# How Do Computer Viruses Transfer from an Infected DVD?

**URL:** https://boards.straightdope.com/t/how-do-computer-viruses-transfer-from-an-infected-dvd/919106
**Category:** Factual Questions
**Created:** [August 27, 2020, 12:01am UTC](https://boards.straightdope.com/t/how-do-computer-viruses-transfer-from-an-infected-dvd/919106 "2020-08-27T00:01:09Z")
**Posts on this page:** 15
**Page:** 1

<div class="post-metadata">

### Author: ![Ptolomy57](https://avatars.discourse-cdn.com/v4/letter/p/6a8cbe/32.png) [@Ptolomy57](https://boards.straightdope.com/u/Ptolomy57)
#### Post date: [August 27, 2020, 12:01am UTC](https://boards.straightdope.com/t/how-do-computer-viruses-transfer-from-an-infected-dvd/919106/1 "2020-08-27T00:01:10Z")

</div>

After reading Google, I only see the same common information over and over. Can a virus transfer from an infected DVD-RW or other storage peripheral by simply viewing the contents? While it is typically said that an infected file has to be opened to activate a virus, are there other ways a virus can spread from the peripheral to the PC hard drive? For one, can a virus lurk as a hidden file sitting in a folder and spread from there once the folder is opened, or must it be embedded within a document?

Please help me understand the ways a computer virus can spread. Thanks!

---

<div class="post-metadata">

### Author: ![crowmanyclouds](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/crowmanyclouds/32/19884_2.png) [@crowmanyclouds](https://boards.straightdope.com/u/crowmanyclouds)
#### Post date: [August 27, 2020, 12:09am UTC](https://boards.straightdope.com/t/how-do-computer-viruses-transfer-from-an-infected-dvd/919106/2 "2020-08-27T00:09:33Z")

</div>

I gave a 'puter the ‘Noint’ virus when I look at the _contents_ of a floppy, didn’t even open a folder!

---

<div class="post-metadata">

### Author: ![Joey\_P](https://avatars.discourse-cdn.com/v4/letter/j/919ad9/32.png) [@Joey\_P](https://boards.straightdope.com/u/Joey_P)
#### Post date: [August 27, 2020, 12:12am UTC](https://boards.straightdope.com/t/how-do-computer-viruses-transfer-from-an-infected-dvd/919106/3 "2020-08-27T00:12:21Z")

</div>

If you’re computer is set to auto-run anything in that drive, that would do it. Think about it, when you put a cd or dvd into your computer, generally, something starts happening automatically. Be it a media player pops up or a game starts playing or there’s an installer that shows up on the screen. All that happens because the computer reads what’s on the disc. If the disc is set to autorun a malicious program, it can easily transfer a virus to your computer.

---

<div class="post-metadata">

### Author: ![beowulff](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/beowulff/32/542_2.png) [@beowulff](https://boards.straightdope.com/u/beowulff)
#### Post date: [August 27, 2020, 12:15am UTC](https://boards.straightdope.com/t/how-do-computer-viruses-transfer-from-an-infected-dvd/919106/4 "2020-08-27T00:15:05Z")

</div>

I don’t know of any current exploits, but in theory, something like a specially-crafted preview icon on a data DVD could be an infection vector. If there was a bug in the jpeg decoder (for [example](https://security.stackexchange.com/questions/97856/can-simply-decompressing-a-jpeg-image-trigger-an-exploit), this (old) issue in Windows), then just inserting the DVD could be enough to compromise your system. But, as I said, I don’t think there are any current exploits like this.

---

<div class="post-metadata">

### Author: ![GreenWyvern](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/greenwyvern/32/2834_2.png) [@GreenWyvern](https://boards.straightdope.com/u/GreenWyvern)
#### Post date: [August 27, 2020, 2:02am UTC](https://boards.straightdope.com/t/how-do-computer-viruses-transfer-from-an-infected-dvd/919106/5 "2020-08-27T02:02:49Z")

</div>

When a DVD is inserted into a drive, your computer will look for a file called **autorun.inf** in the root directory of the DVD. It’s a text file containing a list of commands, similar to a .bat file.

By default it will run whatever it finds in this file, unless the autoplay setting has been turned off.

So you don’t even have to view the contents. Simply inserting the DVD can cause a malicious program to run.

