CHAPTER 2 – VIRUSES, WORMS, AND MALICIOUS SOFTWARE
TRUE/FALSE
1. The W32.Pinfi virus is an example of a destructive virus that can infect Mac OS systems.
2. A benign virus is one that replicates but does not inflict harm on a computer.
3. Backdoor.Egghead is an example of a worm that is spread by buffer overflows.
4. In Netware, the startup.ncf file contains commands used by the server.exe startup program.
5. Boot or partition sector viruses particularly affect Windows and Netware systems.
6. Cookie snarfing is an attack where a spyware operator can reconstruct a user’s every move on the
Internet by capturing cookies or the information contained in the cookies.
7. The Netware 6.x operating system has a software update tool that connects to the Internet to obtain
patches.
8. Windows 2000 Server allows you to create an ERD, which enables you to fix problems that may arise
with the server, such as corrupted system files.
9. The Windows 2003 Server ASR set backs up all system files, system settings, and application data
files.
10. Organizational policy works best when users are included in the process, so that they know the
importance of security.
MODIFIED TRUE/FALSE
1. The first stage of virus spread that occurs is replication within the infected system.
_________________________
2. File infector viruses can infect systems through multiple means, particularly through boot or partition
sectors and through executable files. _________________________
3. A(n) stealth virus uses defenses to make itself hard to find and detect. _________________________
4. The Code Red worm replicates for the first 23 days of the month and then stops.
_________________________
5. The Digispid.B.Worm targets systems running the SQL Server database on Windows-based
workstations and servers. _________________________
6. A(n) macro virus, worm, or Trojan horse is a file that contains lines of computer code that can be run.
_________________________
7. Batch files and scripts are files that contain code or instructions that are run by a(n) interpreter.
_________________________
8. A(n) boot sector virus typically infects or replaces the instructions in the MBR or the Partition Boot
Sector. _________________________
9. Software exploitation is particularly aimed at new software and new software versions.
_________________________
10. Mac OS and NetWare automatically display the boot load information to the screen each time one of
these systems is booted. _________________________
MULTIPLE CHOICE
1. Which of the following virus programs is available for purchase on a Windows-based workstation?
a.
AntiVir Personal Edition
d.
Sophos Anti-virus
b.
Handybits Viruscan
e.
Both b and d
c.
VCatch Basic
2. Which anti-virus software is available for use on only Windows and Mac OS systems?
a.
Central Command Vexira AntiVirus
d.
McAfee VirusScan
b.
F-Prot AV
e.
Both c and d
c.
Norton AntiVirus
3. Which anti-virus software is available for use on Macintosh, NetWare, UNIX/Linux, and Windows–
based systems?
a.
AntiVir Personal Edition
c.
McAfee VirusScan
b.
HandyBits VirusScan
d.
Sophos Anti-Virus
4. Which of the following Microsoft operating systems uses driver signing?
a.
Windows XP
d.
Windows 95
b.
Windows ME
e.
Both a and c
c.
Windows 98
5. Which of the following operating systems uses an emergency repair disk?
a.
Windows 2000 Server
d.
Windows 2003 Server
b.
Windows 2000 Pro
e.
Both a and b
c.
Windows XP Pro
6. How many copies of the ASR set should you have for a server?
a.
1
c.
3
b.
2
d.
4
7. What do you need to have for Red Hat Linux if a system file on the hard disk is corrupted?
a.
An ERD
c.
A boot disk
b.
An ASR set
d.
An MBR
8. In Red Hat Linux, what command do you need to use to create a boot disk?
a.
mkboot
c.
mkbootdisk
b.
makebootdisk
d.
makebtdsk
9. What is another name for malicious software?
a.
malsoft
c.
scriptware
b.
malware
d.
scriptsoft
10. _____ is designed so that it does not infect all of these file types at once, but only a limited number
each time Windows Explorer runs.
a.
INIT 1984
c.
Slammer worm
b.
Code Red
d.
W32.Pinfi
11. The _____ virus can only become destructive if the user executes an infected file on a Friday the
thirteenth.
a.
