|
MICROSOFT 'S FREE VIRUS PROTECTION PROGRAM OVERVIEW
In 2008, the newspaper said that in last year's news was out:
"The world's number one software company Microsoft, PC protection
from viruses in the 2009 program from the users will be free. Center in
the state of Washington in the city of Redmond that Microsoft,
code-named Morro from security software in 2009 from the second half of
users to download free permit. Morro named this security software,
Microsoft's sales in 2009 to June 30 of last will, that sold for $
49.95 Windows Live OneCare security software to replace. Microsoft's
offer of free security software, Symantec, McAfee virus program, such
as independent producers' market will cause distress to live seems to .
This software is a good web site that she was my
http://www.gokhanblog.com asked to address. According to the
information we get out of this software.
Microsoft Security Essentials program name.
Programming Microsoft regarding consumer safety, general manager
Amy Barzdukas "Consumers us with a real-time security protection
software told me that they want. However, this type of software can not
pay or do not want to pay as we know. Microsoft Security Essentials and
consumers to obtain and easy to use, the user does not divide the work,
very good quality can have a protection. " in the form of information
to the site gave www.chip.com tr.
Microsoft Security Essentials program between languages that are
supported by on October 22, 2009 that as of now does not Turkish.
Microsoft this security software that Microsoft Security
Essentials'ın (MSE) Facebook spread over a highly effective against
harmful software such as Koobface was stated.
Detailed information about this program
http://www.chip.com.tr/konu/microsoft-security-essentials-final-surum_15527.html
You can read from. (22 October 2009) This web site has been automatically translated. Please remember when you read this.
Computer virus
From Wikipedia, the free encyclopedia
Jump to: navigation, search
? For other uses of the head Virus (disambiguation), see.
Computer virus, or information within the user without the
permission of the computer that changes the way we work and trying to
hide himself in diğeramların files that are actually a type of program.
The term usually malicious software (malware) dedilen used to
express a wide area even though a real virus in the following two task
conditions.
* You must replicate all
* Run the self (should run)
Topics
[hide]
* 1 Comparison with biological viruses
* 2 Classification
o 2.1 File viruses
Boot sector viruses that 2.2
o 2.3 multi-part viruses
o 2.4 Macro viruses
o 2.5 Network viruses
o 2.6 Companion viruses
o 2.7 software bombs
Cross-site scripting viruses that 2.8
o 2.9 Sentinel
* 3 other malicious software
o 3.1 Trojan Horses
+ 3.1.1 Service attack prevention Trojans
+ 3.1.2 Proxy servers Trojans
+ 3.1.3 FTP Trojans
Blocked Users + 3.1.4 Software Fixes
o 3.2 Worms
o Spyware 3.3
* 4 The effects of computer viruses
* 5 The use of the term virus
* 6 History
* 7 Why are computer viruses?
* 8 Cogan strategies
viruses that do not have built-in 8.1
8.2 Resident viruses that
* 9 protection detection methods
o files and other unwanted Olta 9.1 host to avoid
o 9.2 Kaçaklık
o 9.3 Deformation
+ 9.3.1 Simple strain
+ 9.3.2 with variable key encryption
Multi-pattern Code + 9.3.3
Metamorphosis + 9.3.4 code
* 10 Open and Countermeasures
it vulnerable to virus attacks and 10.1 of the operating system
o 10.2 Software development role
Antivirus software and other preventive measures that 10.3
o 10.4 Toparlar methods
Virus cleaning + 10.4.1
Re-installation of the operating system + 10.4.2
* 11 See also
* 12 References
Comparison with biological viruses
How do viruses work? Computer viruses and biological viruses
spread from person to person from one computer to another, such as can
infect. For example, according to estimates of experts, called Mydoom
worm in a single day in June 2004 on a quarter-million computers were
infected. In other cases, in 2000 the ILOVEYOU virus, has created a
similar effect. As of today in the world of computing and tens of
thousands of viruses every day new ones are identified. Infection or
spread of the virus because of the diversity to be valid for all how
they work is difficult to summarize. However, usually used to indicate
the various virus types most beautiful examples of broad categories
bulunmaktadır.ayrıca is a spam virus.
For information on a floppy disk, the computer, just to copy
DNA with the request that the cell nucleus, such as buzzing, humming is
a paradise. Computers and floppy disks and tape drives that are
connected to them, high-end copying accuracy be created. As with DNA
molecules, magnetism bytes copied 'language can not'. Nevertheless,
steps to duplicate itself can write a computer program that can.
Replicate itself on a computer not only stay, will spread itself to
other computers in a way. Computers bytes copied and bytes within these
instructions blindly to obey are the better that makes itself two
sitting ducks for the programs are as easy prey: software interference
against the devastation of the gates until the end in a clear manner.
