Computer viruses are a problem that almost every computer user has experienced. However, even if you have had experience with computer viruses threatening your system in the past. But do you know what a computer virus actually is?
Computer viruses are a problem that almost every computer user has experienced. However, even if you have had experience with computer viruses threatening your system in the past. But do you know what a computer virus actually is?
Title: Interesting information for safety from computer viruses
Compiled by: Dr. Siwarak Siwamokatham
Source : ThaiCERT: Thai Computer Emergency Response Team, Computer Security Coordination Center, Thailand
Published on : 29 July 2004
Computer viruses are a problem that almost every computer user has experienced. However, even if you have had experience with computer viruses threatening your system in the past. But do you know what a computer virus actually is? How can computer viruses threaten your system? What is the solution to a compromised system? And the important thing is How to keep your system safe from computer viruses? As a Computer Security expert from the ThaiCERT agency (http://www.thaicert.nectec.or.th/) whose main mission is to disseminate knowledge and warn against computer viruses. The author would like to present a brief and basic understanding of computer viruses. So that you can effectively protect your system from being threatened by computer viruses.
What is a computer virus?
In the past, the word "computer virus" It is the definition of a program that creates problems and causes various damages. with computers and can spread itself from one file to another. Inside the computer But it cannot spread across computers on its own. The ability of computer viruses to spread across computers is caused by users using files that contain computer viruses on other computers, such as using diskettes or other storage media. that has files of computer viruses embedded in it to use etc.
However, over time, computer viruses have developed variations. Techniques for spreading, ability, and violence to cause damage to the system which is very different from before, so nowadays the word "Computer virus" Therefore, it has a broader meaning than before and a new term has been coined that "Malware (Malware: Malicious Software)" which means a set of computer instructions Any program or software that has been created with the intent to cause damage to computers or computer network systems and may have the ability to move from one computer to another or from one network to another on its own
That is, currently "computer viruses" is used in the meaning of "Malware" widely (This article is the same) which, in addition to referring to previous forms of computer viruses, also includes (or may be composed of the components mentioned below)
Note: When talking about hoax, I would like to present additional knowledge about the characteristics of another form of hoax that is not a computer virus. But it is a form of computer crime that is becoming more and more common nowadays, that is "Phishing" This is e-mail spoofing and creating a fake website with the same content as the real website and an address similar to the real website. To deceive victims or e-mail recipients into revealing financial or other personal information, such as credit card number information, username and password, national identification card number. or other personal information
How can computer viruses threaten the system?
Usually, computer viruses can threaten a system for three main reasons:
1) A file that has a computer virus embedded is being executed.
As for the cause of computer users executing files that are already embedded with computer viruses, causing the system to be threatened by computer viruses, this is a well-known cause. In addition to being embedded in users' files, which is a form of early computer viruses, modern computer viruses often use a psychological principle called social engineering to trick users into opening files that are. Viruses, for example, come in the form of greeting card programs or screen saver programs, or in files received from people known to the user. which the user may receive via e-mail disguised as being from someone the user knows Or viruses may be hidden in the form of links in e-mails or websites. that tricks users into clicking to run etc.
2) Systems that do not use an Anti-Virus program or that use an Anti-Virus program but do not update the virus database
For another main cause of the system being threatened by a computer virus is that the system does not use an Anti-Virus program or has used an Anti-Virus program but has not updated the virus database to be up to date. Most Anti-Virus software can protect against known computer virus threats that are stored in the Virus Definition Database. This database must be kept up to date. Always so that the program knows and can fight new computer viruses. Some of you may have wrong beliefs. That if Anti-virus software is installed on the system then computer viruses will not be able to threaten the system. In fact, even if the system has such software installed, But if the virus database is not updated regularly or Anti-virus software is not used to thoroughly check that the system is free of computer viruses on a regular basis, Computer viruses can also threaten the system. Moreover, even if the Anti-virus software is properly installed and used in all respects, But the system may still be at risk of being compromised if the system is vulnerable. (Vulnerbilities) which will be discussed in the next section
3) The operating system or software running on the system is vulnerable. (Vulnerbilities) and the system is connected to the network
As for the reasons for the system's vulnerabilities, it is still not fully understood and realized. In fact Operating systems and the software running on them often have vulnerabilities. Often new vulnerabilities are discovered. of the system continuously Continuously, vulnerabilities (vulnerbilities) have a meaning similar to bugs of the system. In general, vulnerabilities mean The system has channels for attackers to take over. control work Bring a computer virus to run or do something on the system. If you are using the Microsoft Windows operating system, you can check what vulnerabilities your system has by running Windows Update or browsing http://windowsupdate.microsoft.com/You may discover that your system has many serious vulnerabilities. These vulnerabilities are a way for computer viruses or malicious actors to enter your system through the network. The fact that the system has vulnerabilities is the cause of what can be called an incident. "Suddenly It's infected with a virus. In addition, using the operating system or software in certain ways can cause vulnerabilities, such as having programs automatically open and read e-mails and attached files. Allowing other people to install files on the system (Full-Right File Sharing), etc.
Fixing a system infected with a computer virus
Remediating a system that is compromised by a computer virus varies depending on the virus that is threatening the system. Therefore, first you must know what virus has entered your system. Most systems that are threatened by computer viruses are systems that do not use an Anti-virus program or that use an Anti-virus program but do not update the virus database. Therefore, to know what viruses are in the system You can choose to use the following methods
Some of you may wonder why you don't use the method of installing Anti-virus software and/or updating the virus database. and run the said program To check for viruses on your system The weak point of this method is when your system is threatened by a virus. Viruses may block or disrupt the system, making it impossible for you to install or run the software. Or it may cause the Anti-virus software to crash or become defective.
When you know what type of virus the system is infected with, Procure a program for eliminating computer viruses (Fix Tool) to use to eliminate viruses on your system. You can download these Fix Tool programs for free from various websites such as http://securityresponse .symantec.com/avcenter/tools.list.html or http://www.pandasoftware.com/download/utilities/ etc. You may need to run your operating system in Safe Mode (consult an expert) in order for these Fix Tool programs to work with maximum accuracy.
When all viruses on your system are eliminated. Check whether your operating system has any critical vulnerabilities or not. If so, fix them. which is checked and corrected You can usually do this by browsing to http://windowsupdate.microsoft.com/ When the operating system vulnerabilities are fixed, Please install an Anti-virus program and/or update the virus database to the most up-to-date date. and run the said program to check your system in detail once again to make sure it is free of computer viruses.
In summary Rough steps To fix a system infected with a computer virus is
Computer virus protection
You should follow the following recommendations to prevent your system from being attacked by computer viruses. (The first 2 things to do are the most necessary.)