Linux.Millen.Worm
c.
W32.Pinfi
b.
INIT 1984
d.
Code Red II
12. A _____ virus appends to program files such as system files, executable files, driver files, and
supplementary files, including .dlls.
a.
partition sector
c.
macro
b.
file infector
d.
multipartite
13. A _____ virus spreads to instruction set files typically used by word processors, spreadsheets,
databases, and other programs.
a.
boot sector
c.
macro
b.
file infector
d.
multipartite
14. A _____ virus can infect systems through multiple means, particularly through boot or partition sectors
and through executable files.
a.
boot sector
c.
macro
b.
multipartite
d.
file infector
15. A(n) _____ virus changes each time it is replicated, making it more difficult to create a defense against
it.
a.
armored
c.
polymorphic
b.
multipartite
d.
heuristic
16. A(n) _____ virus appears to run from a file other than the one to which it is actually appended.
a.
stealth
c.
polymorphic
b.
armored
d.
companion
17. A(n) _____ virus uses defenses to make itself hard to find and detect.
a.
polymorphic
c.
companion
b.
stealth
d.
heuristic
18. Which of the following worms uses buffer overflows to do damage?
a.
Code Red
d.
Both a and b
b.
Code Red II
e.
a, b, and c
c.
Linux.Millen.Worm
19. How many days of the month does the Code Red worm replicate?
a.
15
c.
23
b.
19
d.
29
20. What process does the Linux.Millen.Worm use on the attacked operating system?
a.
Telnet
c.
DNS
b.
FTP
d.
SMTP
21. The _____ targets systems running the SQL Server database on Windows-based workstations and
servers.
a.
Digispid.B.Worm
c.
Linux.Lion.Worm
b.
Linux.Millen.Worm
d.
Code Red II Worm
22. Which of the following is an example of a Trojan horse on a Mac OS system?
a.
Simpsons AppleScript Virus
c.
Backdoor.Egghead
b.
AOL4FREE
d.
Code Red
23. Which of the following is an example of a Red Hat Linux file that can be the target of a virus?
a.
autoexec.bat
c.
startup.ncf
b.
inittab
d.
win.ini
24. Which of the following is an example of a Netware 6.x file that can be the target of a virus?
a.
autoexec.bat
c.
win.ini
b.
startup.ncf
d.
Both a and b
25. Which file on a Windows-based system is run when a system is booted, and can be used to rename
specific files at startup?
a.
win.ini
c.
wininit.ini
b.
autoexec.bat
d.
winstart.bat
26. Which of the following executable file extensions can be found on a Netware 6.x system?
a.
.pl
c.
.wsf
b.
.msi
d.
.bin
27. Which of the following executable file extensions is found only on Windows-based systems?
a.
.mst
d.
.btm
b.
.msi
e.
All of the above
c.
.msp
28. In Red Hat Linux, what mode do you need to be in to run the fdisk/mbr utility which replaces the
MBR?
a.
Safe
c.
Recovery
b.
Rescue
d.
MBR
29. How was the Melissa virus transported?
a.
File sharing
c.
Buffer overflow
b.
Floppy disk
d.
E-mail
30. With which attachment was the Resume virus associated?
a.
Explorer.exe
c.
Explorer.doc
b.
Explorer.msi
d.
Explorer.com
31. Which of the following is notorious for enabling cookie snarfing?
a.
SpyNet
d.
Both a and b
b.
PeepNet
e.
a, b, and c
c.
Cookienet
32. What was one reason the Slammer worm was successful against SQL Server database servers in early
2003?
a.
It gained access through a previously unknown vulnerability in SQL server
b.
Many administrators had not installed new patches designed to block this attack
c.
It was a polymorphic worm that rapidly changed signatures
d.
It was a stealth worm that was difficult to detect
33. What is displayed in the figure above?
a.
Windows Update Setup Wizard
b.
Red Hat Network Alert Notification Tool
c.
Mac OS X Software Update Tool
d.