Selfish gene theory and familiar to me any suspicious modern computer
floppy disk and mail non-discrimination act will know the invitation to
trouble. The only surprising aspect of today's epidemic of computer
viruses, the emergence of the time taken is very sad. ...
DNA viruses and computer for the same reason sanane spread: to
do good in copying and copies will be spread around and will obey the
instructions of viruses containing an environment where machines can be
found. Relatively, respectively, these two environmental media and
cellular physiology of a wide collection of computers and data
processing machines provided by the environment. In other places, other
media, other humming paradise Is Replication?
Richard Dawkins, A Devil's Chaplain
Classification
Many types of viruses can be analyzed in sub-section. The main classification section are:
File viruses
File virus, parasites or viruses, also known as the executable and
the executable files themselves (driver or compressed files) and the
host program is run, effectively keeping the particles becomes code. Is
activated later, the virus can spread itself by other programs that
keep files and programs as provided to a malicious activities. Most of
the files for viruses themselves to the system memory to install and
can be spread on the drive to search for other programs. Found to
contain the virus and the code of the program the next time the program
tries to activate the virus also changes. Any system or program
infected with the virus that has spread to all areas of the public who
use the system again and again Until that do so. In addition to
spreading this virus becomes active immediately, or through a trigger
destructive component within a species are hosted on. Triggers a
specific date, the virus will reach a certain number of copies can be
anything or junk. Randex, Meve are a few examples can be given to
viruses and MrKlunky file. Boot sector viruses
To the hard disk boot sector and all information is stored through
a program that provides the operating system is the place to start.
Virus, each loaded into memory at startup in order to ensure puts the
boot sector code. This, perhaps, today has been caused reduced in
number. Programs on a computer with a floppy disk to another, moving
from the periods when a boot virus was spreading fast. However, the
CD-ROM With the start of the period, CD-ROM of information within and
code can not be added to değiştilemez because this type of virus
propagation stopped. Although the virus still exists in the boot of a
relatively new age of malicious software are very rare. Another common
reason is operating systems no longer protects the boot sector is
receiving. Examples of boot viruses are Polyboot.B and AntiEXE. Multi-part viruses
Boot sector viruses and file multi-part combination of virus.
These viruses CD / DVD or floppy disk media and infected with viruses
such as income and are placed in memory. Subsequently moved to the hard
disk boot sector are. From the executable files on the hard disk sector
(. Exe) infection and spread throughout the entire system. Nowadays
viruses çokparçalı do not have much, but in the golden age, different
transmission techniques combine to cause major problems capabilities
were provided. The most famous multi-part Ywinz'dir virus. Macro viruses
Macro viruses, macros, various programs or applications that
contain viruses files are created. Microsoft Office programs created by
the Word documents, Excel spreadsheets, PowerPoint presentations,
Access databases, Corel Draw, etc. AmiPro application files created.
among the affected file types. Macro viruses belonging to the
application of the operating system is not spelled in the language they
are independent and application platform that can run all operating
systems (Windows, Mac, etc..) Can be spread between. Increasing
capabilities of macro languages in applications and networks süreki
likely to spread over such a large threat from the virus makes. The
first macro virus written for Microsoft Word macro virus and found
thousands edilmişti.Bugun are determined in August 1995. Relax,
Melissa.A and macro viruses Bablas terms örnekleridir.Çoğalma worm
(worm) lara similar but they differ in terms of functions. how to make
friends who'll be happy solerse it done ... Network viruses
Network viruses, and even in the local network on the Internet
about the sweep is very versatile. In general, shared resources, shared
drives or folders are spread over. To a new system once infected, they
search for potential targets on the network as they work to identify
vulnerable systems. System, the system vulnerable to the virus when
they infect the network and try to spread the entire network in a
similar way. Nimda and was renowned network viruses are bad SQLSlammer.
metropolis Hacker (ayace) m.ayak
Companion viruses
Companion viruses [1], host files, but do not have MS-DOS on hold
can be abused. Is a companion virus. EXE (application) files that use
the name in general. COM rarely. Exd is creating new files with the
extension. If the user of a particular program to run the command
console, only the name of the program write. EXE extension, you forget
to write DOS, the name and extension with the same extension of the
files in the dictionary, which appears in front of the file to run the
virus has been assumed will play. For example, user files adı.COM
(virus file) and file adı.EXE (executive file) you have two files named
on the command line and get just the file name is typed. Were examined
as a result, the file extension virus file that will be carried out
adı.com. Perform other duties assigned to spread viruses and is the
same as my own after you have. Exe files will run. So that the user
probably will not have the virus ayırdına. Under Windows 95 with some
viruses and can run on Windows NT users are known in the DOS emulator.
