Virus knowledge: Understanding the four major families of malicious viruses"

Source: Internet
Author: User

Since the birth of the virus in, the number of viruses has increased dramatically. Currently, there are about to kinds of viruses. It is almost impossible to analyze these viruses one by one. We classify these viruses into four categories by popularity and prevalence. Readers can mainly prevent these four types of viruses.

I. macro virus

Microsoft's Office software and Windows systems account for the vast majority of the PC software market, and Windows and Office provide the necessary libraries for macro virus compilation and operation (mainly based on the VB library) therefore, macro virus is one of the most easily compiled and spread viruses.

Macro virus attack mode: When a Word opens a virus document, the macro takes over the computer, then infect itself with other documents, or directly delete files. Word stores macros and other styles in templates. Therefore, viruses always convert documents into templates and store their macros. As a result, some Word versions force you to store infected documents in the template.

Determine whether the virus is infected: Generally, there is no special sign in the attack, and it is often disguised as another dialog box for you to confirm. On machines infected with the macro virus, files cannot be printed, Office documents cannot be saved, or saved as files.

Damage caused by macro virus: delete files on the hard disk, copy private files to public occasions, and send files from the hard disk to the specified email or FTP address.

Preventive Measure: It is recommended that you do not share an Office program with several people at ordinary times and load Real-Time virus protection functions. Virus variants can be included in the attachment of the email and executed when the user opens the email or previews the email. Pay attention to them. General antivirus software can clear macro viruses.

Ii. CIH Virus

CIH is one of the most famous and destructive viruses of this century. It is the first virus that can damage hardware.

Attack damage: the main cause is to tamper with the data in the BIOS of the motherboard, resulting in a black screen when the computer is started, so that users cannot perform any data rescue and anti-virus operations. CIH variants can be transmitted through bundling other programs or email attachments on the network, and files on the hard disk are often deleted and partition tables on the hard disk are damaged. Therefore, after CIH attack, even if the motherboard or other computer boot system is changed, if the partition table is not backed up correctly, there is little chance to recover the data on the infected hard disk, especially its C partition.

Preventive Measure: Many CIH immunization programs have been developed, including the immunization programs written by the virus maker himself. Generally, CIH is not afraid of running the immune program. If the virus has been poisoned but has not yet occurred, back up the Partition Table of the hard disk and the data in the boot area before scanning and killing the virus.

Iii. Worm

The worm virus is named after trying to replicate itself as much as possible (like a large number of worms). It is infected with computers and occupies system and network resources, causing heavy loads on PCs and servers and crashes, in addition, the main means of destruction is to confuse the data in the system. It may not immediately delete your data for discovery, such as the famous Worm Virus and Nimda virus.

Iv. Trojan

The trojan virus is named after the famous Trojan horse in the ancient Greek Trojan war. As its name implies, it is a kind of network virus that disguises the latent. When the time is ripe, it will cause harm.

Transmission Mode: it is sent by email attachments and bundled in other programs.

Virus features: it will modify the registry, resident memory, install Backdoor programs in the system, and load the accompanying trojan at startup.

The destruction of the Trojan virus: the attack of the Trojan virus needs to run the client program on the user's machine. Once the attack occurs, you can set a backdoor, periodically send the user's privacy to the address specified by the trojan program. Generally, the user's computer port can be entered and can be controlled at any time, illegal operations such as deleting, copying, and changing passwords.

Preventive measures: users are vigilant against downloading and running programs with unknown origins, and do not open emails or attachments with unknown origins.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.