← Back to list

Malware Part Two: What is a Computer Virus?

A computer virus is a form of malicious software (malware) that spreads between computers, causing data corruption, software damage, and…

Trinesh Rai · 2025-02-15 08:31 · 6 claps · 7.8 min read paywalled
#virus #computer-virus #cyber-threats-2025 #ai-for-cybersecurity #ai-and-cyber-threats
Open on Medium ↗
Wiki topics: MIC · Microbiology & Immunology 🔒 · Cybersecurity

Malware Part Two: What is a Computer Virus?

A computer virus is a form of malicious software (malware) that spreads between computers, causing data corruption, software damage, and system disruptions.

Viruses are designed to:

  • Attach themselves to executable files or programs.
  • Activate when the infected file is opened or executed.
  • Spread through networks, external drives, file-sharing platforms, and email attachments.

Once inside a system, viruses replicate and embed themselves in multiple files, often going undetected until they cause significant damage, such as slowing down systems, deleting files, or leaking sensitive data.

Mechanisms of Infection

Once inside a system, viruses use various techniques to infect and spread. These mechanisms allow them to evade detection, replicate, and execute malicious actions.

1. Code Injection

  • The virus embeds itself into legitimate executable files or system processes.
  • When the user runs the infected program, the virus executes alongside it, injecting malicious code into the system’s memory.
  • Some viruses hook into system APIs (Application Programming Interfaces), allowing them to manipulate files, steal information, or interfere with normal processes.

2. Boot Sector Infection

  • Certain viruses target the boot sector of storage devices (hard drives, USBs).
  • When a computer starts, it loads data from the boot sector first. If this sector is infected, the virus gains control before the operating system starts.

These viruses persist across reboots and often require specialized boot-level antivirus tools for removal.

3. Polymorphic and Metamorphic Techniques

  • Polymorphic viruses modify their code slightly each time they replicate, changing their signature to avoid detection by traditional antivirus programs.
  • Metamorphic viruses rewrite their entire codebase while maintaining the same functionality, making detection even more difficult.

These techniques allow the virus to spread undetected for long periods while continuously evolving.

4. Macro-Based Infection (Document Viruses)

  • These viruses exploit macro-enabled documents such as Microsoft Word, Excel, or PowerPoint files.
  • When a user opens an infected document, the virus executes malicious macros (automated commands).
  • Some macro viruses spread by sending infected documents via email or cloud storage, targeting unsuspecting users.

5. Network Propagation (Worm-Like Behavior)

  • Some viruses use network vulnerabilities to spread without user interaction.
  • They scan for open network ports, unpatched systems, or weak security configurations to infiltrate multiple computers.
  • Examples include worm-like viruses, which spread across LANs (Local Area Networks) or the internet, infecting new devices automatically.

6. File Infector Viruses

  • These viruses attach themselves to executable files (e.g., .exe, .dll, .sys) and activate when the user opens the infected program.
  • When executed, the virus may copy itself into other files, system directories, or even attach itself to new software installations.
  • Some file-infecting viruses modify system files so they can reinfect the machine even after removal attempts.

7. Social Engineering (User Trickery)

  • Many viruses disguise themselves as legitimate files, software, or updates to trick users into executing them.
  • Common techniques include:
  • Phishing Emails: Viruses embedded in email attachments (e.g., fake invoices, resumes, or security alerts).
  • Fake Software Updates: Pop-ups claiming the user needs a software update that installs malware instead.
  • Trojan Viruses: Malware disguised as a useful tool but secretly carrying a virus payload.

8. Remote Execution & Drive-By Downloads

  • Some viruses exploit browser vulnerabilities to install themselves automatically when a user visits a malicious website.
  • This method, called a drive-by download, doesn’t require the user to click or approve anything — simply loading the webpage is enough to trigger the infection.
  • Remote execution techniques allow attackers to inject malicious code into a website, ad network, or software repository, leading to widespread infections.