The current system files with viruses associated with the path of the
same name creates files and directories within the path of the old with
the new changes the virus. These viruses do not use MS-DOS command
prompt to be available for use with Windows XP increasingly rare. Software bombs
Software bombs, creating the necessary conditions are taken until
the remaining code and special software are functioning. Maturing of
the Terms to show user messages or files to delete will trigger certain
functions, such as. Independent software programs in bomb shelters,
such as viruses or worms can also can be part of. Affect the host after
a certain number of bombs as an example can be given the software
becomes active. Time bomb, software bombs and their sub-clusters in
specific date or time have been programmed to be enabled. The famous
Friday the 13th time bomb virus are examples. Cross-site scripting viruses
A cross-site scripting virus (XSSV) cross-site scripting
vulnerabilities to replicate the virus that are used. A web
applications and web browsers XSSV who will spread the virus type is
simbiyoz is needed. Actually xss not a virus, the system is open.
Php-based sites with malicious code görülür.id = variable is used after
the open is called. If the site is open to road link with the cookies
can be played with open adminine. This is also so open hotmail mail
from any address in terms of security should not be opened Sentinel
Quite sophisticated and useful sentinel virus type infected
computer remotely gives authorization to use. Sentinel boats,
computers, called zombies or slaves created and block attacks such as
the Service to be used in a malicious purpose in creating large
networks are used.
Viruses, infect your machine or your machine is activated without
the many ways is hiding. However, get active or not is very dangerous
viruses and expeditious way to rein in the problem should be done. Other malicious software
In the past, a computer hard disk is a computer that can carry
harmful only method was to place. With the start of a new era of
technology, now almost every computer is connected to the rest of the
world. Therefore, locations and times of harmful contamination source
exactly difficult to detect passing day. These are not enough in the
age of computer, such as new types of malicious software are derived.
Nowadays, the term virus, a computer will be exposed to attacks by
malicious software, all the different methods used to specify a generic
term has become. Described outside of the virus type found problems we
face today are newish. Trojans
Trojan horses that appear attractive but deceptive in fact
malicious files. Existing files in the system, rather than add code to
download screensavers, emails photos to show the impression they are
dealing with a business such as wake. However, in the background, in
fact, harmful activities, such as access to the files to delete. Trojan
horses are computer hackers to access your personal and confidential
information, allowing your secret doors are also created.
Trojans are not viruses because in fact, contrary to assumption
fail to replicate themselves. The spread of a Trojan horse for the
opening of the reserve is located, or e-mail attachment contains a
Trojan horse of the file should be downloaded to a computer via the
Internet and must be carried out. Service attack blocking Trojans
Service blocking attacks (Denial of service attacks) is based on
the basic idea of the Trojan horse on the victim's computer or Internet
traffic to reach a web site to block file downloading to increase.
Services Block Trojan horses, attack another version of mail-bombs are
Trojan horses that the main objective as possible, to infect as many
machines and certain e-mail addresses simultaneously, without filter
münkün various objects and content is to attack with. Proxy Trojans
This kind of Trojan horse to the victim's computer to the proxy
server converts. This way, the victim computer at risk of internet
service to be used for anonymous access to the whole world is open
access. An attacker using the domain name registration for the victim
computer can do, adult content sites with stolen credit cards to access
and is illegal without a trace can take a lot of work. FTP Trojans
This type of Trojan horses Trojan horses are the most simple and
outdated. The only thing they do is used for FTP transfer 21 port to
open and everyone can connect your computer to recognize opportunities.
New versions of this type only allows the attacker to access your
password-protected systems are in the structure. In fact the virus to
become outdated Trojan'ın money you still use yaygındır.Bu such viruses
entering your system does not can steal the necessary information,
credit card numbers and can make a lot of things similar. Today's
technology has produced many programs will prevent this. Blocked Users Detection Software
This Trojan horses to protect your machine, the work of popular
antivirus and firewall software to block access to your system allows
the attacker. One of the above-mentioned types of Trojan horse that
will contain one or more structures may be in one. Worms
Computer worms growing, independent and network connections that
can work are programs that can move on. The main difference between
viruses and worms are the multiplication and dissemination methods. To
work with a virus to the host file or boot sector needs, while the
spread between machines for the gene carriers need files. However, you
can work independently on their own worms and network connections
without the need for a carrier file can be spread over. Security
threats caused by worms, a virüsünküne equals. Essential files on your
system to destroy the worms, greatly slow down your machine and cause
the collapse of some necessary programs such as the ability to create
damage are all possible. MS-Blaster and Sasser worms, most worms are
examples tanınış. Spyware
Spyware, ad-supported software, the other is a term used to
qualify. Producing a shared software authors, in a program also earn
money from selling advertising yayınlatarak product can kulanıcıya. On
the market, many large media companies to write their software, banner
ads and banner ads in their attempt to suggest a certain percentage for
each product sold through the commission promises to give. If the user
in the software, you find annoying banner ads and licensing fees paid
if the opportunity to get rid of tape accesses. This band produces
advertising companies, in addition to the continuous use of your
internet connection for your internet use statistical information to
advertisers without your knowledge within the sending of some
monitoring programs are installed on your system. Descriptive precision
and software in the privacy policy of the data is not collected from
your system and your identity will not be clear your personal computer,
although specified by working as a server for your use at your own
information and internet habits 3 is sent to the person or institution.
