Monday, July 02, 2007

Virus Behavior

Viruses come in a great many different forms, but they all potentially have two phases to their execution, the infection phase and the attack phase:

Infection Phase

When the virus executes it has the potential to infect other programs. What's often not clearly understood is precisely when it will infect the other programs. Some viruses infect other programs each time they are executed; other viruses infect only upon a certain trigger. This trigger could be anything; a day or time, an external event on your PC, a counter within the virus, etc. Virus writers want their programs to spread as far as possible before anyone notices them.

It is a serious mistake to execute a program a few times - find nothing infected and presume there are no viruses in the program. You can never be sure the virus simply hasn't yet triggered its infection phase.

Many viruses go resident in the memory of your PC in the same or similar way as terminate and stay resident (TSR) programs. (For those not old enough to remember TSRs, they were programs that executed under DOS but stayed in memory instead of ending.) This means the virus can wait for some external event before it infects additional programs. The virus may silently lurk in memory waiting for you to access a diskette, copy a file, or execute a program, before it infects anything. This makes viruses more difficult to analyze since it's hard to guess what trigger condition they use for their infection.

On older systems, standard (640K) memory is not the only memory vulnerable to viruses. It is possible to construct a virus which will locate itself in upper memory (the space between 640K and 1M) or in the High Memory Area (the small space between 1024K and 1088K). And, under Windows, a virus can effectively reside in any part of memory.

Resident viruses frequently take over portions of the system software on the PC to hide their existence. This technique is called stealth. Polymorphic techniques also help viruses to infect yet avoid detection.

Note that worms often take the opposite approach and spread as fast as possible. While this makes their detection virtually certain, it also has the effect of bringing down networks and denying access; one of the goals of many worms.

Attack Phase

Many viruses do unpleasant things such as deleting files or changing random data on your disk, simulating typos or merely slowing your PC down; some viruses do less harmful things such as playing music or creating messages or animation on your screen. Just as the infection phase can be triggered by some event, the attack phase also has its own trigger.

Does this mean a virus without an attack phase is benign? No. Most viruses have bugs in them and these bugs often cause unintended negative side effects. In addition, even if the virus is perfect, it still steals system resources. (Also, see the"good" virus discussion.)

Viruses often delay revealing their presence by launching their attack only after they have had ample opportunity to spread. This means the attack could be delayed for days, weeks, months, or even years after the initial infection.

The attack phase is optional, many viruses simply reproduce and have no trigger for an attack phase. Does this mean that these are "good" viruses? No! Anything that writes itself to your disk without your permission is stealing storage and CPU cycles. (Also see the "good" virus discussion.) This is made worse since viruses that "just infect," with no attack phase, often damage the programs or disks they infect. This is not an intentional act of the virus, but simply a result of the fact that many viruses contain extremely poor quality code.

An an example, one of the most common past viruses, Stoned, is not intentionally harmful. Unfortunately, the author did not anticipate the use of anything other than 360K floppy disks. The original virus tried to hide its own code in an area of 1.2MB diskettes that resulted in corruption of the entire diskette (this bug was fixed in later versions of the virus).

Sunday, July 01, 2007

Computer Help

How Do I Find Autostarting Applications?

Frequently when Windows starts a number of other programs start with it. Some of these you will see as small icons in the System Notification Area at the bottom right of your screen by the clock; for example...

System Notice Area

Others may not leave an icon but run in the background anyhow. Using one of a number of utilities (or just pressing the CTL-ALT-DEL keys together once only) usually displays their names. Often these are programs you want running in the background. Sometimes, however, a program that doesn't have to autostart will impolitely install itself as autostarting without giving you the option. When this happens, how do you stop it from running every time you start Windows?

First, be certain you know the name of the program you are trying to stop from autostarting. If you just let the mouse cursor rest over an icon the name of the controlling program will usually pop up after a short period. If it doesn't try right-clicking on the icon to see what menu pops up and work from there. Autostarting programs also usually have a counterpart in the Start|Programs menu; you can look for matching icons. Or in the Windows Task Manager (the windows that pops up when you press the CTL-ALT-DEL keys together once only) you can find the names of running programs.

Once you have the program name there are several places to look for the command that starts it when Windows starts. Try them in order as some are more commonly used than others (and easier to work with):

[Icon] Startup Folder

Polite programs will install autostart shortcuts into the \Windows\Start Menu\Programs\StartUp folder. Any shortcut found in this folder when Windows starts will be run as part of the Windows startup routine. Open the Windows Explorer (right-click My Computer and pick Explore). Navigate to the above-named folder to see what's there (you can get a quick look by clicking Start|Programs|StartUp). Edit as necessary (Computer Knowledge recommends you drag the shortcuts you are removing onto the desktop or into a temporary folder until you are certain you don't need them; they'll be easier to replace than recreate if you make a mistake).

Be careful. Some things may not be obvious. Try removing one thing at a time and then restarting the computer to see what happened. Changing more than one thing will make it difficult to detect which is at fault if problems occur.

One you probably should delete would be Microsoft FindFast. That program is supposed to speed file searches in Office but more often than not is the source of problems.

[Icon] Registry

The registry contains much information of importance to both Windows and programs running under Windows. For this reason one has to take great care in working with the registry. A backup is critical before doing anything with the registry. This is easily done from within the registry editor.

