Mastodon Mastodon Mastodon Mastodon

Virus

Updated: · CyberSecureFox Editorial Team

A computer virus is malware that copies itself by inserting its code into other files or boot sectors and runs when they are opened.

How a virus works

A virus needs a host: an executable file, a document with macros or the boot sector of a disk. When the infected host runs, the virus code runs too, infects further files and may execute its payload – deleting data, displaying messages or installing other malware. Main types:

  • file infectors that modify executables;
  • boot sector viruses, like Brain (1986), one of the first PC viruses;
  • macro viruses in Word and Excel documents, like Melissa (1999);
  • polymorphic viruses that change their code with every infection to evade detection.

Virus, worm, trojan – what is the difference?

In everyday language any malicious program is called a “virus”, but technically a virus is only one type of malware. A worm spreads by itself over networks without infecting files (for example WannaCry in 2017). A trojan does not replicate at all; it pretends to be useful software (see remote access trojan). Most of today’s threats – ransomware, infostealers, RATs – are trojans or worms rather than classic viruses.

Why viruses matter for security

Classic file infectors are rarer now, but they are still found in industrial and legacy environments, on USB drives and in pirated software, and they can damage many files at once. The name also lives on in “antivirus” products that protect against all kinds of malware.

How to protect yourself

  • Keep antivirus or EDR active and updated on all devices.
  • Install OS and software updates; block macros in documents from the internet.
  • Scan USB drives and avoid pirated software.
  • Keep offline backups so infected files can be restored.
Synonyms:
computer virus