---

<div class="post-metadata">

### Author: ![Melbourne](https://avatars.discourse-cdn.com/v4/letter/m/b5e925/32.png) [@Melbourne](https://boards.straightdope.com/u/Melbourne)
#### Post date: [August 27, 2020, 2:07am UTC](https://boards.straightdope.com/t/how-do-computer-viruses-transfer-from-an-infected-dvd/919106/6 "2020-08-27T02:07:02Z")

</div>

> [@beowulff](#):
>
> But, as I said, I don’t think there are any current exploits like this.

I think a specially crafted .ini file would still work. (It’s a way of changing the meaning of a folder). It doesn’t depend on anything particular being broken, and doesn’t depend on autoruns, just on looking at the folder using Windows Explorer. I don’t remember that the functionality was removed.

---

<div class="post-metadata">

### Author: ![Terminus\_Est](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/terminus_est/32/3087_2.png) [@Terminus\_Est](https://boards.straightdope.com/u/Terminus_Est)
#### Post date: [August 27, 2020, 2:14am UTC](https://boards.straightdope.com/t/how-do-computer-viruses-transfer-from-an-infected-dvd/919106/7 "2020-08-27T02:14:24Z")

</div>

If we extend the definition of “virus” to encompass all malware, then you need look no further than the infamous Sony rootkit. This was a copy protection measure on certain CDs produced by Sony BMG. Upon insertion, the CD would install software that would modify the OS to interfere with CD copying. It would also phone home about what the user was listening to.

> **[Sony BMG copy protection rootkit scandal](https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootkit_scandal)**
>
> Pages for logged out editors learn more
> 
> 		 
> A scandal erupted in 2005 regarding Sony BMG's implementation of copy protection measures on about 22 million CDs. When inserted into a computer, the CDs installed one of two pieces of software that provided a form of digital rights management (DRM) by modifying the operating system to interfere with CD copying. Neither program could easily be uninstalled, and they created vulnerabilities that were exploited by unrelated malware. One of the progra...

---

<div class="post-metadata">

### Author: ![echoreply](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/echoreply/32/3641_2.png) [@echoreply](https://boards.straightdope.com/u/echoreply)
#### Post date: [August 27, 2020, 4:04am UTC](https://boards.straightdope.com/t/how-do-computer-viruses-transfer-from-an-infected-dvd/919106/8 "2020-08-27T04:04:51Z")

</div>

Modern versions of Windows ask what to do when new media is inserted. It is possible for somebody to have selected “always do whatever the media wants.” In that case, yes a simple autorun.ini virus could install something.

Windows has recently [had flaws in it’s jpeg decoding software](https://nakedsecurity.sophos.com/2020/07/01/microsoft-issues-critical-fixes-for-booby-trapped-images-update-now/). It’s not clear that _those_ flaws could be used to infect a system, but it’s within the realm of possiblity. The example would be something like (as mentioned above) a nefarious image or movie is on a DVD. A flaw in the Windows software which creates the thumbnail images to display in Windows Explorer is exploited, and another flaw used to elevate the privileges, and then a virus installed before any file is opened by the user (though it was opened by the operating system to draw the thumbnails).

The “[Thunderspy](https://threatpost.com/millions-thunderbolt-devices-thunderspy-attack/155620/)” family of thunderbolt attacks might interest you. In order to be fast, thunderbolt devices can do things like directly access system memory. Because of that, they are supposed to be lots of security features. Those particular flaws involve live rewriting of the computer’s thunderbolt controller’s firmware, and then connecting a rogue device to take over the computer. This obviously is an evil maid type attack–the attacker needs physical access to the machine. (Imagine an encrypted or locked system, so simple physical access isn’t enough to get into it.)

It is also entirely possible that flaws exist in the thunderbolt controller which allow a rogue device to take over the computer simply by being plugged in, without having to hijack the thunderbolt controller first. I’m not aware these flaws exist, but again, it’s not some SciFi attach which is impossible.

I’m using Windows here as an example. All operating systems have exploitable bugs. Which does not mean that all are equally easy to infect, or all are equally likely to be exploitable.

So, if the question is, did inserting a DVD from a friend into your computer give you a virus, even though you didn’t actually run anything on the DVD? The answer is probably no.

If the question is, can you make this work plausibly in your spy novel, then the answer is probably yes.

> The disk labeled “Alice sessions 2008-11–2009-02” was left where Bob was sure to find it, and the sleeve saying “Carol’s intimate photography” was going to make the disk irresistible to Bob. His prurient nature would overcome his best opsec insticts. Little did he know of the zero day exploit in the Windows UDF filesystem driver would mean his computer was already owned before the thumbnails had finished loading.

