How viruses appear in the computer. Who wrote the first computer virus

Ilya Aleksandrov

History of computer viruses

They are already accustomed to them. School teachers of informatics are not afraid of them, they do not write about them on the first stripes of newspapers. But they continue to fulfill their destructive role in the life of users of computers.

Prerefficers of electronic epidemics

To say where and when the first virus appeared, it is impossible, since there are no such data in nature. If the "computer" of the Charles Babbja, the "father" of the first computing car, there were no viruses, by the mid-seventies of the last century they became very common and unpleasant for most phenomenon. Nevertheless, the prerequisites for their creation appeared almost immediately with the creation of the first computer.

Back in 1940, Mathematics John von Neuman wrote a book in which self-replicating mathematical machines were described, that is, the principles that have formed the basis of all viruses. In 1959, American science Magazine SCIENTFIC AMERICAN has published the article L. Penrose, who spoke about independently propagating biological structures. The author considered the ability of such structures to mutations, activation and reproduction. Another scientist, F. Stahl, obtained from this knowledge article implemented in practice. Working by the Operator in the Research Laboratory, he had access to the most powerful computer for that time - IBM 650. The experiment was very surprised by the strand, surpassing all his expectations. The resulting "mutation" of mathematical algorithms, the electronic "Zvek" deleted all the traces of his "parents", who were present in the system, after which she self-esteem.

Naturally, all of the above works and experiments were directed not in order for the current virus writers to throw out a new "infection" on the Internet megabytes. Initially, these studies belonged to the field of creating artificial intelligence were academic interest. However, any discovery made in peaceful purposesmay be without much difficulties turned into a powerful weapon of destruction.

In 1961, the game "Darwin" was very popular among the computer. Her plot and meaning were simple: the player led the "race," which was supposed to destroy its competitors. Won the one who captures the whole given under the gameplay rAM. Special actions in the game did not need: it was necessary only to propagate the RAM to their free cells belonging to their race or grab the cells of the enemy. A similar algorithm is very similar to the logic of the work of destructive programs.

The wide distribution of computer networks has become a catalyst for the appearance of the first destructive programs - computer viruses.

70s: Start

The appearance of the world's first computer virus was recorded at the beginning of the 70s of the last century, when APRANET is on the expanses of the Military Computer Network modern Internet - Creeper was found. The virus was written for common in those days. operating system Tenex in which he penetrated, spreading through a modem connection. The inscription is periodically displayed on the screen of infected computers: "I'm The Creeper: Catch Me If You Can". Creeper's destructive actions did not commit to only this message annoying users. A little later, the "Antidiet" was written for him - the Reaper program that found a virus file and removed it. It spread, by the way, similar to CreePer. It can be said that the world's first antivirus was created "by analogy with a malicious program."

In 1974, the "frequent guest" on various servers had a program with a cute animal husbandry name Rabbit. "Rabbit" nothing but the spread and reproduction of yourself, did not. The program has been reproduced at a huge speed, gradually occupying all system resources. Sometimes Rabbit even caused servers failure.

Another example is the PERVADING ANIMAL logic game for the EXEC 8 operating system, the meaning of which was guessing the user of the riddled animal program. If he could not succeed, the game offered to modernize it, after which it appeared the opportunity to ask additional leading questions.

The modified version of the program strangely started to copy to other directory, as a result of which after a while in all folders hard disk It contained a copy of Pervading Animal. Since at the time every kilobyte of space was "on the weight of gold", such a behavior of the game was happy. It is still not clear whether this is a programmer error or the idea of \u200b\u200bvirus writers. However, the problem was quickly solved - the new version of the Exec 8 operating system was based on another type of file system, on which the program clog the file space could no longer.

80s: First epidemics

By the eighties of the last century, the computer stopped being a luxury available only to the chosen. PC owners are becoming more and more, in addition, the exchange of information between users using electronic announcements boards (BBS - Buletin Board System) has achieved an international scale.

In 1981, a truly massive viral epidemic occurred. Computers II computers are widespread at that time. ELK CLONE virus was recorded in boot sectors Doubles at the time of contacting them. ELK Clone distorted the image on the monitor, displayed various text messages, forced the text to flash. Increhensive users have shown from the actions of the virus to a stupor, while he continued to "move" from one computer to another.

