computer viruses a guide to virus protection,detection, and removal for the average computer user
TRANSCRIPT
Computer VirusesComputer Viruses
A guide to virus protection,detection, and removal for the
average computer user
The Team:The Team:
Ross SmithComputer Engineering
Andrew Freed Computer Science
Emily BruckerComputer Engineering
Matt PeterComputer Science
Greg Williams
GoalsGoals
Background on virus definitions
Protecting your computer
Identifying computer viruses
Instruct on removal of viruses
What is a Computer Virus?What is a Computer Virus?
Logic BombTriggered by certain event/date
Trojan HorseBad software ‘masquerades’ as good software
WormTries to spread over networks by duplicating
VirusUses good software as a host
Virus AvoidanceVirus Avoidance
Monitor Electronic Mail
Check the Sender’s NameUnknown Sender
Check the Subject of the MailKeywords
Identifying Viruses Before They Strike
Identifying Viruses Before They Strike
1) Keep up with technology news for impending attacks
2) Visit Symantec’s virus calendar and encyclopedia to learn about lesser publicized threats
www.symantec.com
How to Detect an Infected Computer
How to Detect an Infected Computer
1. Abnormal Activity
2. Visual Signs
3. Decreased Bandwidth
Best Method of Virus Detection
Best Method of Virus Detection
… is definitely virus software.
Source : Download.com
Removing a Virus – Places to Check
Removing a Virus – Places to Check
WebsitesSymantec (Norton) – www.symantec.com/avcenterMcAfee (VirusShield) – www.mcafee.com
Windows ToolsSafe ModeSystem Configuration EditorSystem Configuration UtilityRegistry Editor
Removing a Virus – Safe Mode
Removing a Virus – Safe Mode
Safe Mode is a basic configuration of Windows – used primarily for debugging
Minimum number of items are loadedThis means no extra programs can start – AIM,
AOL, or viruses!If a virus doesn’t start up, you can find the file
and delete it
Removing a Virus – System Configuration
Editor
Removing a Virus – System Configuration
EditorA look at system
filesLook for ‘run=‘
and ‘load=‘ lines that might initialize a virus
Removing a Virus – System Configuration
Utility
Removing a Virus – System Configuration
UtilityA more intuitive look at
system startupInteresting tab is
‘Startup’Shows you programs
that load automatically – do any look out of place?
Removing a Virus – Registry Editor
Removing a Virus – Registry Editor
Difficult – not for the faint of heart!
Must be very careful in the Registry
Viruses often affect the same Registry locations <HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - Startup
<HKEY_CLASSES_ROOT\exefile\shell\open\command> - Executables