(But actually well written, and stuff.)

---

<div class="post-metadata">

### Author: ![GreenWyvern](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/greenwyvern/32/2834_2.png) [@GreenWyvern](https://boards.straightdope.com/u/GreenWyvern)
#### Post date: [August 27, 2020, 5:50am UTC](https://boards.straightdope.com/t/how-do-computer-viruses-transfer-from-an-infected-dvd/919106/9 "2020-08-27T05:50:27Z")

</div>

NB: There is a technical difference between AutoRun and AutoPlay. They are _not_ the same thing.

AutoRun is a layer between AutoPlay and the Shell Hardware Detection service.

The dialog box that pops up to ask you what to do is for AutoPlay - but from Windows Vista onwards AutoRun will also pop up an AutoPlay box by default.

But the user may simply choose to run an autorun.inf file - or to _always_ run such files - without understanding the potential danger.

> Any user can configure AutoPlay to make various decisions for them; **by checking the appropriate box in the AutoPlay dialog, running flash drive malware becomes silent and automatic.**

See:

> **[autorun.inf](https://en.wikipedia.org/wiki/Autorun.inf)**
>
> An autorun.inf file is a text file that can be used by the AutoRun and AutoPlay components of Microsoft Windows operating systems. For the file to be discovered and used by these component, it must be located in the root directory of a volume. As Windows has a case-insensitive view of filenames, the autorun.inf file can be stored as AutoRun.inf or Autorun.INF or any other case combination.
> The AutoRun component was introduced in Windows 95 as a way of reducing support costs. AutoRun enabled appl...

> **[AutoRun | Attack vectors](https://en.wikipedia.org/wiki/AutoRun#Attack_vectors)**
>
> AutoRun functionality has been used as a malware vector for some time. Prior to Windows Vista, the default action with a CD-ROM drive type was to follow any autorun.inf file instructions without prompts or warnings. This makes rogue CD-ROMs one possible infection vector.
> In the same category are mixed content CD-ROMs. An audio CD, that a user would not expect to contain software at all, can contain a data section with an autorun.inf. Some companies, such as Sony BMG, have used this vector to ins...

---

<div class="post-metadata">

### Author: ![AHunter3](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ahunter3/32/368_2.png) [@AHunter3](https://boards.straightdope.com/u/AHunter3)
#### Post date: [August 27, 2020, 6:09am UTC](https://boards.straightdope.com/t/how-do-computer-viruses-transfer-from-an-infected-dvd/919106/10 "2020-08-27T06:09:22Z")

</div>

The last serious Macintosh virus was the AutoStart Worm which spread by exploiting the Mac equivalent of autorun as applied to removable media. We learned to shut off the option in the Control Panel.

Unlike a lot of previous Mac viruses, which did silly things like rename your hard drive to “trent” or pop up a message saying “Greetings from the great beyond” or equivalent, this one erased digital image files from people’s hard drives.

It was a MacOS 8 vintage virus.

---

<div class="post-metadata">

### Author: ![GreenWyvern](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/greenwyvern/32/2834_2.png) [@GreenWyvern](https://boards.straightdope.com/u/GreenWyvern)
#### Post date: [August 27, 2020, 7:42am UTC](https://boards.straightdope.com/t/how-do-computer-viruses-transfer-from-an-infected-dvd/919106/11 "2020-08-27T07:42:54Z")

</div>

> [@AHunter3](#):
>
> The last serious Macintosh virus was the AutoStart Worm…
> 
> It was a MacOS 8 vintage virus.

Um…no.

> **[All the Mac malware we know about](https://www.macworld.com/article/672879/list-of-mac-viruses-malware-and-security-flaws.html)**
>
> Wondering how many viruses exist for the Mac? Here is a list recent Mac malware attacks, viruses for Apple computers, and security threats that Mac users have suffered

> **Intego reckons that one in ten Mac computers is infected with the so-called Shlayer virus**

> **[Macs can get viruses, but do Macs need antivirus software?](https://www.macworld.com/article/670537/do-macs-need-antivirus.html)**
>
> Wondering if you need antivirus for Mac? Macs can get viruses and there are protections in macOS to keep you safe - but it's wise to extend the protection.

Malwarebytes added that: “Mac detections per endpoint increased from 4.8 in 2018 to a whopping 11.0 in 2019, a figure that is nearly double the same statistic for Windows. This means that **the average number of threats detected on a Mac is not only on the rise, but has surpassed Windows** ”.

