All Exams Test series for 1 year @ ₹349 only
Question

_______viruses are embedded in a system's memory so it can be reactivated if the original virus is deleted.

The correct answer is Resident

Understanding Computer Viruses and Persistence

Computer viruses are malicious software programs designed to replicate themselves and spread to other computers. They can cause various types of damage, from slowing down systems to corrupting data or stealing information. The question asks about a specific type of virus that utilizes a system's memory for persistence.

What are Resident Viruses?

A Resident virus is a type of computer virus that embeds itself into the computer's Random Access Memory (RAM). Once loaded into memory, the virus stays active and can execute its code whenever the operating system runs certain functions or whenever an infected program is launched. The key characteristic of a Resident virus is its ability to remain in memory even after the initial infected program that launched it has finished executing or the original virus file has been deleted.

Because the Resident virus resides in memory, it can continuously monitor the system and infect new files or perform other malicious activities without needing the original virus file to be present on the disk. This memory residency allows the virus to be reactivated or continue its operations even if antivirus software detects and deletes the source file on the disk.

Comparing Virus Types

Let's briefly look at the other options to understand why Resident viruses are the correct fit for the description provided:

  • File viruses: These viruses primarily infect executable files (.exe, .com, .bat, etc.). They attach themselves to the file's code. While they need a file to spread, their main characteristic described is infecting files, not necessarily residing persistently in memory after the initial file is closed or deleted.
  • Polymorphic viruses: These viruses are designed to change their code signature or encryption pattern each time they replicate. This makes it harder for signature-based antivirus software to detect them. Their defining feature is their ability to morph, not their memory residency for persistence.
  • Rootkit: A Rootkit is a type of malicious software that is designed to hide the existence of other malware and provide privileged access to a computer. Rootkits operate at a very low level within the operating system to remain undetected. While some Rootkits might use memory techniques, their primary purpose is stealth and gaining control, not necessarily residing in memory solely to reactivate after a source file is deleted.

Based on the defining characteristic described - embedding in memory to reactivate if the original virus file is deleted - the Resident virus is the type that fits this description precisely.

Conclusion

The virus type that embeds itself in a system's memory to reactivate if the original virus file is deleted is known as a Resident virus. This allows it to maintain persistence and continue its malicious activities even if the original point of entry or source file is removed.


Revision Table: Common Virus Types

Virus Type Primary Characteristic Persistence Method Example
Resident Virus Resides in RAM (memory) Stays active in memory, infecting files executed or opened.
File Virus Infects executable files Attaches to files; needs an infected file to run.
Boot Sector Virus Infects boot sector of disks Loads into memory during system boot-up.
Polymorphic Virus Changes its code to evade detection Modifies its signature upon infection.

Additional Information: Virus Persistence Mechanisms

Viruses and other malware employ various techniques to ensure they survive system reboots, antivirus scans, and user attempts at removal. Beyond memory residency used by Resident viruses, other common persistence mechanisms include:

  • Registry Modification: Adding entries to the Windows Registry to automatically launch when the system starts.
  • Startup Folders: Placing malicious executable files in system startup folders.
  • Service Installation: Installing themselves as a system service that starts automatically.
  • Scheduled Tasks: Creating scheduled tasks to run the malicious code at specific times or intervals.
  • Hooking System Processes: Injecting code into legitimate running processes to gain persistence and evade detection.

These mechanisms highlight the sophisticated ways malware attempts to maintain a foothold on infected systems, making removal challenging.

Was this answer helpful?

Important Questions from Memory

  1. Which among the following is incorrect about cache memory?

  2. Which among the following statements is incorrect about secondary memory?

  3. ______memory is sometimes used to increase the speed of processing by making current programs and data available to the CPU at a rapid rate.
  4. Which among the following registers in Instruction Cycle holds the last instruction fetched?

  5. Which among the following statements is incorrect?

Need Expert Advice?

Start Your Preparation with Prepp Mobile App

Download the app from Google Play & App Store
Download the app from Google Play & App Store
Prepp Mobile App