In 1983, the American programmer Len Aidelman for the first time used the term "virus", which he identified self-magazing programs.

In 1986, a 19-year-old Pakistani bassita Faruk Alvi wrote a Brain virus. As well as ELK Clone, Brain hit the boot sector floppy disks. The program was not focused on any devastating functions, it only changed the label of all disks on "(c) brain." According to the author, he chased only one goal - to find out the level of computer piracy in his country. But after a few weeks after the activation of the virus, thousands of computers around the world were infected, which caused a real perolet among users and a storm of discussions in the media. In Brain, the reception was first used when, when reading an infected disc sector, the virus was substituted instead of the selected section.

In 1988, the first malicious program was created, which did not just infect the computer, but also applied to him with real harm. This virus was created at the University of Lehi, in which, by the way, he had previously mentioned Fred Cohen. Lehigh virus destroyed information on disks, hitting system files The presence of qualified specialists at the university was salvation - per wall educational institution He did not get his way. However, a considerable role in eliminating the threat of an epidemic was played by the algorithm of Lehigh itself - during the formatting of the Winchesters, he self-deducted with the rest of the information.

At the same time began to actively develop softwarewho defended computers from viruses. Antivirus programs The time was simple scanners that were trying to detect viral code in programs through contextual search. Another common "medicine" from malicious programs of that time were "immunizers". This type of software modified all programs in such a way that the viruses consider them already infected and did not perform any actions in relation to them. After the amount of viruses increased thousands of times, the use of immunizers was already useless.

Antivirus firms most often consisted of two or three people and their products were sold for the symbolic amount or distributed free. But the prevalence of protective programs was very low, and the continuous appearance of new viruses made them powerless. Internet at that time did not have time to "break out" from the "hugs" of scientists and the military, and to be updated without global Network It was almost impossible.

In the mid-1980s, the term "Virus Hoax" appeared - "viral hoax". At the end of the eighties, users were panically afraid of viruses: myths about programs that are out of order of the PC hardware, excited the mind of each computer owner. Virus Hoax was nothing more than false rumors about new computer epidemics. A story is remembered when one joker sent to different BBS messages about the appearance of a new virus, which spread through modems that operated at a speed of information transfer 2400 bits per second. In order not to infect the virus, the author recommended switching to modems at a speed of 1200 bits / s. And what do you think? The mass of users threw faster modems for their "security".

In 1988 there was a first epidemic caused by a network computer virus. Subsequently, such viruses became referred to as "worms". Created by some Robert Morris, the program struck computers working under UNIX OS. The creator's plans did not make harm to the system, the worm had only to penetrate the ARPANET network and remain unnoticed there. The virus had the ability to open passwords in the OS, and in the list of executing processes, the Morris's brainchild was displayed as an ordinary user process. The worm rapidly self-impeded and devoured all the free resources of the computer, as a result of which whole servers were out of order. Some of them were able to return to work only five days, since the vaccines against the worm did not exist. During his "walking around the world", the virus struck about 6,000 computer systems, torn even computers of the NASA research center. Robert Morris got 400 hours of public works, but entered the story as the author of the first devastating network worm.

90s: polymorphic viruses

In the early 90s of the last century, the English company Sophos, which worked by Jan Khuchar, Ed Wilding and Peter Layer, began to release the magazine Virus Bulletin. Virus Bulletin talked about computer viruses, as well as about all aspects of protection against them. The authors of the magazine were programmers, heads of antivirus companies, software developers. The magazine was non-profit: in his entire history, it was not printed in it advertising announcement. Because of this, Virus Bulletin was not widespread. His readers were mainly professionals in the field of IT ( information technologies), as well as employees of computer firms.

In 1990, a new type of malicious programs appeared - polymorphic viruses. The "polymorphism" was called the technology at which the virus could not be found by a scanner, looking for viruses using fragments of the already known malicious code. Polymorphism allows programs to generate code during execution, with the result that a copy of the virus on each new infected computer will differ from the previous one. The first such virus was Chameleon, written by Mark Kabi. After the appearance of polymorphic programs, an integral part of the antivirus was an emulator for the decryption of codes used by Evgeny Kaspersky.