---

<div class="post-metadata">

### Author: ![beowulff](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/beowulff/32/542_2.png) [@beowulff](https://boards.straightdope.com/u/beowulff)
#### Post date: [August 27, 2020, 1:21pm UTC](https://boards.straightdope.com/t/how-do-computer-viruses-transfer-from-an-infected-dvd/919106/12 "2020-08-27T13:21:34Z")

</div>

Once again, it comes down to the definition of “virus.”  
All viruses are malware, but not vice-versa.

---

<div class="post-metadata">

### Author: ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)
#### Post date: [August 27, 2020, 3:49pm UTC](https://boards.straightdope.com/t/how-do-computer-viruses-transfer-from-an-infected-dvd/919106/13 "2020-08-27T15:49:47Z")

</div>

True. As far as it goes, which IMO isn’t far. Unless it’s two security experts talking to each other, IMO we can / should assume “virus” is used as a 100% synonym for “malware”.

The OP is very clearly not a technical person. So we should apply the non-technical interpretation to their use of “virus”.

---

<div class="post-metadata">

### Author: ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)
#### Post date: [August 27, 2020, 6:55pm UTC](https://boards.straightdope.com/t/how-do-computer-viruses-transfer-from-an-infected-dvd/919106/14 "2020-08-27T18:55:27Z")

</div>

Eh, at least some level of distinction is necessary. There’s a difference between seeing your computer ask “This executable file is from a source that is not known to be trustworthy. It could potentially carry malware. Are you absolutely certain you want to run it?” and clicking “yes”, and your computer being automatically infected just because you put a disc in the drive and did nothing else. The former sort of malware, we’ll never be rid of, because after all, computers are supposed to do what we tell them to do. The presence of such malware is not a sign of an insecure computer system, but of an insecure user.

---

<div class="post-metadata">

### Author: ![Acierocolotl](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/acierocolotl/32/6241_2.png) [@Acierocolotl](https://boards.straightdope.com/u/Acierocolotl)
#### Post date: [August 27, 2020, 8:49pm UTC](https://boards.straightdope.com/t/how-do-computer-viruses-transfer-from-an-infected-dvd/919106/15 "2020-08-27T20:49:57Z")

</div>

> [@Ptolomy57](#):
>
> Please help me understand the ways a computer virus can spread. Thanks!

Very short version, as reasonably succinct as I can make it, with a minimum of technical details.

A virus is a program. In order to work its magic, two conditions have to happen: It has to be loaded into memory, and its instructions have to be executed. Some of its instructions are to self-replicate. One of the first things it may do is modify your computer’s files in such a way that the virus is now automatically loaded when you turn your computer on.

If you were to change the language around, using terms like “cell” and “DNA”, you’d be describing an actual virus: it injects itself into programs, and it (generally) duplicates itself.

Since you as a user are unlikely to just straight-up run a virus program, it has to resort to trickery. In the olden days, the virus would have to find an executable program and inject itself into the code so that when you ran the infected program, you also ran the virus.

Later on, one of the common infection vectors was from “buffer overflow attacks”. The .jpg one was mentioned above. This is challenging to explain briefly and I may need to pass over finer details.

In essence, your computer’s memory is used for both executable code and data that the executable code may refer to. A classic case is the .jpg buffer overflow. When the computer “sees” it’s to deal with an image, it will set aside a portion of memory for the image data (the “buffer”). It does this based on some data at the beginning of the file which informs the computer about the dimensions of the image, amongst other things. The viral payload sits at the end of this data, adding extra information to the image file.

When the computer loads the image data, it fills up the buffer, as predicted. The virus, however, is written “past” the limits of the buffer, into other memory that may have been used for actual running code. This can happen only because the coders who wrote the .jpg reading code trusted the data was going to be safe and didn’t enforce memory limits.

Buffer overflow attacks aren’t limited to just images. CMC’s experience above suggests it was also a buffer overflow attack (though there’s not enough information to hand to do more than guess).

In the case of your (theoretical, I hope) infected DVD, if you have all the autorun stuff turned off (I recall holding down shift while inserting media would prevent autorun) then no code from the disc would run. So long as there’s no attack vector from the file listing itself (and that looks secure), you’d be theoretically safe. If I wanted to be sure, I’d open that disc on another, older computer that contained little of value and was isolated from the network.

This turned out longer than I’d hoped. I hope I didn’t put you to sleep.
