System information

18 Kaspersky Internet Security 2009
Classic viruses reproduce only on the local resources of a certain computer, they
cannot independently penetrate other computers. They can penetrate other
computers only if it adds its copy into a file stored in a shared folder or on a CD
or if the user forwards an e-mail messages with at infected attachment.
Code of a classic virus can penetrate various areas of a computer, operating
system or application. Based on the environment, there is a distinction between
file, boot, script and macro viruses.
Viruses can infect files using various methods. Overwriting viruses write their
own code replacing the code of the file they infect and after they destroy the
content of such file. The infected file stops working and cannot be disinfected.
Parasitic viruses modify files leaving them fully or partially operating. Companion
viruses do not modify files but create their duplicates. When such infected file is
opened, its duplicate, that is the virus, will be run. There are also link viruses,
(OBJ) viruses that infect object modules, viruses that infect compiler libraries
(LIB), viruses that infect original text of programs, etc.
Worm
After it penetrates the system, the code of a network worm, similarly to the
classic virus code, gets activated and performs its malicious action. The network
worm received its name due to its ability to tunnel from one computer to another -
without he user's knowledge - to send copies of itself through various information
channels.
The major method of proliferation is the main attribute that differentiates various
types of worms. The table below lists types of worms based on the method of
their proliferation.
Table 1. Worms by the method of proliferation
TYPE
DESCRIPTION
IM-
Worm
These worms propagate through IM (instant
messaging) clients, such as ICQ, MSN
Messenger, AOL Instant Messenger, Yahoo
Pager or Skype.
Usually such worm uses contact lists to send
messages containing a link to a file with its copy
on the website. When a user downloads and
opens such file, the worm will be activated.