Spyware also slows down your computer, to use a portion of
processing power, inappropriate at times annoying pop-up windows to
bring up the Internet browser settings, such as change and anasayfanızı
celebrity are changing. In addition, this type of illegal software to
create a big security threat, and viruses from your system to be
cleaned up considerable power can be clearly shows the trouble. Effects of computer viruses
Some viruses cause damage to applications, files, delete and
re-format the hard disk in various ways, such as damage to computer
have been with the program. Some harm, rather than to replicate only
within the system and text, picture or video messages to be noticed by
showing prefer. It seems harmless virus that can cause problems for
Insert user. Occupied by the memory of the computer may slow down the
machine, the system may be hesitant to act or even to crash. In
addition, many viruses, the error (bug) is a source, and these errors
can cause system crashes and data loss. Use of the term virus
The term computer virus, is derived from the biological equivalent
of the same logic kulanılmaktadır him. Although not exactly the correct
term virus usually including Trojan horses and worms also expressed to
all kinds of pests are used. Today, most well-known anti-virus software
packages that can defend all kinds of attacks has a structure. Some
technology community in terms of viruses, with the intention to
underestimate the harmful to specify the printer is used.
Virus was first term in 1984, prepared by Fred Cohen Experiments
with Computer Viruses used in his thesis, and the term is derived with
Len Adleman indicated. But the 1972 David Gerrold'e When a
science-fiction novel called HARLIE Was One, biological viruses, such
as a computer program running VIRUS mentioned his dream. The term
computer virus gene, Chris, and in 1982 his Claremont'in Uncanny X-Men
graphic novel was published in the past. Therefore, Cohen's first time
as virus definitions even though the academic term had been derived
from very early on. Date
First, in 1948 by John Von Neumann self-replicating computer program may have raised the idea.
A program called Elk Cloner was manufactured outside the lab or
computer virus has been described as the first computer. In 1982,
written by Rich Skrenta virus spread to the Apple DOS 3.3 operating
system has been spread through floppy disks. This virus actually
prepared by a high school student was a joke and a kind of game files
were hidden inside. Game 50 viruses are released and subsequently a
blank screen work in a poem about the virus named Elk Cloner spread by
showing complete.
Computer Virus doctoral thesis in 1983 created the first theme.
The first PC (Personal Computer) virus (c) a boot sector virus
called Brain, respectively, and Pakistan's Lahore city in 1986, working
in the simple and was written by two brothers named Amjad Farooq Alvi.
Brothers virus, formally, write their software to prevent pirated
copies were prepared. But analysts Brain a kind of derivative (variant)
of the Ashar virus, codes were examined were in fact created Brain'den
claim ago.
Computer networks before becoming widespread, many virus removable
media, particularly floppy disks, spread through. In the early days of
the personal computer era many users with information or programs from
one computer to another disk were already carrying. Some of the
programs on this disk viruses spread by infected. Some of their
computer by installing the boot sector is executed not executed
intended to take were already enabled.
Traditional computer viruses in the 1980s as a result of the rapid
spread of personal computers and modems to computer-based information
systems as a result of the increase in the use of the software became
common share. Computerized information systems (BBS) allows sharing of
software, while contributing to the proliferation of Trojan horses,
viruses commonly used software specially written to influence began.
Gene shared software (Shareware) and illegal software on the BBS used
for propagation of viruses were common carriers. On the one hand
pirates, illegal copies of commercial software market, while the
business community also has become the target of viruses on the current
practices and games were already trying to secure.
The second half of the 1990s, macro viruses became common. Many of
these types of viruses, such as Word and Excel in a scripting language
that can affect many Microsoft programs get ready. Microsoft Office has
been created with this virus infects documents and spreadsheets were.
Word and Excel on Mac OS to run on Macintosh computers this virus
spread. Many of these types of virus-infected virus were not in the
ability to email. Viruses spread via e-mail showing the advantages of
Microsoft Outlook Com arayüzününün were already using.
Macro viruses can be problematic for programs identified features.
For example, some versions of Microsoft Word macros that were allowed
to increase with additional blank lines. Some macro viruses behave in
the same way normal macros Due to a new virus mistakenly identified as.
In another example of the two macro virus infects documents at the same
time, it is perceived as mated combination of the two, and probably a
new virus as separate from their parents were identified. [2] Preparing a computer virus can be sent via instant messaging. Infected
by using the machine have a link to a web address to all persons in the
list of people ready to send as a message. Person receiving the message
from friends (or any other reliable source) come to believe that clicks
the link, located on the site can be reached and the virus can be
transmitted to the computer by using the above mentioned methods can be
spread to other victims computer.