Start the registry editor by clicking on Start|Run and then typing "regedit" (without the quotes) into the dialog box that appears. Click OK. Navigation in the registry editor works just like navigation in Windows Explorer. First navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

There you will see, in the right window, more programs that Windows runs at startup. If you intend to delete or modify any of these entries first export the key to a file you can use to reinstate the entries should there be problems. With the Run key selected click on Registry|Export Registry File. Pick a name and location you can remember for the exported file and then export the key.

Now, edit the registry as necessary and then immediately restart Windows. If there are no problems, great; if there are problems double-click on the Run key registry file you created and then restart Windows. Double-clicking on the file will install it into the registry and restarting Windows should put things back the way they were.

Now, repeat the whole procedure above with the key:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

(Never said this would be easy![Smile]

[Icon] WINSTART.BAT

You remember batch files from DOS (if you are old enough). These are text files that run commands in them; line by line. If you have not found the autostart program you are looking for do a search for the file WINSTART.BAT. It will usually be in the root directory of the drive. If found while your computer is starting this file will be given control before Windows itself starts. The errant autostart program may be hiding here. Use any text editor to look at the contents of the file if one is found.

[Icon] AUTORUN.INF

An AUTORUN.INF file is designed to hold the information necessary to allow a disc, like a CD-ROM, to autostart when loaded. As the disc is detected by the operating system the AUTORUN.INF file is detected and the information in that file directs the operating system to, perhaps, start a particular program on the disc. This can be very convenient but it also can be a problem in that the operating system does not restrict itself to just CD-ROMs for AUTORUN.INF. If that file is found in the root directory of the system boot drive (usually C:\) then it will be accessed and the directions in the file followed during system boot. Thus, AUTORUN.INF becomes yet another way of autostarting something during Windows boot. If you find and need to delete an AUTORUN.INF file you may have to change its attributes first; if copied from a CD it's likely to be a read-only file (right-click the file, choose "Properties" and uncheck "Read-only").

[Icon] WIN.INI

This is a startup holdover from Windows 3.x. No matter, if found in the \Windows directory later versions of Windows will read and process the file. Navigate to the \Windows folder using Windows Explorer and look for a WIN.INI file. Use any text editor to look inside the file. What you are looking for is a line starting with either "load=" or "run=" in the section [windows] which is usually right at the start of the file.

If found, make a backup of the file and then edit those lines as necessary relative to your autostart program problems. Restart Windows and see if that fixes things. If not, use the backup to put things right and restart Windows to continue searching.

[Icon] AUTOEXEC.BAT and CONFIG.SYS

These startup leftovers from DOS still run on startup if found in the root directory of your main drive (usually C:\). While of little practical value they may contain older "real mode" drivers and programs that must load before Windows because the hardware these drivers control is not able to be reconfigured dynamically (Plug and Play). To see if any real mode drivers are active right-click on My Computer, select Properties, then click on the Performance tab. Look for any real mode drivers listed. If found, decide if you need the drivers and, if not, edit either AUTOEXEC.BAT or CONFIG.SYS to delete them (instead of deleting the line just put the letters REM and a space in front of the line so it's not executed; makes it easier to reinstate the line if necessary).

The easiest way to check to see if these files are needed is to use Windows Explorer to rename them (right-click on the file and select Rename). Then, reboot and see if there are problems. If not, great; if there are follow the prompts to boot into Safe Mode (if needed) and then rename the files back to their original names. After restarting again the problems should disappear.

Final Notes

We've described a number of places programs that start automatically when Windows starts can hide. And, we've described how these places can be modified to stop these programs from autostarting. But, you need to know that Windows is a very complicated operating system and can be fairly sensitive to changes. It's very important that you have a good backup before attempting to make any changes to any autostarting programs and then proceed with great caution; changing one thing at a time and then testing to see if the change caused any problems. This incremental approach will take much longer but is considerably safer.

Good luck.

Monday, May 28, 2007

How to stay young

HOW TO STAY YOUNG
1. Throw out nonessential numbers. This includes age, weight and height.
Let the doctors worry about them. That is why you pay "them."
2. Keep only cheerful friends. The grouches pull you down.
3. Keep learning. Learn more about the computer, crafts, gardening,
whatever. Never let the brain be idle. "An idle mind is the devil's
workshop." And the devil's name is Alzheimer's.
4. Enjoy the simple things.
5. Laugh often, long and loud. Laugh until you gasp for breath.
6. The tears happen..... Endure, grieve, and move on. The only person, who
is with us our entire life, is ourselves. Be ALIVE while you are alive.
7. Surround yourself with what you love, whether it's family, pets,
keepsakes, music, plants, hobbies, whatever. Your home is your refuge.
8. Cherish your health: If it is good, preserve it. If it is unstable,
improve it. If it is beyond what you can improve, get help.
9. Don't take guilt trips. Take a trip to the mall, even to the next
county; to a foreign country but NOT to where the guilt is.
10. Tell the people you love that you love them, at every opportunity.
AND ALWAYS REMEMBER:
Life is not measured by the number of breaths we take, but by the moments
that take our breath away.
We all need to live life to its fullest each day!!