2 Malware Flashcards

1
Q

What is a boot sector virus

A

They are stored in the first sector of a hard drive and are loaded into memory upon boot up

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is a macro virus

A

They are embedded into a document and is executed when the document is opened by the user

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a program virus

A

They infect an executable or application

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a multipartite virus

A

A virus that combines boot and program viruses to first attach itself to the boot sector and system files before attacking other files on the computer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is an encrypted virus

A

A computer virus that encrypts its payload with the intention of making detecting the virus more difficult

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a polymorphic virus

A

advanced version of encrypted virus that changed itself every time it is executed by altering the decryption module to avoid detection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is a metamorphic virus

A

A virus that is able to rewrite itself entirely before it attempts to infect a file

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is an armored virus

A

A virus that has a layer of protection to confuse a program or person analyzing it

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a hoax virus

A

A virus that is a threat that seems real but does not exist

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the difference between a polymorphic virus and a metamorphic virus

A

a polymorphic virus changes itself very time it is executed and alters the decryption module. A metamorphic virus rewrites itself entirely before it attempts to infect a file

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a DLL injection

A

Malicious code is inserted into a running process on a Windows machine by taking advantage of Dynamic Link Libraries that are loaded at runtime

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is Driver Manipulation

A

An attack that relies on compromising the kernel-mode device drivers that operate at a privileged or system level

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is placed between two components to intercept called and redirect them

A

A shim

How well did you know this?
1
Not at all
2
3
4
5
Perfectly