November 2001 using Outlook and Outlook Express security
vulnerability "Badtrans" worm, a virus infected e-mail attachments for
viruses must be opened with the thesis disproved.
New types of computer viruses are cross-site scripting virus.
Revealed as a result of virus research in 2005 was serving as academic.
Cross-site scripting vulnerability on the virus to spread to use. Since
2005 several cross-site scripting virus sample was observed. Among the
major sites affected are located Myspace and Yahoo. Why are computer viruses?
Unlike computer viruses on their own biological virus evolution.
Computer viruses, nor what may have spontaneously from errors in the
software (bug) may derived. Programmers or by people who use the
software to virus are produced. Computer viruses are programs, but is
able to perform activities.
Virus writers to produce and disseminate a harmful purpose can be
attributed to many different reasons. Viruses for research projects,
for a joke, to attack the products of certain companies for political
purposes or to spread messages of identity theft, spyware and viruses
hidden through methods such as racketeering and financial gain can be
written for. Some viruses as printers was made on works of art and
writing some kind of virus described as constructive hobby. In
addition, many virus writer, the destructive effects of viruses on the
system is not in favor of showing. Most printers, the operating system
they are attacking a mental exercise or a pending çözülenmeyi seen as a
logical question against the anti-virus software and played cat and
mouse chase them attract the said. Some viruses are considered as well
as viruses. Their programs in terms of security have to be developed
infection or other viruses, they delete. Such viruses are very rare,
and uses system resources, can damage infected systems, and sometimes
other malicious code from being accidentally infected with the virus
may become carriers.
Weak written form may become a good virus gene accidental damage.
For example, a virus could identify the wrong target file may
inadvertently delete a system file and innocent. In addition, normally
works without the computer user's permission. Self-replicating code
added continuously as they are acting in good faith to the problems
caused by a virus, that does not replicate itself and a valid program
that can handle the problem than the problem can be resolved to what
extent raises suspicion. Virus writers to explain briefly the general
realm of a qualified extraction is difficult. [3]
Many in the field of law to write any computer crime is considered as harmful.
Computer viruses, such as disks and data lines is not limited
to electronic media. Virus, the path to the other computer is a
computer printed ink, the light rays to the human eye, the optic nerve
and finger muscle contraction may continue. The codes of a virus
program by pressing a computer that is presented to the attention of
readers enthusiasts magazine was condemned by a large. In fact, any
type of virus program about 'How' information published and the
specific type of childish minds attention to the idea of viruses such
withdrawal, the right is seen as irresponsible act.
Richard Dawkins - A Devil's Chaplain
Multicast strategies
Of the virus to replicate itself by a virus able to be written to
the execution and memory must be allowed. Hence many of the executable
file virus program to keep their current. If a user program to start up
if infected, the virus code is executed first. Their behavior according
to the viruses out are classified into two types. Will hold
non-resident viruses immediately seek other hosts, these goals can be
transmitted to the control and eventually leave the program they
infected. Built viruses begins playing when they do host lookup.
Instead of execution with their loads into memory and control are left
to the host program. This virus remains active in the background, the
infected program file or the files of each program that accesses the
operating system itself to cause infections. Non-resident viruses
Non-resident viruses discovered consists of modules that can be
considered a replicator module. Modules to be used for discovering the
virus to infect new files is obliged to call. Explore the executable
file modules facing each infected through replicator module is invoked.
For simple viruses the replicator tasks are:
* 1 Open a new file
* 2 Check the file has not been previously infected with a virus (if the bulaştırlımış back to discover modules)
* 3 Virus code into the executable file is kept.
* 4 Save the starting point of the executable file.
* 5 New additions to the starting point of the executable file virus code redirect to the launch area.
* 6 Former starting field virus is executed the virus will spread to those areas will not be executed save.
* 7 Save changes to the executable file.
* 8 Save the file infected.
* 9 Coupler module can find the virus files bulaştıracaği back to discover modules.
Built viruses
Built-in non-resident viruses similar to the virus in the samples
contain a multiplexer module. However, the built-in virus discovery
modules that are called replicator module. Instead, the virus is loaded
into memory module is executed Coupler time operating system and thus a
task at a time while applying certain types of replicator modules are
provided in the execution. For example, the operating system at a time
when you play a file that can be called replicator module. In this case
the virus being carried out in all eligible programs can be
transmitted.
Built viruses, sometimes fast and slow-infectious sub-categories
to be infectious can leave. Are fast catching much work to be infected
file. For example, can be reached quickly infectious virus can infect
every potential host file. This situation creates a particular problem
for antivirus programs, because the virus scanner to scan the system in
system-wide access to all potential host file will. If the virus
scanner can not detect the existence of virus in the system memory, the
virus, the virus scanner to scan the rear accessed by following all the
files will be infected. Quick infectious, systems will rely on
high-speed expansion. Mind that this method of transmission of the
virus to other files, and in a sense, easier to identify himself.
