# computer virus question

**URL:** <https://boards.straightdope.com/t/computer-virus-question/34634>\
**Category:** Factual Questions\
**Created:** [September 26, 2000, 5:51pm UTC](https://boards.straightdope.com/t/computer-virus-question/34634 "2000-09-26T17:51:59Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![jk1245](https://avatars.discourse-cdn.com/v4/letter/j/49beb7/32.png) [@jk1245](https://boards.straightdope.com/u/jk1245)\
**Post date:** [September 26, 2000, 5:51pm UTC](https://boards.straightdope.com/t/computer-virus-question/34634/1 "2000-09-26T17:51:59Z")

</div>

Hey all computer whizzes.

Is it possible for a non-executable file attachment to be infected? I am referring to things like bitmaps, jpegs and the like. Also, avi movies or MP3’s. I know word and excel can have macro viruses in them, can they have other types as well?  
Thanks!

---

<div class="post-metadata">

**Author:** ![mrblue92](https://avatars.discourse-cdn.com/v4/letter/m/5daacb/32.png) [@mrblue92](https://boards.straightdope.com/u/mrblue92)\
**Post date:** [September 26, 2000, 6:13pm UTC](https://boards.straightdope.com/t/computer-virus-question/34634/2 "2000-09-26T18:13:30Z")

</div>

The recent lovebug virus worked by taking the name of a legitimate file, changing the contents to it’s own executable code, and adding the “.vbs” extension so it would run as a Visual Basic script. So the file could look like an image, but actually be executable virus code.

Technically an HTML attachment could payload a virus as well, but I am unaware of any in the wild. And you mentioned Word and Excel documents (which can contain .vbs scripts).

Otherwise, non-executable file attachments are pretty safe since they don’t actually instruct the computer to take any action–they need an executable program to make any sense of them, like Notepad.

---

<div class="post-metadata">

**Author:** ![Lance\_Turbo](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lance_turbo/32/6156_2.png) [@Lance\_Turbo](https://boards.straightdope.com/u/Lance_Turbo)\
**Post date:** [September 26, 2000, 6:39pm UTC](https://boards.straightdope.com/t/computer-virus-question/34634/3 "2000-09-26T18:39:32Z")

</div>

> [@](#):
>
> \*Originally posted by mrblue92 \*  
> \*\*The recent lovebug virus worked by taking the name of a legitimate file, changing the contents to it’s own executable code, and adding the “.vbs” extension so it would run as a Visual Basic script. So the file could look like an image, but actually be executable virus code.  
> \*\*

No it didn’t. The lovebug was transmitted via a file named “iloveyou.txt.vbs”. Or something pretty close to that. It looked like a visual basic script to anyone who knew what a visual basic script was. People who didn’t know what a visual basic scripts was could make the mistake of thinking it was a text file. At that time I didn’t know what that visual basic scripts could be viruses or that they had the extension .vbs but I still didn’t open the iloveyou file sent to me with a file extension that I didn’t know to be safe.

To answer the OP, bitmaps, jpegs and mp3s and the like will not contain viruses. However, you can create a virus and name it BeaArthurNaked.jpg.exe and this could fool some people. Especially those anxious to see Bea Arthur Naked.

---

<div class="post-metadata">

**Author:** ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)\
**Post date:** [September 26, 2000, 7:03pm UTC](https://boards.straightdope.com/t/computer-virus-question/34634/4 "2000-09-26T19:03:49Z")

</div>

One particularly insidious thing about the iloveyou.txt.vbs scam is that you can turn off the disply of the extension in Windows. Thus, it would be displayed as iloveyou.txt and you wouldn’t notice it was something different by the name (though the icon would be different).

There’s also one particular extension that never displays in Windows unless you edit the registry.

However, for a file to spread a virus, it must be executable (i.e., a program). Graphics and MP3s are not programs and “virus” embedded in them would merely be displayed as gibberish and have not effect.

---

<div class="post-metadata">

**Author:** ![mrblue92](https://avatars.discourse-cdn.com/v4/letter/m/5daacb/32.png) [@mrblue92](https://boards.straightdope.com/u/mrblue92)\
**Post date:** [September 26, 2000, 7:07pm UTC](https://boards.straightdope.com/t/computer-virus-question/34634/5 "2000-09-26T19:07:59Z")

</div>

> [@](#):
>
> No it didn’t.