None of the above
34. What is displayed in the figure above?
a.
A bashrc file in Red Hat Linux
c.
A startup.ncf file in Netware
b.
A win.ini file in Windows XP
d.
The kernel file in Mac OS X
35. Which of the following operating systems would use the commands listed in the figure above?
a.
Windows XP
c.
Red Hat Linux
b.
Netware 6.x
d.
Mac OS X
YES/NO
1. Can the VCatch Basic Anti-virus program be used both in Windows and Linux environments?
2. Is Sophos Anti-virus free software that can be used in Macintosh, Netware, UNIX/Linux, and
Windows-based systems?
3. Is one advantage of a digital signature that it helps ensure the security of your system by allowing only
drivers and system files that have been verified by Microsoft?
4. Does Windows 2000 use an ASR set to recover from a system failure?
5. Should you create a new ASR set each time you add a protocol or install a new driver for a network
interface card?
6. Does an organizational policy work best if users are not included in the policy creation process?
7. In its destructive mode, will the INIT 1984 virus rename files using random characters and delete files
on hard drives?
8. Is Windows the only operating system that is vulnerable to a macro virus?
9. Does the AOL4FREE e-mail hoax contain the AOL4FREE.com attachment?
10. Can a boot or partition sector virus corrupt the address of the primary partition that is specified in the
partition table of a disk?
COMPLETION
1. Typically, eradicating boot or partition sector viruses involves recreating the ____________________
and Partition Boot Sector instructions.
2. One way to spread a(n) ____________________ virus is to attach it to a template that many users
share, enabling it to spread each time the template is opened in a new document.
3. The ____________________ virus did not destroy data, but instead inserted the following line in the
virus-carrying document when it was opened: “Twenty-two points, plus triple-word-score, plus fifty
points for using all my letters. Game’s over. I’m outta here.”
4. Viruses, worms, and Trojan horses all represent malicious software that use
_________________________ to find weaknesses or holes in operating systems and networks.
5. Code Red and Code Red II use a buffer overflow to attack weaknesses in ____________________
Services on Microsoft servers.
6. ____________________ may operate without being installed on a user’s computer by capturing
information related to the user’s Internet communications.
7. Windows XP Professional and Windows Server 2003 come with the ____________________ Setup
Wizard which is designed to help you remember to obtain new updates, or even to obtain them for
you.
8. In the ____________________ operating system, you can display the boot process by booting into
either single user mode or verbose mode.
9. ____________________ are one of the most vulnerable points of attack in an organization.
10. A(n) ____________________ is a program that replicates and replicates on the same computer, or one
that sends itself to many other computers on a network or the Internet.
MATCHING
Match the following terms to the appropriate definitions.
a.
ASR Set
f.
digital signature
b.
back door
g.
driver signing
c.
boot disk
h.
ERD
d.
boot sector
i.
MBR
e.
cookie
j.
spyware
1. A removable disk used to boot an operating system
2. The process of placing a digital signature in a device driver
3. A code that is placed in a file to verify its authenticity
4. A set of instructions used to find and load the operating system
5. A secret avenue into an operating system that bypasses normal security
6. In Windows 2000, a disk that contains repair and backup information
7. Information that a Web server stores on a client computer
8. Captures information about cookies sent between a Web server and a client
9. Backup media needed to start a failed Windows XP Pro system
10. The beginning of a disk where code to start up the operating system is stored
SHORT ANSWER
1. One way to classify viruses is by how they infect systems. List the four different classifications.
2. Viruses can be classified by the way they protect themselves from detection or from a virus scanner.
List the four classifications.
3. What is a destructive virus?
4. What is a benign virus?
5. What are the six typical methods used in malicious software attacks?
6. List eight examples of executable-type file extensions and the operating systems that use them..
7. List the three steps in the process of the initial bootup from a disk.
8. List five of the services, applications, systems, or functions that are known to be vulnerable in which
attackers may look for problems.
9. What basic steps should be taken to protect an operating system from malicious software?
10. List seven features should you look for when you purchase virus scanning software.