Because viruses invade the system memory and slow down gradually to the
machine by performing suspicious actions by antiviruüs software
edileleceklerdir difference. Slow-infectious while the host file are
designed to be rarely infected. For example, certain slow-infectious
only when they copy their files they hold. By limiting their activities
being detected are slowly catching work to avoid. The computer can be
the difference is not likely to slow down and fixes detect suspicious
behavior to avoid triggering the anti-virus software will not put their
best ardlarına. Approach to the spread of infection and slow the entire
system allowing such viruses did not achieve their goals. Detection methods of protection
By users to be detected viruses on behalf complicate uses some
deception. Especially in MS-DOS platform, some of the older viruses,
infect a host file to change the content, despite the last modified
date to remain unchanged in particular provide.
However, this approach can not deceive anti-virus software.
Some viruses, they are accessible without changing the files and
file size without damaging the cause infections. This executable files
by overwriting the unused areas perform. Such viruses are called cavity
viruses. For example, a time of great devastation caused Chernobyl
virus because this type of portable executable files affects the files
are too many gaps. 1 KB in size, virus, infected files, the file size
will not change.
Some antivirus programs as viruses, some anti-virus program before
identified themselves as they try to avoid detection by the
termination.
Computers and operating systems, development and preservation
methods to update legacy karmaşıklaştıkca or need to be replaced with
new ones that are open. Fishing and other unwanted files from the host avoidance
Continue to spread a virus but a host must hold on to. In some
cases, the host program is not a good idea to mess with. For example,
some antivirus programs to control the integrity of their code are
examined. Therefore, these types of programs to keep the virus will
cause the disclosure. Hence, some viruses, some anti-virus programs
that are known parts of the program are designed not to hold on to.
Another is the fear of the virus host species fishing (bait) files.
Olta files, anti-virus or anti-virus programaları by experts specially
prepared for the virus to infect files. This is intended to detect the
virus files in all of them for various purposes which are produced;
* Antivirus experts to obtain virus samples bait files are
used. To keep the virus in a small fishing and reviewing files, system
files infected with the virus of major program review by experts is
more practical use bait files.
* Antivirus experts examine the behavior of the virus files
and fishing methods used to assess their possible detection. This
particular virus is very handy in situations where multiform. In this
case, the virus was prepared to file a large number of fishing is
intended to infect. All infected bait file, a virus scanner can not
detect all virus evaluation versions are available.
* Some anti-virus software is also regularly used files are
accessed fishing. This is adaptation to fly anti-virus software user,
the system could have warned the virus is active.
Olta files, viruses are detected or identified were first used
makes it easier, such a virus infected files can not self-benefit.
Virus, which contains commands that make sense, such as small program
files, by staying away from suspicious looking program performs.
Another way to avoid viruses without the fishing line is also
infected sparse. Brackets sometimes sparsely spread, in other
circumstances, a candidate may be eligible to hold the host file will
not hold. For example, a virus infected file on any host can decide not
to be a random way or the host files on certain days of the week may
prefer to spread. Kaçaklık
Some viruses, antivirus transferred to the operating system,
stopping some of the requests are trying to fool antivirus software. A
virus, anti-virus software to read the file is forwarded to the
operating system requests from reaching the correct target, and even
forward the request through its own antivirüsten can achieve hiding.
Virus, then a clean version of the same file clean of the file, such as
by offering anti-virus seemingly allows. Modern anti-virus software of
this type of virus works to counteract concealment techniques. The only
way to prevent system Kaçaklık known to be clean from an environment
önyüklemektir. Strain
Many anti-virus software, ordinary program to check the virus
signature files and scan for potential viruses are trying to find.
Signature of a virus or virus family, indicating the specific type of
virus is a special byte samples. If such a virus scanner examined the
files in the sample is compared with a user is informed about the
virus. In this case the user can delete the file or virus-free can.
Some viruses, virus signatures and detection will be difficult or
impossible to use techniques. These kinds of viruses during each dish a
different version of the virus codes değiştirmektedir.Dolayısıyla every
host has to keep in house. Simply change
In the past, viruses change themselves in ways simple. For
example, viruses, and tasks contained in the source code exchange units
were similar to subroutines. 2 +2 forum 1 +3 in the structure of a
virus at the end of clearing any change in function was not revolves.
Today, this situation does not create a problem for advanced virus
scanner. Encryption with variable key
More advanced method of the virus with a simple encryption method
was to hide. In this case the virus, with a small decoder module
consisted of a copy of the encrypted virus code. Each file is encrypted
with a key different viruses in infected even if only part of the virus
will always remain constant, the virus attached to the last part of the
module will be solvent. In this case the virus scanner detected the
virus using virus signatures will not be able, but hard to determine
which part of the solver to find the virus there is the possibility of
indirect ways.
