A computer virus is self-replicating malicious code that attaches to legitimate programs or files and spreads when the infected host is executed or opened.
A computer virus is self-replicating malicious code that inserts itself into legitimate programs, documents, or boot sectors. Unlike worms, viruses require host file execution to activate and propagate. Once triggered, viruses replicate by infecting additional files and may deliver destructive payloads including data corruption, system modification, information theft, or resource consumption. While less prevalent than modern malware types, viruses remain a relevant threat category.
Virus types include file infectors attaching to executable programs, macro viruses embedding in document templates, boot sector viruses infecting system startup areas, polymorphic viruses changing their code with each replication to evade detection, metamorphic viruses completely rewriting themselves, multipartite viruses combining multiple infection methods, and cavity viruses inserting code into empty sections of host files without changing file size.
Viruses spread through infected email attachments, compromised software downloads, infected removable media, network file shares containing infected documents, malicious websites exploiting browser vulnerabilities, and supply chain compromise of legitimate software distributions. Social engineering accelerates spread by tricking users into opening infected files. Modern distribution increasingly leverages cloud storage services and collaboration platforms for propagation.
Protect against viruses through next-generation antivirus with behavioral detection, email security scanning attachments and links, endpoint detection and response platforms, application whitelisting preventing unauthorized executable execution, regular software updates closing exploitation vectors, user security awareness training, network segmentation limiting propagation paths, and web content filtering blocking malicious download sources.
Malware is the broad category encompassing all malicious software including viruses, worms, trojans, ransomware, spyware, and adware. A virus is a specific malware type distinguished by its self-replication through host file infection requiring user action to propagate. While all viruses are malware, not all malware qualifies as viruses. Modern threats increasingly use non-viral malware delivery methods that do not require host file infection.
Virus detection evolved from simple signature matching in the 1980s through heuristic analysis detecting suspicious code patterns, behavioral monitoring identifying malicious runtime actions, machine learning classifying unknown samples, sandboxing executing suspicious files in isolated environments, and cloud-based reputation systems leveraging collective intelligence. Modern solutions combine multiple techniques for defense against polymorphic and zero-day viral threats.
Polymorphic viruses modify their code with each replication while maintaining functional equivalence, generating unique signatures that evade static signature-based detection. Techniques include encryption with variable decryption routines, code transposition, register substitution, and instruction replacement. Detection requires behavioral analysis, emulation-based scanning that executes code to observe behavior, and machine learning pattern recognition across variant families.
Historical virus outbreaks caused massive global disruption. The ILOVEYOU virus (2000) caused an estimated $10 billion in damages by spreading through email. Melissa (1999) overwhelmed email servers worldwide. CIH/Chernobyl (1998) destroyed BIOS firmware and hard drive data. Code Red (2001) infected hundreds of thousands of servers. These incidents drove the evolution of antivirus technology, email security, and organizational security awareness programs.