
• It is not required to change the beginning of the file.
Thus, when launching any file, the virus takes control (the operating system starts
it itself), is resident installed in memory, and delegates control to the called file.
Boot viruses. These viruses specifically infect the boot sector of computer hard
drives.
The principle of their operation is as follows. The virus adds its code to one of the
special programs, which usually always start to run immediately after the computer
is turned on, even before the operating system is loaded. The task of this software
is basically just the “preparation” and the launch of the OS. Thus, the virus itself
gains control and can perform certain actions specified by the attacker, for example,
write itself into the RAM. And only after that the “normal” operating system will be
loaded. The only thing is that the virus will already be in memory and will be able
to control its operation at its creator’s convenience.
The main destructive effect is encryption of the hard drive sectors. Every time the
virus is started, it encrypts the next portion of sectors, and by encrypting half of the
hard disk, it happily reports this. The main problem in the treatment of this virus is
2 Computer Viruses, Malicious Logic, and Spyware
code, which can perform any specific actions set by the creator. After performing
its actions, this virus delegates control to the original program, which is executed
further in a normal way. Obviously, if special software has not been installed on the
user’s computer, it may take a long time to get aware of the infection.
File viruses are among the most common types of computer viruses. Their characteristic feature is that they are initiated when an infected program is started. The
virus code is usually contained in the executable file of this program (a file with the
extension of.exe or .bat) or in the dynamic library (extensionˆ) used by the program.
At present, such viruses, as a rule, are scripts written using a scripting programming
language (e.g., JavaScript) and can be included in web pages. They are embedded
in executable files, create duplicate files, or use file system organization features to
perform unauthorized actions.
Consider now the operation scheme of a simple file virus.
Unlike boot viruses, which are almost always resident, file viruses are not necessarily resident. Let’s consider the operation scheme of a non-resident file virus.
Suppose we have an infected executable file. When you run such a file, the virus
gains control, performs some actions, and delegates control to the “host.”
What does the virus do? It is looking for a new target object—a file suitable by
the type that is not yet infected. By infecting a file, a virus is embedded in its code
in order to gain control when launching this file. In addition to its main function—
reproduction, the virus may well do something intricate (say, ask, play)—this already
depends on the imagination of the virus creator. If a file virus is resident, it will be
installed in memory and will be able to infect files and show other abilities not only
while the infected file is running. By infecting an executable file, the virus always
changes its code; therefore, infection of the executable file can always be detected.
But, changing the file code, the virus does not necessarily make other changes:
• It is not required to change the length of the file;
• It is not required to change unused sections of the code;
• It is not required to change the beginning of the file.
Thus, when launching any file, the virus takes control (the operating system starts
it itself), is resident installed in memory, and delegates control to the called file.
Boot viruses. These viruses specifically infect the boot sector of computer hard
drives.
The principle of their operation is as follows. The virus adds its code to one of the
special programs, which usually always start to run immediately after the computer
is turned on, even before the operating system is loaded. The task of this software
is basically just the “preparation” and the launch of the OS. Thus, the virus itself
gains control and can perform certain actions specified by the attacker, for example,
write itself into the RAM. And only after that the “normal” operating system will be
loaded. The only thing is that the virus will already be in memory and will be able
to control its operation at its creator’s convenience.
The main destructive effect is encryption of the hard drive sectors. Every time the
virus is started, it encrypts the next portion of sectors, and by encrypting half of the
hard disk, it happily reports this. The main problem in the treatment of this virus is