In the same year, in Bulgaria, which was the center of world virus, a specialized BBS appeared, with which every wishes could download malicious programs. Conferences devoted to programming viruses appeared in UseNet.

At the same time, the book "Little Black Book On Computer Viruses" Marka Ludwig was published. She became the "Bible" of all the creators of viruses. The so-called "VX-scene" was formed - a community of programmers specializing in creating computer viruses.

Malicious program designers

In 1992, a hacker, known under the nickname Dark Avenger, released the MTE utility (Mutation Engine). With it, anyone, even the most primitive virus could be made polymorphic. The Peach virus endowed with the ability to bypass anti-virus software was created by the same person. Peach removed the database of the CENTRAL POINT AntiVirus program. This program, without finding a database, believed that it was launched for the first time, and created it again. Thus, the virus has progressed and continued to infect the system.

A group of programmers known on the network like Nowhere Man released VCL virus designer (Virus Creation Laboratory). From now on, any schoolboy, even who does not own programming languages, could be armed with the designer and collect a virus of any type and destructive power. With the advent of VCL, and so considerable "stream" of new computer pests was just huge. Is it wondering that a few days after entering the light of Windows 3.11, the first destructive program for this platform appeared? Win.vir_1_4 hit the executable operating system files, leading some of them to disrepair.

The first arrested virus writer

During 1993-94, the light saw new virus designers: PS-MPC and G2. Malicious programs generated by them became the most common danger on the Internet.

At the same time, a real "boom" was held among antivirus manufacturers - their programs finally became the mandatory component to almost any OS. Even Microsoft decided to penetrate the security market, which released Microsoft Antivirus (MSAV). Initially, the program was popular, but later the largest software manufacturer in the world stopped developing the product.

Leadership in this area gradually won the company Symantec, part of which became the largest producers Anti-virus software: CENTRAL POINT and FIFTH Generation Systems.

The epidemic of a new polymorphic virus, Pathogen, was no longer an event out of a series of outgoing, all the events were all started to get used to this. However, it was the first virus that was found and convicted. The unemployed Christopher Paul for creating malicious programs was sentenced to 18 months in prison.

Attack on Microsoft.

In 1995, all paca testers discovered with the Windows 95 operating system were infected with the Form boot virus. Fortunately, one of them discovered non-carry, and on the counters of the stores there was a normal, unreleased system.

In August of the same year, the first MacroVirus appeared, written in WordBasic, built into text editor MS Word. CONCEPT Macrowurus was infected with hundreds of thousands of computers around the globe, as a result of which he has long been leading in statistical studies of computer journals.

In 1996, the first epidemic was survived windows users 95 - their computers were amazed by the boza boot virus. In July of the same year, macrovirus creators switched from Word to the editor spreadsheets MS Excel, having released the Laroux virus for him.

It was not forced to wait and resident viruses using the "zero ring" of the OS. Win95.punch loaded into the system as a VXD driver, intercepted access to files and infected them.

Anti-virus slots

By 1997, Linux operating system, previously considered a stronghold of "purity and stability", was no longer a platform free from viruses. Linux.bliss, distributed through the Usenet conferences, infected executable files of this OS.

In the same year, two new types of worms spread through IRC and FTP were noted. Of particularly large amounts could "boast" IRC, in many respects because of its popularity, as well as numerous "holes" MIRC - the main client of such networks.

Under the end of the twentieth century, the scandals among antivirus producers began to be frequent in pursuit of leadership. Thus, McAfee's representatives announced that its programmers found a mistake in Dr.Solomon's antivirus. The essence of the statement was reduced to the fact that Dr.Solomon's could find new and technically advanced viruses only in a special "enhanced" mode, which switched only after finding ordinary, primitive worms. As a result, the antivirus showed good high-speed results when scanning unreleased discs, and excellent detection indicators when working with infected files. In response, Dr.Solomon`s filed a lawsuit to the court on McAfee, the cause of which was the "incorrectly built advertising company". As a result, the whole "fuel" ended with the purchase of McAfee control package of DR.Solomon`s.