Picky, picky. The original “Lovebug” didn’t, but some of its subsequent variants did. I remember seeing files here like your “BeaArthur” example, only with .vbs as the real extension.

---

<div class="post-metadata">

**Author:** ![handy](https://avatars.discourse-cdn.com/v4/letter/h/b5a626/32.png) [@handy](https://boards.straightdope.com/u/handy)\
**Post date:** [September 26, 2000, 11:11pm UTC](https://boards.straightdope.com/t/computer-virus-question/34634/6 "2000-09-26T23:11:03Z")

</div>

“bitmaps, jpegs and the like. Also, avi movies or MP3’s”

No, not that I know of.

---

<div class="post-metadata">

**Author:** ![Greg\_Charles](https://avatars.discourse-cdn.com/v4/letter/g/839c29/32.png) [@Greg\_Charles](https://boards.straightdope.com/u/Greg_Charles)\
**Post date:** [September 26, 2000, 11:24pm UTC](https://boards.straightdope.com/t/computer-virus-question/34634/7 "2000-09-26T23:24:51Z")

</div>

It would be possible to take an executable or VBS file and rename it as something.jpg or something.MP3. Later, a small triggering program could rename this file back and start it running. I thought that’s what the Love Bug virus was doing. The most annoying side effect was that it would destroy your MP3s and images.

---

<div class="post-metadata">

**Author:** ![Greg\_Charles](https://avatars.discourse-cdn.com/v4/letter/g/839c29/32.png) [@Greg\_Charles](https://boards.straightdope.com/u/Greg_Charles)\
**Post date:** [September 26, 2000, 11:30pm UTC](https://boards.straightdope.com/t/computer-virus-question/34634/8 "2000-09-26T23:30:28Z")

</div>

It would be possible to take an executable or VBS file and rename it as something.jpg or something.MP3. Later, a small triggering program could rename this file back and start it running. I thought that’s what the Love Bug virus was doing. The most annoying side effect was that it would destroy your MP3s and images.

---

<div class="post-metadata">

**Author:** ![Bobort](https://avatars.discourse-cdn.com/v4/letter/b/ac8455/32.png) [@Bobort](https://boards.straightdope.com/u/Bobort)\
**Post date:** [September 26, 2000, 11:42pm UTC](https://boards.straightdope.com/t/computer-virus-question/34634/9 "2000-09-26T23:42:34Z")

</div>

Actually, it is quite possible to hide executable code in all sorts of random files with tricky ways to get it to execute. Here’s an example that recently happened: JPEG image files contain an internal “comment” field that’s used to store text information about the image (who made it, copyright, etc.). The field is basically ignored, but programs that display JPEGs have to parse it anyway. I don’t remember the details, but somebody figured out a way to cause a buffer overflow in many implementations that would execute code stored in the comment. Pretty devious. If you have an older version of Netscape or IE you’re probably vulnerable to it, although I’ve never heard of it actually being exploited.

A buffer overflow or format string vulnerability that can be exploited by user input can exist in any program, but it’s important to note that this is strictly a flaw of that program. Just because some program handles, e.g., JPEG comments unsafely doesn’t mean that there’s anything inherently dangerous about JPEGs or whatever.

---

<div class="post-metadata">

**Author:** ![JoeyBlades](https://avatars.discourse-cdn.com/v4/letter/j/a87d85/32.png) [@JoeyBlades](https://boards.straightdope.com/u/JoeyBlades)\
**Post date:** [September 27, 2000, 2:14pm UTC](https://boards.straightdope.com/t/computer-virus-question/34634/10 "2000-09-27T14:14:47Z")

</div>

Virus code can be attached to pratically any file. For the virus to spread, there has to be a mechanism to execute this code. For file types like jpgs, bmps, and mp3s to spread a virus, there needs to be a bit of code in the application that reads these file types that executes this embedded code. Since there is no earthly reason to facilitate this except to propagate viruses, you’re pretty safe. BTW, this is the same reason why most email viruses are hoaxes. Mail readers don’t execute embedded code. Microsoft mail servers do, and this was one of the mechanisms that facilitated the spread of the lovebug and similar vbs viruses. Also, I’m told that Microsoft Outlook could be configured to automatically execute attached vbs scripts, which would be an exception to my statement that mail readers don’t execute code… but Microsoft loves exceptions… which is the main reason I don’t use Outlook or Internet Explorer and I constantly curse the funky behavior of the Office Suite…

I think the example cited by Bobort would be technically a trojan horse, since there was no spread of infection - just an unhappy surprise. I could be wrong, since I’m not familiar with this particular incident.

