answersLogoWhite

0

As the name indicates, a directory virus functions by infecting the directory of your computer. A directory is simply a larger file that contains information about other files and sub-directories within it. The general information consists of the file or directory name, the starting cluster, attributes, date and time and so forth. When a file is accessed, it scans the directory entry in search of the corresponding directory. There it is able to locate the starting cluster which is an index to the FAT (File Allocation Table). The FAT contains the addresses for all subsequent clusters until the last cluster is indicated by a marker like this: 0xFFF (16-bit FAT).

A directory virus inserts a malicious code into a cluster and marks it as allocated in the FAT. This prevents it from being allocated in the future. The virus then saves the first cluster and forces it to target other clusters, indicating each file it wants to infect. The malicious code typically contains an extension such as COM. (command) or EXE. (execute) which executes the virus.

User Avatar

Wiki User

14y ago

What else can I help you with?

Related Questions

How do you remove S-1-5-21-823518204 from recycler?

The directory S-1-5-21.... is a default directory when you create an account (for your PC) in a network. It mean you can not delete files in the directory and itself. And virus found that directory is a ideal place to stay in. If your anti-virus programme found viruses in the directory: Turn off your PC. Reboot in DOS (with Hirent Boot CD...), use Volkov Commander to find and delete all files in this directory (include virus files). Otherwise you can reinstall Windows on your PC. contact me at: galabaco@yahoo.com


Account constantly locked in active directory?

In Network, any computer is having virus.


How do you remove files that can not be healed?

If you're referring to your anti-virus/spyware not being able to heal an infected file then it's simple. Use the directory shown in your anti-virus software to locate the file. Copying the directory in to the address bar of your "My Documents" window is easier, then look through the directory for the name of the virus/malware. This should also be shown on the Anti-Virus. Then get rid of it from there.. If it doesn't work, re-boot your PC in to safe mode and follow the same steps. :)


How do you get rid of the Trojan bispy?

With AVG virusscanner Good Luck, Jahewi :-) Bispy might be in a directory that has a .exe extension on it, with a colon (:) on the end, which screws up Windows' ability to see that directory. Scan the computer with AVG (Norton and Symantec won't even find Bispy), and AVG will tell you what directory the virus is in. In my case, it was in c:\windows\system32\biview.exe:\ Because of the weird name for that directory, Windows Explorer couldn't even see that directory, and so couldn't remove it. Record the path to the virus on a piece of paper, then boot into Safe Mode. Start up a DOS box (Start >> Run >> type 'Command' >> Click 'OK') Change the directory in the DOS box to the directory directly above the directory holding the virus (in my case, it'd be C:\windows\system32\), then rename the weirdly named folder so it no longer has the .exe extension or the colon (:) on it. After that, remove the directory to get rid of the virus, and do another virus scan with AVG. You need to run these 5 essential steps to remove all the spyware on your computer. 1. Run Deckard's System Scanner (DSS) 2. Run Malwarebytes Anti-Malware 3. Run the anti spyware removal programs spybot 4 Run Superantispyware 5. Run a complete scan with free curing utility Dr.Web CureIt! Install threat fire which will enhance your antivirus protection


What is a cluster virus?

A type of computer virus that associates itself with the execution of programs by modifying directory table entries to ensure the virus itself will start when any program on the computer system is started. If infected with a cluster virus it will appear as if every program on the computer system is infected; however, a cluster virus is only in one place on the system.


How do you delete a virus in C RESTORE ARCHIVE FS28 CAB when you try to delete this file and you get told 'access denied source file may be in use'?

A virus in the _restore directory could not be deleted, I'm assuming you're using Windows XP and the _restore directory is the directory in windows for system restore (to return your computer to a previous date) therefore windows blocks all access as far as deleting and saving in that directory to keep viruses out of it.. The only way a virus could have got in that directory in the first place is if you had a virus when windows created a restore point, so if you ever go back to the date it created that restore point you'd have that virus, as far as the virus doing anything now FROM that directory (since you can't even read the files in there the virus wouldn't be able to run) but most antivirus programs will pick it up, but it will not affect your system as long as the virus isn't resident in any other program files NOT in that directory.. Hope this helps.. Matt Hello.... Here I am sitting with a very stiff neck working now foar about 5 hours to clean up a virus in the restore CAB... I "caught it" w/ my antivirus & Spyware scan... but could not remove it... But.... I typed the path into the address bar & when I got to C:_Restore/A ...then down dropped the LIST!!!! I scrolled down to the file number & clicked delete!! Amazing stuff ! I now have been able to access my PC to finish the scans... I just found 249 bots which are now being deleted! The PC was REALLLY Habging up & crashing prior to this! <a href="http://longpathtool.com"> here</a> you will find a handy tool to overcome this problem. Cheers!


How do you remove Trojan horse downloader. 1stbar.5.L?

OK, you need to run AVG or a virus scanner. Find the directory that the infected file is in. some how the folder is hidden, and i don't mean just a hidden file. i mean a fully hidden file. the virus was fond on a friends system in a subdirectory of "C:\Recycler\...\dc4.zip" . Once the directory is known, oppen a command promted, type CD "the directory its in", then "del *.*". Hope this helps people. Ewok and Marauder.


What are the warning symptoms ofAnna kournikova virus?

This a computer virus and there are no actual symptoms. The Anna Kournikova virus is a self-replicate virus which means that when the system is infected with this virus the system will spread the infection to other systems which will propagate the virus further and so on. Users get this virus through an e-mail attachment. Upon opening this attachment the system gets infected and the virus mail itself to all users found in the windows Address Book. Once the system is infected by this virus, the virus copies itself to the Windows directory as "AnnaKournikova.jpg.vbs". You will find it here : C:WINDOWSAnnaKournikova.jpg.vbs


What are the advantages and disadvantages of novell directory service?

pro: technical,easy to use, understandble, smells nice, looks good con: unreliable, sucks me, has a virus.


If you can't even get into Windows how can you remove a startpage virus from DOS?

I believe that if you hold the buttons 'd', 'i', and 'r' while the computer starts up, you can go into the directory system.


What do you mean by sub directory and current directory?

Current directory/Sub-directory **************************************** The current directory is simply the directory a user is currently in - for instance: when in the Home directory, or the Music directory, and so on. A sub directory is another directory inside a main directory - for instance: in the Music Directory - Jazz, Elkie Brooks, Classical, are examples of three sub directories.


Difference between directory and sub directory in dos?

A directory within an existing directory is called a sub directory.