Malicous Code Flashcards
In 2010 how many strains of Virus’s did Symantec claim to exist?
Over 286
What are the two primary functions of a virus?
Propagation and destruction
What does a MBR virus do?
Infects/ overwrites the master boot record of a disk/ media.
What is the difference between master boot record and master boot sector?
MBR - determines what media partition to boot from.
Master boot sector - sector of disk with boot data.
What is the sequence of execution extensions in a windows OS?
.com
.exe
.bat
What is a companion virus?
Virus that has an executable name one sequence of execution higher than intended program.
What is a service injection virus?
Virus that takes over a trusted OS service ie SVCHOST.exe
What are two forms of AV methodology?
- Signature based
2. Heuristic
What actions can a AV platform typically take against a virus?
- Eradicate and clean.
- Quarantine.
- Delete
What is a multipartite virus?
Virus that can infect in multiple methods.
What is a stealth virus?
Virus that will cover itself from inspection.
What is a polymorphic virus?
Virus that changes itself as it moves form system to system.
What is an encrypted virus?
Virus that will encrypt portions of its executable to hide.
What was the code red worm?
Launched in 2001. Did three things:
- Port scan to find IIS platforms and exploited weakness.
- Changed webpages with hack message
- Turned server into a bot that would attack WH.gov.
What is spyware?
Watches activities of users on system.