---

<div class="post-metadata">

**Author:** ![muppetsoup](https://avatars.discourse-cdn.com/v4/letter/m/aca169/32.png) [@muppetsoup](https://boards.straightdope.com/u/muppetsoup)\
**Post date:** [September 27, 2000, 2:28pm UTC](https://boards.straightdope.com/t/computer-virus-question/34634/11 "2000-09-27T14:28:25Z")

</div>

> [@](#):
>
> \*Originally posted by mrblue92 \*  
> \*\*
> 
> > [@](#):
> >
> > No it didn’t.
> 
> Picky, picky. The original “Lovebug” didn’t, but some of its subsequent variants did. I remember seeing files here like your “BeaArthur” example, only with .vbs as the real extension. \*\*

i don’t think that was due to the code actively changing a file, but just people trying to spread by renaming the ‘beaarthur’ part.

---

<div class="post-metadata">

**Author:** ![mrblue92](https://avatars.discourse-cdn.com/v4/letter/m/5daacb/32.png) [@mrblue92](https://boards.straightdope.com/u/mrblue92)\
**Post date:** [September 27, 2000, 5:09pm UTC](https://boards.straightdope.com/t/computer-virus-question/34634/12 "2000-09-27T17:09:26Z")

</div>

> [@](#):
>
> i don’t think that was due to the code actively changing a file, but just people trying to spread by renaming the ‘beaarthur’ part.

Here’s the Norton write-up on the [LoveLetter Virus](http://www.norton.com/avcenter/venc/data/vbs.loveletter.a.html). (Well _technically_ it’s a worm, but you get the idea.) There are 29 recorded variants there–note that many say that files are overwritten. I don’t remember which variant(s) hit my company, but I know some of our users fell for the trick and lost files that needed to be restored from backup, assuming they had one.

---

<div class="post-metadata">

**Author:** ![mrblue92](https://avatars.discourse-cdn.com/v4/letter/m/5daacb/32.png) [@mrblue92](https://boards.straightdope.com/u/mrblue92)\
**Post date:** [September 27, 2000, 5:23pm UTC](https://boards.straightdope.com/t/computer-virus-question/34634/13 "2000-09-27T17:23:14Z")

</div>

From the Norton link:

> [@](#):
>
> This worm overwrites files on local and remote drives, including files with the extensions
> 
> .vbs, .vbe, .js, .jse, .css, .wsh, .sct, .hta, .jpg, .jpeg, .wav, .txt, .gif, .doc, .htm, .html, .xls, .ini, .bat, .com, .mp3, and .mp2.
> 
> The contents of these files will be replaced with the source code of the worm, thus destroying the original contents. The worm will also append the extension ‘.vbs’ to each of these files. For example, the file image.jpg will become image.jpg.vbs.

So according to Norton, the original version **did** overwrite files, as I stated at the very beginning. In fact, it appears all of the variants overwrite at least some files, though the extensions it touches vary.

---

<div class="post-metadata">

**Author:** ![AHunter3](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ahunter3/32/368_2.png) [@AHunter3](https://boards.straightdope.com/u/AHunter3)\
**Post date:** [September 27, 2000, 6:16pm UTC](https://boards.straightdope.com/t/computer-virus-question/34634/14 "2000-09-27T18:16:58Z")

</div>

In order to release (not merely contain) viral code, a computer file must contain instructions that either the OS or an individual application (program) running under it will interpret as instructions to go DO something.

On the PC platform, the OS reacts to a file depending on its extension (.vbs, .exe. .bat, .doc. .xls, etc); you could have a file chock full of viral code, put the “.jpg” file extension on it, and the OS would try to open it as an image (and would probably fail since it wouldn’t make sense as an image). Since most image viewers (Photoshop, Paint Shop Pro, etc) aren’t set up to engage in activity directed by instructions embedded in the files they open, viral code in a .jpg file (even if it were an image file) would for the most part lie dormant. (Exceptions that depend on tricking the application by overflowing its buffer have already been described above). You could make the same case for multimedia files (.mov, .avi, .mpg), sound files (.snd, .wav, .aif, .mp3), and plain text files (.txt).