In general, the application of the virus was simple techniques and
a large majority solvents main virus file that is stored in each byte
random key and has been making jewelry with Xor were obtained by merge.
Encryption and decryption have the same order because of additional
advantage to the virus were used uygulmalarının Xor. (a XOR b = c, c
XOR b = a.) Multi-pattern Code
Multi-pattern codes, the browser for the first technical was a
serious threat to supply. Encrypted viruses similarly encrypted files
in multi-pattern viruses are transmitted with copies, respectively.
However, the decoder module in each file ranged infected. Therefore, a
well-written multi-pattern viruses in each infected did not have no
item will remain constant and that the virus using signatures to detect
viruses was impossible. Antivirus software virus, emulator (emulator)
via an encrypted virus body, or by solving the statistical model could
be found by doing analysis. To have multi-pattern code, viruses,
encrypted within the body of multi-pattern engine (replacement engines
or engine changes) should have.
Some viruses that increases the pace of change of the virus
multi-pattern codes are using. For example, a virus in time can be
programmed to show a slow change in shape or any other virus infected
files hold copies may retain to himself. This kind of slow viruses
multi-pattern rule, such viruses belonging to antivirus experts
representing numulerini difficult to obtain. Because only a certain
time in the process of similar or same type of bait file version of the
virus will infect. This situation clearly demonstrates that the
detection of such viruses in the virus scanners are not reliable and as
a result of some samples of the virus is clearly able to escape being
detected. Metamorphosis code
Emulator Users (emulator) to avoid being detected by means of each
new executable file is infected with the virus before their completely
rewrites. They can spend a metamorphosis of this virus engines are
required to metamorphosis. Engine is usually too large a metamorphosis
and complex. For example, assembly language contains W32/Simile 14000th
line and 90% belong to the meta-engine. Open and Countermeasures
Of the operating system vulnerable to virus attacks
Computer viruses and biological viruses are known in many respects
they are similar. The more genetic diversity within a community, the
vibrant community of any disease that destroys the virus that are
becoming extremely difficult. Likewise, the diversity of software
systems over a network, viruses are destroyed limit.
Microsoft's desktop operating systems and office software packages
provide advantages in the market has created a special interest in this
case the 1990s. Users of Microsoft software (especially networking
software such as Microsoft Outlook and Internet Explorer users) are
defenseless against the propagation of viruses. Microsoft software, the
company's desktop operating systems because of their superiority as the
quantity is the target of many viruses and virus printers printer abuse
by the many errors (bug) and they often keep their deficits within the
review are received. Embedded (integrated) software that allows access
to the file system includes a scripting language applications (eg
VBScript and networking applications) is also vulnerable to attack.
Although the most popular operating system for Windows viruses
printers although some viruses has been observed on other platforms.
Third-party software runs on any operating system can theoretically run
viruses. Some operating systems, others are relatively less safe.
Unix-based operating systems (Windows NT-based platforms and downloads)
by users of their own executable applications only allow to run in a
restricted area.
As of 2006, one of the Unix-based operating system, Mac OS X to
open the target areas of abuse (exploit) [4] is very low. Known
security vulnerabilities of the worms and trojans to abuse the open
categories included in the. Apple Mac OS Classic for older operating
systems known as the number of viruses, according to sources of
information to supply to changes. Apple only 4, while 63 independent
sources to the operating system so the virus can infect is specified.
Can be said for certain is that the Unix-based Mac Os operating system
because of their vulnerability to abuse other operating system be
relatively more difficult. Macintosh computers are few, because only
part of Mac viruses, computer viruses can affect the printers that this
situation is not very appealing. Viruses affected properties, often the
basis of comparisons between Apple and Microsoft oluşturmaktdır.
Windows and Unix have similar scripting abilities, but normal
users are Unix operating system environment by preventing access to the
passes in front of possible substitutions, Windows does that. In 1997,
Bliss is known as Linux has emerged for the virus, antivirus companies,
the leading Unix-like operating systems (Linux or Unix based) on
Windows, such as viruses can come under bondage in predictions found.
[5] Bliss, a typical Unix system for virustür. Bliss, activated by the
user to run their own income and only the areas of user access rights
(or programs) is infected. Unlike Windows users, most Unix user to
install programs and software to make settings with the exception of
such cases with the administrator account does not sign, so the user
running the virus even if the operating system the virus can not infect
files can not harm the system. Bliss virus never very common and more
did this research as a means of curiosity remained. The source code,
the creator of how it works by researchers were able to mail on behalf
Usenet. [6] Software development role
Software to prevent unauthorized use of system resources with
security features designed, many virus systems or applications software
errors (bug) the spread of abuse. Too many errors in the software (bug)
created to stand in the software development strategy, but also the
main source of many potential abuse will be.
Microsoft and proprietary software company of choice for producing
closed-source software development process that by many is seen as the
main source of security vulnerability. Open source software (GNU
Association Software vb.) Allows users to examine the application code
and to solve security problems, only one institution must be adhered to
eliminate.