How Viruses Maintain Persistence

Once inside a system, viruses often use techniques to remain active and hard to remove, such as:

  • Rootkits: Modify system-level files and hide from antivirus scans.
  • Registry Modification: Edit Windows Registry keys to launch automatically at startup.
  • Process Injection: Embed into legitimate processes like explorer.exe or svchost.exe to blend in.
  • Self-Replication: Copy themselves to multiple locations, including external drives, cloud storage, and email attachments.

Viruses can remain undetected for extended periods, often causing damage like slowing down systems, deleting files, stealing credentials, or leaking sensitive data.

Signs of a Virus Infection

A virus can significantly impact your device, often showing clear signs of infection. Recognizing these early symptoms can help prevent further damage and protect your data.

1. Sluggish System Performance

If your computer suddenly becomes slow or unresponsive, a virus could be consuming system resources. Performance drops may affect:

  • Overall system speed.
  • Application responsiveness.
  • Internet browsing experience.

If you haven’t installed any heavy software but notice a slowdown, malware could be running in the background.

2. Unwanted Pop-up Windows

Frequent pop-up ads on your desktop or browser are classic indicators of malware. These pop-ups can:

  • Contain fake warnings prompting you to download more malicious software.
  • Redirect you to suspicious websites.
  • Install spyware or adware without your consent.

3. Self-Executing Programs

If programs close unexpectedly or fail to open, they may be infected. A virus can:

  • Corrupt software files, preventing them from launching.
  • Automatically terminate applications, disrupting your workflow.

If this happens, running an immediate virus scan is recommended.

4. Unexpected Account Logouts

Some viruses target specific applications, causing frequent crashes or logouts. If you’re being logged out of:

  • Email accounts
  • Social media platforms
  • Online banking services

…it could indicate unauthorized access or a virus trying to steal your credentials.

5. Frequent System Crashes

Infected computers often experience:

  • Sudden crashes or reboots.
  • Unusual error messages.
  • Files opening or closing on their own.

Some viruses even simulate random keystrokes, making it seem like your computer is typing by itself.

6. Mass Emails Sent from Your Account

Viruses often spread through email phishing campaigns. If you notice:

  • Emails sent from your account that you didn’t write.
  • Complaints from contacts receiving strange messages from you.

…it’s a sign that malware is using your device to spread further.

7. Unauthorized Browser Changes

A virus can alter your homepage or browser settings without permission. If you suddenly see:

  • A new default search engine or homepage.
  • Unwanted toolbars or extensions installed.

It likely means a virus or adware has hijacked your browser.

Common types of computer viruses

Resident Virus

Resident viruses spread by infecting applications on a host computer. They become active when applications are opened by the user. In contrast, non-resident viruses can infect executable files even when programs are not running.

Multipartite Virus

Multipartite viruses use multiple methods to infect and spread. They typically stay in the computer’s memory to infect the hard disk and other drives, altering application content. This causes performance issues and low memory. Avoiding these viruses involves not opening un-trusted attachments, using reliable antivirus software, and cleaning the boot sector and the entire disk.

Direct Action

Direct action viruses infect all programs, files, and folders in the autoexec.bat path by accessing the computer’s main memory, and then they delete themselves. These viruses affect system performance and can destroy data on the hard disk and USB devices. They can be prevented with antivirus scanners and are relatively easy to detect and remove.

Browser Hijacker

Browser hijackers manually change web browser settings like the homepage, new tab page, and default search engine. While not technically viruses, they can be very damaging and difficult to restore. They often come with free software or malicious applications from unverified sources, so it’s important to use trusted software and antivirus solutions.

Overwrite Virus

Overwrite viruses delete data and replace it with their own content or code. Infected files cannot be recovered, and the virus can affect Windows, DOS, Linux, and Apple systems. Removing this virus requires deleting all infected files, which can be devastating. Using a trusted and updated antivirus solution is the best protection.

