PC virus
Self-replicating malware that requires a host program to spread.
A PC virus is a type of malware that replicates itself by modifying other computer programs and inserting its own code. It generally requires a host program to execute, distinguishing it from a computer worm. PC viruses have been a persistent threat to personal computers since the early 1980s, using social engineering and security vulnerabilities to spread.
- First detected in the wild
- 1982 (Elk Cloner)
- First ibm pc compatible virus
- (c)Brain, 1986
- First windows virus
- WinVir, April 1992
- First windows 95 virus
- Bizatch (Boza), February 1996
- First windows nt virus
- Win32.Cabanas, late 1997
- Typical parts
- infection mechanism, payload, trigger
- Phases
- dormant, propagation, triggering, execution
Lore & Background
The first personal computer virus to appear in the wild was Elk Cloner in 1982, written by ninth grader Richard Skrenta. It attached to Apple DOS 3.3 and spread via floppy disk, displaying a poem on its 50th use. The first IBM PC compatible virus was (c)Brain, created in 1986 by Amjad Farooq Alvi and Basit Farooq Alvi in Lahore, Pakistan, reportedly to deter unauthorized copying of their software.
Reader's Guide
PC viruses have evolved significantly since the early 1980s. The first virus to target Microsoft Windows, WinVir, appeared in April 1992, relying on DOS interrupts. Later, in February 1996, the Bizatch virus targeted Windows 95's portable executable files. Win32.Cabanas, released in late 1997, was the first known virus to target Windows NT. Viruses use anti-detection strategies and can be motivated by profit, political messages, or exploration of cybersecurity. The antivirus industry emerged in response, providing protection for various operating systems.
Did You Know?
- The first PC virus in the wild, Elk Cloner, was written by a ninth grader in 1982 and activated on its 50th use.
- The first IBM PC compatible virus, (c)Brain, was created in 1986 by two brothers in Pakistan to deter software piracy.
- The first virus to target Windows 95, Bizatch, was created by Australian hackers from the VLAD crew.
- Fred Cohen's 1984 paper was the first to explicitly call a self-reproducing program a 'virus', a term suggested by Leonard Adleman in conversation.
Origins in Lahore: A Protective Measure Gone Awry
The Brain virus, released on 19 January 1986, holds the distinction of being the first computer virus designed for the IBM Personal Computer and its compatibles. Its creators were two brothers, Basit Farooq Alvi and Amjad Farooq Alvi, who at the time resided in Chah Miran, a neighborhood near Lahore Railway Station in Pakistan. According to statements the brothers gave to Time magazine, their motivation was purely defensive: they had developed a heart monitoring application for the IBM PC, and copies of the software were being pirated and distributed without authorization. The virus was conceived as a tracking tool meant to halt and monitor illegal duplication of their media. The Alvi brothers insisted the program was intended solely to target copyright infringement, not to cause harm to users. What began as a small-scale protective measure for a medical software product in a modest Pakistani neighborhood would soon spiral into a global phenomenon that neither brother could have anticipated.
Technical Design and Deliberate Restraint
Brain operated by overwriting the boot sector of a floppy disk with its own code, then relocating the genuine boot sector to a different location on the disk and flagging it as defective. Infected media typically displayed approximately five kilobytes of marked-bad sectors, and the disk label was altered to read ©Brain. The program also degraded performance, slowing the floppy drive and rendering seven kilobytes of memory inaccessible to DOS. Notably, the virus included a full street address in Allama Iqbal Town, Lahore, along with three telephone numbers, and a message inviting the user to contact the authors for a vaccination. One of Brain's most significant design choices was its deliberate avoidance of hard disks. By examining the most significant bit of the BIOS drive number, the virus could distinguish between floppy and fixed drives and simply skip the latter. This restraint set it apart from contemporaneous viruses that treated all storage identically and routinely destroyed hard-disk data. The combination of mild symptoms and hard-disk immunity meant Brain frequently escaped user notice, particularly when the slight slowdown in floppy access went unremarked.
The Phone Lines That Never Stopped
The Alvi brothers' carefully limited protective tool quickly became an international nuisance. Callers from the United Kingdom, the United States, and numerous other countries flooded their phone lines, demanding that the brothers disinfect their machines. The two were reportedly stunned by the volume and intensity of the calls, and they spent considerable effort trying to convince the increasingly furious callers that their original intent had never been malicious. The sheer volume of incoming calls overloaded their telephone lines entirely. Despite the chaos, the Alvi family did not abandon their tech ambitions. Together with a third brother, Shahid Farooq Alvi, they continued operating a business in Pakistan under the name Brain Telecommunication Limited, providing Brain NET Internet services. The irony was palpable: the very name that had become synonymous with the first PC virus was now the brand of a legitimate telecommunications company, a testament to the brothers' determination to keep building in their home city despite the global notoriety their code had earned.
A Quarter-Century Later: Legacy and Reckoning
Twenty-five years after its January 1986 debut, Brain remained the benchmark against which all subsequent PC viruses were measured. In 2011, Finnish security researcher Mikko Hyppönen of F-Secure traveled to Pakistan to sit down with Amjad and Basit for a documentary that explored the brothers' story from their own perspective. The film gained widespread popularity and sparked a wave of renewed interest in the virus's origins. Inspired by the documentary's reach, a collective of Pakistani bloggers operating under the banner Bloggerine conducted their own interviews with the Alvi brothers, adding a local journalistic dimension to the global conversation. Hyppönen also delivered a TED talk titled Fighting viruses, defending the net, further cementing Brain's place in cybersecurity lore. The Welcome to the Dungeon message that greeted users on infected disks, a nod to an early programming forum on Dungeon BBS, had only appeared a year after the initial release, when the brothers licensed a beta version of the code and could no longer be reached for the final update. That single cryptic greeting became one of the most recognized strings in early computing history.
Frequently Asked Questions
What is a PC virus?
A PC virus is a self-replicating piece of malicious code that spreads by rewriting the instructions inside legitimate programs. It must be carried by a host application before it can execute and propagate to other files.
How does a PC virus differ from a computer worm?
The core distinction is that a PC virus embeds its code into an existing program to spread, whereas a worm moves independently across networks without needing a host file. This makes viruses more dependent on a user opening or running an infected program.
What are the three typical components of a PC virus?
Every PC virus generally contains an infection mechanism for spreading, a payload that delivers the harmful effect, and a trigger that decides when the payload activates. These three elements work together to make the virus functional.
When was the first PC virus detected in the wild?
The earliest known wild detection was the Elk Cloner virus in 1982, which spread via floppy disks. The first virus targeting IBM PC-compatible machines was (c)Brain, which appeared in 1986.
Why is the PC virus considered a milestone in computing history?
It established the foundational model of self-replicating digital threats that still shapes cybersecurity today. Its reliance on social engineering and exploiting security gaps set the pattern for decades of subsequent malware development.
More in Pakistani inventions 1-20
Spotted an error? Know more?
Reader corrections go straight into our review queue. Suggest an edit · How this site is sourced