On platforms that do not rely on (or solely upon) file extensions to indicate to the OS what to do with the file, a live, executable viral file could have any name you wanted to give it. A Mac virus could be in a file named OpenMe, or LoveLetter.txt, or NakedBeaArthur.jpg when it actuality it was an application (directly executable Mac program), a compiled AppleScript, a Java executable, an Excel or Word file with embedded (viral) macros, etc. However, in order to be executable in this fashion on a Mac, the file would have to have the four-character file type and (if not APPL) file creator which tell the OS what to open it with (APPL, aplt; XLS5, XCEL; etc), and this would cause the attachment to announce its basic file type by the type of icon it displays with. (Windows does this too–I assume text files do not have icons that look like visual basic .vbs files, and that the loveletter virus file would have shown such an icon).

To embed a virus in, let’s say, an MP3 file, you’d first have to have at least one popular MP3 player out there that was set up to do more than send the decompressed sound wave code to your audio output devices. But if someone (let’s say Microsoft, for instance :rolleyes:) were to decide to package a built-in MP3 player with every copy of the OS and that MP3 player were capable of responding to suddenly optional scripts in MP3 files that could direct it do things like changing the volume or switching its “skins” when the song came on, you then have opened the doors for a possible MP3 virus.

The wicked evil viruses of the last couple years have all spread via Microsoft Outlook, which was set up to respond to certain scripted commands by forwarding a given message to everyone in the associated MS Outlook Address Book; and which was set up to try to automatically open and display a wide range of types of attachments inline, thus saving the end user the hassle of downloading it to the Desktop and double-clicking it there. Most of these virii could infect a PC user who used Eudora or ccMail, but it required more intentional behavior on the part of the user and would not then automatically spread to other victims based on the current victim’s address book.

In light of this-- why the bloody hell so many businesses continue to standardize on Outlook is entirely beyond me.

---

<div class="post-metadata">

**Author:** ![jk1245](https://avatars.discourse-cdn.com/v4/letter/j/49beb7/32.png) [@jk1245](https://boards.straightdope.com/u/jk1245)\
**Post date:** [September 27, 2000, 7:26pm UTC](https://boards.straightdope.com/t/computer-virus-question/34634/15 "2000-09-27T19:26:36Z")

</div>

thanks for the informative replies everyone!

On the other hand, I’m sorry I ever started this thread for 3 simple words:

Naked Bea Arthur.  
ARRRRRRGGGGGHHHHHH!!!

---

<div class="post-metadata">

**Author:** ![carnivorousplant](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/carnivorousplant/32/3563_2.png) [@carnivorousplant](https://boards.straightdope.com/u/carnivorousplant)\
**Post date:** [September 27, 2000, 8:19pm UTC](https://boards.straightdope.com/t/computer-virus-question/34634/16 "2000-09-27T20:19:32Z")

</div>

In the latest very funny attack, what retset the browser’s homepage?

---

<div class="post-metadata">

**Author:** ![mrblue92](https://avatars.discourse-cdn.com/v4/letter/m/5daacb/32.png) [@mrblue92](https://boards.straightdope.com/u/mrblue92)\
**Post date:** [September 27, 2000, 10:52pm UTC](https://boards.straightdope.com/t/computer-virus-question/34634/17 "2000-09-27T22:52:48Z")

</div>

> [@](#):
>
> On the other hand, I’m sorry I ever started this thread for 3 simple words…

Oh, I think we all are.

“Part of me is dead. Part of me is gone forever…” - Crow

---

<div class="post-metadata">

**Author:** ![JoeyBlades](https://avatars.discourse-cdn.com/v4/letter/j/a87d85/32.png) [@JoeyBlades](https://boards.straightdope.com/u/JoeyBlades)\
**Post date:** [September 28, 2000, 2:04pm UTC](https://boards.straightdope.com/t/computer-virus-question/34634/18 "2000-09-28T14:04:54Z")

</div>

AHunter3:

> [@](#):
>
> A Mac virus could be in a file named OpenMe, or LoveLetter.txt, or NakedBeaArthur.jpg when it actuality it was an application (directly executable Mac program)…

Just for the record (and I know you know this Hunter) the “OpenMe” file or whatever is not the virus itself. This would be an example of a trojan horse launching a virus.

> [@](#):
>
> let’s say Microsoft, for instance :rolleyes were to decide to package a built-in MP3 player with every copy of the OS and that MP3 player were capable of responding to suddenly optional scripts in MP3 files that could direct it do things like changing the volume or switching its “skins” when the song came on…

YIKES! Don’t give them any ideas…