On the other hand, some open-source software development, virus
writers can use reveals potential security problems, and therefore
would increase the incidence of abuse is alleged. These people also
very much like Microsoft's popular closed source software and software
that are being abused because of a much wider area of influence due to
the spread of abuse must be claimed against the natural.
A sample of the virus code (virus, certain death): del C: /
WINDOWS / system / MOUSE.DRV del C: / WINDOWS / system / KEYBOARD.DRV
del c: \ WINDOWS \ system32 \ drivers \ cdrom shutdown-s Antivirus software and other preventive measures
Used to detect viruses that antivirus software has two methods.
The first is to navigate and the most common, is to use virus signature
definitions. Objection to this method, the user's list of virus
signatures have been detected only viruses containing the signatures
derived From the new threats due is to remain vulnerable. The second
method by focusing on the general behavior of the virus detection is
performed using the heuristic algorithm. Thanks to this method of
anti-virus companies have already determined that they could not find
viruses on your system.
Viruses belonging to many users downloading executable files to
the computer to perform in case detection and antivirus programs that
can clean the files from the system uses. Anti-virus software, computer
memory (RAM and boot sectors), fixed or removable drives (hard disks
and floppy disks) by reviewing files and virus signature database by
comparing it with work. Some anti-virus software with the same
procedure when opening files or even send and receive email while
browsing can be done. This practice is called on access scanning.
Anti-virus software, a host program to spread the virus zaafiyetlerini
(open to) do not correct. I was taken a few steps to perform but to
adopt this kind of anti-virus solutions can override the host software
warranty. Therefore, users often belong to update the software
vulnerabilities should be patched.
Person, in addition to important data and even the operating
system will cause the virus by taking regular backups and can prevent
possible damage. Backup hard not connected to the system, read-only
access or disabilities (formatted with different file systems) is
stored in environments that are very important. With this path, because
if the virus data loss if compensatory damages using the latest backup
is taken. Likewise, an employee disk (livecd) operating system, the
actual operating system become unavailable to open the computer can be
used. Another method belonging to the different operating systems to
store backups on different file systems. A virus is unlikely to affect
all file systems. Therefore, the data in the file system backup to
different types of transfer is appropriate. For example, Linux can
write to NTFS partitions using special software has to, Therefore this
type of person does not install the software and backup of the NTFS
partition will be transferred in order to create the MS Windows
installation performs the backup of Linux viruses will be preserved.
Similarly, MS Windows file system Ext3 can not read and therefore to be
obtained by installing Linux Ext3 section away from the threat of
replacement will make a backup of the transfer. Methods roundup
A computer virus is below the harmful effects, re-install the
operating system from continuing to use the computer will not be safe.
However, a computer virus can be caught when the preferred option has
many rally. Appropriate application, depending on the seriousness of
the virus type is selected. Virus cleaning
1. method: Windows Xp on a probability, important records and
system files have been pre-recorded back to a checkpoint system restore
will kulanmaktır tool.
2. methods: AntiVirus and AntiSpyware with Antivirus
silmektir.Bedava as Avast, Free Avg AntiSpyware Download Download
AntiSpyware AntiSpyware'dirAvast Avg Incentives Re-installation of the operating system
Serious cases of extreme operating system may be necessary to
reinstall. To do this, delete all the disk and virus infection did not
need to perform a clean environment through the installation.
GNU Free Documentation License This text and the license has
been (an official Turkish translation of this license real-mecuttur).
"Computer Virus" is quoted from his Wikipedia article.
Computer viruses themselves to legitimate programs and patches
that are pieces of program code that disrupts their normal functioning.
In exchange the disk, internet, local networks can move. Themselves
with a program, usually through networks and 'worms' called programs
are technically different. A different kind, 'Trojan horses', is the
third member of the destructive program. But the people themselves do
not copy them because of pornographic or otherwise appealing content
are based on the principle of copy. Virus and worm programs in computer
language, both in fact 'Two Enable me at are programs. Both types of
assets make you feel insignificant and perhaps the author will satisfy
their sense of self-conceit can do other things. Side effects
'ridiculous' may (Macintosh computer speakers, even the 'do not panic
Do' testimony can call and predictably the opposite effect, such as
viruses); may be malicious (will take place shortly after the disaster
snicker a laugh with the display after notice of the hard disk, the
viruses have etc.), may be political (Spanish Telecom and Beijing
viruses, respectively, and the phone charges from being massacred
protesting students shall only); may be clumsy or simply (effective
programmers write a virus or worm, the low-level systems required to
handle calls about is incompetent). November 2, 1988 the United States
the vast majority of computing power stroke, the most famous Internet
Worm (very) bad faith was not written but are out of control and within
24 hours, approximately 6000 computer memory occupied by growing at a
pace began to copy itself.
|