After some time, a public statement was made by Taiwanese developers from Trend Micro, accused McAfee and Symantec in allegedly "violations of their patent for data scanning." The world was immediately represented by evidence of "sinless" companies, but Trend Micro has achieved its own, having received excellent free advertising in the media.

The most destructive viruses

Continue a detailed history of computer viruses up to this day does not make sense, since hundreds and thousands of new malicious programs occur annually. I will be limited only by a brief story about the most famous viruses that appeared after 1997:

CIH (1998) - The damage caused by the virus was about 80 million dollars. The virus was written by a programmer from Taiwan, and became one of the most destructive in history. "Chih" infected executable files and activated every year on April 26 - on the day of the anniversary of the accident at the Chernobyl NPP. CIH overwriting Flashbios, after which motherboards Become unsuitable for use. The first and last virus that caused the harm to the PC hardware.

Melissa (1999) - On March 26, 1999, this Macrovirus spread e-mail, infected about 20% office computers around the world. The largest corporations, such as Intel, were forced to stop working inside their local networks. Damage - from 300 to 500 million dollars.

Iloveyou (2000) - Script written on Visual Basic macro-language. Just like Melissa, spread by email with the letter "I Love You". The virus sent its copies according to all the address book data. mail client. All logins and passwords found by the worm on the computer were sent to the author's author. The latter, by the way, did not try to hide: he is a resident of the Philippines, where punishments for computer crimes are not provided.

Code Red (2001) - Network worm that uses an error in network service Microsoft IIS. On a given day, infected computers were to start a DDoS attack on the list of various servers, among which were the US government systems. Huge scales of the epidemic and as a result - losses of 2.5 billion (!) Dollars.

Blaster (2003) - Network worm that has displayed a message about the need to reboot on infected computers. A few days after its release on the Internet (August 11), millions of computers around the world were infected.

Sobig.f (2003) - Network worm, spread by email. Breeding with a huge speed of the virus downloaded on the infected computer additional files, "Burning" traffic and system resources. An interesting feature - September 10, the virus stopped its activities, no longer representing the threat to the user. Author Sobig.f, for information about which Microsoft offered 250 thousand dollars, not found so far.

Bagle (2004) - Network worm, distributed by classical method using file attachments in emails. A special "loophole" was installed on the infected computer, through which the attacker received full access to the system. The virus has more than a hundred modifications.

MyDoom (2004) - In January 2004, this virus lightningly spread throughout the Internet, as a result of which the average speed of downloading sites in the global network decreased by 50%. The worm owns a record for the speed of distribution: less than a day was infected by about two million computers. The exact figure is impossible due to the scale of the epidemic. The virus was created by an unknown programmer as an experiment, and independently ceased its activities on February 12 of the same year.

Sasser (2004) - The virus caused a "break" in the work of French satellite channels Data transfer, canceled some airlines, not to mention ordinary computers whose work was completely suspended. Sasser distributed thanks to the error in the Windows 2000 and XP security system, starting the port scanner on the infected computer. The virus was written by a 17-year-old German schoolboy. Interesting the fact that the guy launched the virus on the network on the day of his majority.

No end and edges

The history of computer viruses is not fully completed, continuing today. Perhaps while you read these lines, some provincial programmer writes new virus, even more cunning and destructive than all of the above.

Well, it remains only to us to hope for the mercy of the manufacturers of antiviruses and follow the security of their systems.


Mobile viruses

In 2000, a virus was first found for the Palmos platform. The PHAGE.936 program passed between the PDA during transmission through the IR port. In infection pocket computer Some files could be deleted, and applications are often spontaneously closed. Since then, several dozen viruses have appeared for various PDA platforms, although they are not so diverse and "bending" as their "counterparts" for personal computers.

To date, the malware for smartphones do not cause surprise. The first virus for Symbian OS, became the Cabir virus. He did not commit any destructive actions and was created only to demonstrate the potential susceptibility to mobile devices to viral attacks and epidemics. The worm spread through Bluetooth connections. How many more remaining to wait until the appearance of truly destructive viruses for mobile devices will show time.

  1. - viral encyclopedia, a description of all viruses. News and analytical reviews.
  2. - magazines, articles about viruses. Source codes and manuals.

Dmitry Moroz