Web Scripting Virus

Web scripting viruses compromise web browser security, allowing hackers to inject web pages with malicious code. This enables cybercriminals to attack major websites and use the virus to send spam, commit fraud, and damage server files. Protecting against these viruses involves using real-time web browser protection, securing cookies, disabling scripts, and using malware removal tools.

File Infector

File infectors are common and overwrite files when opened, quickly spreading across systems and networks. They mostly affect files with .exe or .com extensions. Avoiding file infectors requires downloading official software and deploying antivirus solutions

Network Virus

Network viruses can cripple entire networks and are hard to detect, as they can hide within any computer on the network. They replicate and spread easily via the internet to connected devices. Robust antivirus solutions and advanced firewalls are essential for protection.

Boot Sector Virus

Boot sector viruses target a computer’s master boot record (MBR), injecting code into the partition table and moving into main memory upon restart. Symptoms include boot-up problems, poor performance, and an unlocatable hard disk. Modern computers usually have boot sector safeguards to limit these viruses’ effects.

In today’s digital age, protecting your computer from viruses is more crucial than ever. With the increasing prevalence of malware and cyber threats, it’s essential to adopt effective strategies to safeguard your system. This document outlines several key methods to help you maintain a secure computing environment and minimize the risk of virus infections.

Prime Examples of Computer Viruses

Throughout computing history, several viruses have had a major impact, shaping cybersecurity responses and antivirus development.

1. Creeper (1970s) — The First Computer Virus

The Creeper virus, created in the early 1970s, is considered the first computer virus. It spread across ARPANET (a predecessor to the Internet) and displayed the message:

“I’M THE CREEPER: CATCH ME IF YOU CAN.”

To combat it, programmers developed Reaper, one of the first antivirus programs, specifically designed to remove Creeper.

2. Elk Cloner (1982) — First Virus to Spread in the Wild

Created by high school student Rich Skrenta, Elk Cloner was the first virus to spread outside a controlled environment. It infected Apple II computers via floppy disks and displayed a poem on the screen.

3. Brain (1986) — First IBM PC Virus

The Brain virus, created by two Pakistani brothers, was the first known PC virus. It targeted floppy disk boot sectors, marking a new era of personal computer threats.

4. Melissa (1999) — Email-Based Virus

The Melissa virus spread through infected Word documents sent via email attachments. When opened, it:

  • Sent itself to the top 50 contacts in the user’s Outlook address book.
  • Caused email servers to crash, leading to widespread disruption.

5. I LOVE YOU (2000) — $10 Billion in Damages

One of the most destructive viruses ever, I LOVE YOU spread through email as a fake love letter attachment. When opened, it:

  • Overwrote files, rendering them useless.
  • Spread to millions of computers worldwide.
  • Caused an estimated $10 billion in damages.

Understanding how viruses infect systems is crucial for anyone studying cybersecurity. Attackers constantly evolve their techniques, and security professionals must stay ahead. Mastering virus behaviour helps in detection, mitigation, and proactive defence. Whether you’re aiming to be a malware analyst or security engineer, hands-on practice with real threats is essential.

Cybersecurity isn’t just about defense — it’s about thinking like an attacker to anticipate and counter threats. Keep learning, experimenting, and staying ahead.If you’re a professional looking to upgrade your skills in the field of cybersecurity or a student eager to build a thriving career in cybersecurity, we invite you to explore our **AI for Cybersecurity program. Taught by the world’s leading academics and industry professionals, this cutting-edge program offers unparalleled insights into the role of AI in cybersecurity. Plus, it’s run partially within the metaverse**, providing a truly immersive and innovative learning experience.


메타데이터
post_id
905cbfa76a5e
slug
malware-part-two-what-is-a-computer-virus-905cbfa76a5e
url
https://medium.com/@trinesh.rai/malware-part-two-what-is-a-computer-virus-905cbfa76a5e
canonical_url
https://medium.com/@trinesh.rai/malware-part-two-what-is-a-computer-virus-905cbfa76a5e
author_url
https://medium.com/@trinesh.rai
status
ok
fetched_at
2026-08-15 23:23:07