108
2 Computer Viruses, Malicious Logic, and Spyware
their main variety—replicator viruses—called worms, which instantly spread across
computer networks at the command of an attacker, accurately calculate the addresses
of network computers, and write their copies to these addresses.
Stealth viruses. These are viruses that can very well hide their presence in the
attacked system. It is very difficult to detect them, because stealth viruses use various
methods to ensure “invisibility.”
The most common variation is as follows: The attacking virus consists of two
parts. One of them is resident (permanent) and resides in the computer’s memory. In
this case, if the attacked operating system gains access to the infected file, then this
conditional “resident” intercepts a message and simply deletes the virus code from
the file. Thus, the application turns out “clean.” But after this particular application
completes its work, the “resident” again “infects” it.
The use of stealth algorithms is based on the interception of infected object read
or write requests from the OS. In this case, there is a temporary treatment of these
objects or their replacement with non-infected areas of information. This allows
viruses to hide themselves in a system.
Stealth viruses cheat antivirus programs and as a result go unnoticed. However,
there is an easy way to disable a stealth virus masking mechanism. It is enough to boot
a computer from an uninfected system floppy and immediately, without starting other
programs from the computer disk (which may also be infected), scan the computer
with an antivirus program.
Polymorphic viruses. A specific feature of these viruses is the ability to change
their own code. This is done in order to mislead well-known antivirus programs,
which often use so-called masks (excerpts from the main code typical of such viruses).
Polymorphic viruses are of two types. The first group simply encrypts their own
“body” with a non-permanent key and a random set of decoder commands. The
second group is more difficult, since the viruses belonging to it can “rewrite” their
code, i.e., in fact, they are programmers themselves.
It is very difficult to detect viruses based on the use of polymorphicity algorithms
in a system, since such viruses do not contain a single permanent code segment,
which is achieved by encrypting the virus code and modifying the decoder program.
As a rule, two samples of the same virus will not have a single match in the code.
This type of computer viruses seems to be the most dangerous today. Let’s explain
what it is.
Polymorphic viruses are viruses that modify their code in infected programs in
such a way that two instances of the same virus may not match in any of bits.
Such viruses not only encrypt their code using various encryption paths, but also
contain a code for generating an encryptor and a decryptor, which distinguishes them
from ordinary cryptographic viruses that can also encrypt sections of their code, but
they also have a permanent code of a cryptographer and a decryptor.
Polymorphic viruses are viruses with self-modifying decryptors. With this encryption, having infected and original files, you still cannot analyze its code using normal
disassembly. This code is encrypted and is a meaningless set of commands. Decryption is done by the virus itself directly during the execution. In this case, the following
2 Computer Viruses, Malicious Logic, and Spyware
their main variety—replicator viruses—called worms, which instantly spread across
computer networks at the command of an attacker, accurately calculate the addresses
of network computers, and write their copies to these addresses.
Stealth viruses. These are viruses that can very well hide their presence in the
attacked system. It is very difficult to detect them, because stealth viruses use various
methods to ensure “invisibility.”
The most common variation is as follows: The attacking virus consists of two
parts. One of them is resident (permanent) and resides in the computer’s memory. In
this case, if the attacked operating system gains access to the infected file, then this
conditional “resident” intercepts a message and simply deletes the virus code from
the file. Thus, the application turns out “clean.” But after this particular application
completes its work, the “resident” again “infects” it.
The use of stealth algorithms is based on the interception of infected object read
or write requests from the OS. In this case, there is a temporary treatment of these
objects or their replacement with non-infected areas of information. This allows
viruses to hide themselves in a system.
Stealth viruses cheat antivirus programs and as a result go unnoticed. However,
there is an easy way to disable a stealth virus masking mechanism. It is enough to boot
a computer from an uninfected system floppy and immediately, without starting other
programs from the computer disk (which may also be infected), scan the computer
with an antivirus program.
Polymorphic viruses. A specific feature of these viruses is the ability to change
their own code. This is done in order to mislead well-known antivirus programs,
which often use so-called masks (excerpts from the main code typical of such viruses).
Polymorphic viruses are of two types. The first group simply encrypts their own
“body” with a non-permanent key and a random set of decoder commands. The
second group is more difficult, since the viruses belonging to it can “rewrite” their
code, i.e., in fact, they are programmers themselves.
It is very difficult to detect viruses based on the use of polymorphicity algorithms
in a system, since such viruses do not contain a single permanent code segment,
which is achieved by encrypting the virus code and modifying the decoder program.
As a rule, two samples of the same virus will not have a single match in the code.
This type of computer viruses seems to be the most dangerous today. Let’s explain
what it is.
Polymorphic viruses are viruses that modify their code in infected programs in
such a way that two instances of the same virus may not match in any of bits.
Such viruses not only encrypt their code using various encryption paths, but also
contain a code for generating an encryptor and a decryptor, which distinguishes them
from ordinary cryptographic viruses that can also encrypt sections of their code, but
they also have a permanent code of a cryptographer and a decryptor.
Polymorphic viruses are viruses with self-modifying decryptors. With this encryption, having infected and original files, you still cannot analyze its code using normal
disassembly. This code is encrypted and is a meaningless set of commands. Decryption is done by the virus itself directly during the execution. In this case, the following
