Windows Viruses on Windows Platforms
To date there is no such thing as a Windows boot virus, although theoretically NT is ripe for such an exploit. Windows executable viruses, however, are able to spread on different Windows versions depending on how they were written and the platform they land on.
First Windows Viruses
The first native Windows virus, WinVir, didn’t appear until April 1992, a full two years after Windows 3.0 was released. Although it infected Windows .EXE files, it contained no Windows API calls and instead resorted to DOS interrupts, which showed even two years later that virus writers didn’t really understand the Windows environment. When WinVir was run, it would infect every Windows .EXE in the current subdirectory, and at the same time disinfect the program it was initially launched from. Virus writers didn’t wait as long to develop a 9x virus, although Windows NT proved a tougher nut to crack.
Released in Internet newsgroups in February 1996 by the Australian VLAD virus writing group, Boza was the first Windows 95 virus. When run, the direct infection (nonresident) virus would look for three 32-bit executables to infect in the current directory. If it couldn’t locate three hosts, it kept moving up a directory level until it found three files to infect. Eventually, it would stop at the root directory. On the 30th of every month, Boza will display a message box announcing its presence and list other viruses programmed by the VLAD group.
Released in late 1997, ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access