Computer Forensics 2 CGS 5132 Dr. S. Lang: April 23, 2002
Computer Forensics 2 CGS 5132 Dr. S. Lang: April 23, 2002
Computer Forensics 2 CGS 5132 Dr. S. Lang: April 23, 2002
CGS 5132
Dr. S. Lang
Floppy disks
These factors set the stage for a technological
petri dish for computer viruses to flourish
Initialization
When first turned on, a computer loads an
operating system or DOS into main memory
from a disk
When an infected file is run, that file is loaded
into main memory also
Once the file begins to execute, the virus
becomes “active”
Reproduction
Typically, its first objective is to replicate (or
reproduce)
“Virus programs, typically written in machine
code, usually employ DOS commands to
commandeer system resources that the virus
must use.”
Reproduction
This := findfile findfile – uses DOS to open the
LOAD (this) directory of executable files on
disk, picks a random file name,
loc := search and assigns it to this
(this)
LOAD – A DOS command that
insert (loc)
brings the selected file into
STORE (this) main memory
****** search – a subroutine that scans
findfile the file to find a suitable
insertion site for the virus and
assigns its physical memory to
search loc
insert – the virus appends itself at
the end of the file and reroutes
insert the progression of the file to the
virus and back
loc Reproduction
Unaffected program
memory
Virus
Infected program
Trigger & Bomb
day/date := check
(clock)
if day = 5 and date = 13
then bomb
check
bomb
check – uses DOS commands to read the system clock and
assigns the appropriate values to day and date
bomb – this is the heart of the virus, what does all the
damage
Evolution
Headlines it caused:
http://news.com.com/2009-1001-270945.html?l
cnet
Other Famous Viruses
Lorena Bobbit Virus – turns your hard disk into a 3.5
inch floppy
Woody Allen Virus – bypasses the motherboard and
turns on a daughter card
Tonya Harding Virus – turns your .BAT files into lethal
weapons
Paul Revere Virus – warns of impending virus infection:
1 if by LAN, 2 if by C:\
Adam and Eve Virus – Takes a couple bytes out of your
Apple computer
Freudian Virus – your computer becomes obsessed with
its own motherboard, or becomes very jealous of the
size of your friend’s hard drive
No Laughing Matter
U.S. Businesses lost $5 billion to $6 billion due to
computer viruses
Viruses have penetrated the computers of: