Computer Virus
Introduction
Section titled “Introduction”A computer virus is malware that attaches its own code to legitimate host files or programs. When the infected file executes, the virus code runs, potentially causing damage and replicating to other files. Like a biological virus, it cannot spread without a host.
History & Origin
Section titled “History & Origin”| Milestone | Year | Details |
|---|---|---|
| Self-replication theory | 1949 | John von Neumann’s “Theory of Self-Reproducing Automata” |
| Elk Cloner | 1982 | First wild virus (Apple II, floppy disk); Rich Skrenta, age 15 |
| Brain | 1986 | First MS-DOS boot sector virus; Pakistani brothers Basit & Amjad Farooq Alvi |
| Morris Worm | 1988 | First internet-scale worm; led to CERT/CC creation |
| Melissa | 1999 | Macro virus via Word docs; $80M+ damage |
| CIH / Chernobyl | 1998 | Overwrote BIOS chips; machines unbootable |
| ILOVEYOU | 2000 | VBScript hybrid; ~$10B global damage |
How It Works
Section titled “How It Works”1. INFECTION PHASE └─ Search target hosts (executables, macros, boot sectors) └─ Inject copy of own code into host
2. TRIGGER PHASE └─ Dormant until condition met (date, replication count, user action)
3. PAYLOAD PHASE └─ Execute malicious action (delete, corrupt, exfiltrate)
4. PROPAGATION └─ Replicate to other files/drives/network shares when host executes
5. POLYMORPHISM (advanced) └─ Mutate code on each replication to evade signaturesNotable Examples
Section titled “Notable Examples”| Virus | Year | Platform | Impact |
|---|---|---|---|
| Elk Cloner | 1982 | Apple II | First wild spread via floppy |
| Brain | 1986 | MS-DOS | First global PC virus |
| Melissa | 1999 | Word/Windows | $80M+ damage, mail server overload |
| CIH | 1998 | Windows 95/98 | BIOS overwrite, unbootable |
| ILOVEYOU | 2000 | Windows | $10B+ global, email propagation |
Prevention & Solutions
Section titled “Prevention & Solutions”- ✅ Keep OS and all software fully patched
- ✅ Reputable AV/anti-malware with real-time protection
- ✅ Never execute untrusted files or email attachments
- ✅ Disable auto-run for removable media (USB, DVD)
- ✅ Enable macro security — block macros from internet
- ✅ Regular, tested, offline backups (3-2-1 rule)
- ✅ Application whitelisting — block unauthorised executables
MITRE ATT&CK Mapping
Section titled “MITRE ATT&CK Mapping”| Technique | ID | Description |
|---|---|---|
| Malicious File | T1204.002 | User executes infected file |
| Modify System Image | T1601 | Boot sector infection |
| System Binary Proxy Execution | T1218 | Macro execution in Office |
Related Pages
Section titled “Related Pages”- Computer Worm — Standalone replication
- Trojan Horse — Disguised malware, no self-replication
- Polymorphic & Metamorphic — Signature evasion