How does virus or trojan work ?

Bubbaleone

Golden Member
Nov 20, 2011
1,803
4
76
AFAIK, all flavors of Zbot use a 'social engineering' vector to infect your PC; meaning you had to have convinced yourself to click on a link or email attachement in order to get infected. That's the big problem with malware that uses this vector; you (albeit inadvertently) gave the malware permission to install itself, thus your AV doesn't detect anything wrong. Unless you have your AV specifically configured for PUP (potentially unwanted program), and PUM (potentially unwanted modification) detection, and heuristic analysis enabled, your AV won't stop a Zbot.
 

Charlie98

Diamond Member
Nov 6, 2011
6,298
64
91
AFAIK, all flavors of Zbot use a 'social engineering' vector to infect your PC; meaning you had to have convinced yourself to click on a link or email attachement in order to get infected. That's the big problem with malware that uses this vector; you (albeit inadvertently) gave the malware permission to install itself, thus your AV doesn't detect anything wrong. Unless you have your AV specifically configured for PUP (potentially unwanted program), and PUM (potentially unwanted modification) detection, and heuristic analysis enabled, your AV won't stop a Zbot.

That's how it was explained to me, once. Essentially there isn't anything the AV can see until you click on a link... and the computer figures if you are clicking on it, it must be OK... and allows it to open.
 

lxskllr

No Lifer
Nov 30, 2004
59,994
10,475
126
so you can't watch a user all day long, what do you use ?

Give the user as few rights, and as much education as possible. In the end, there's limits on what you can do, especially if the user needs a level of freedom to do their job.
 

rsutoratosu

Platinum Member
Feb 18, 2011
2,716
4
81
i just read a few article, no admin acces no virus/malware = dont bet your life on it..

seems some of these virus trojan are getting a lot better some how..
 

Bubbaleone

Golden Member
Nov 20, 2011
1,803
4
76
i just read a few article, no admin acces no virus/malware = dont bet your life on it..

seems some of these virus trojan are getting a lot better some how..

What's the scenario you're talking about? I mean for example; kids on your home network browsing bad sites, you're a small business owner with a limited number of PCs on your network, working in IT for a bigger operation, but in any case you're looking for a better security solution than what you have now?


.
 
Last edited:

gitano

Member
Aug 4, 2008
93
0
66
+1 to the "social engineering" part, the user its allways the weak link.

Advertisment networks have a high rate of malware too, its possible to even get infected whitout clicking when browsing, using some addblock software to block adds can have the benefit to avoid a good amount.

Flash and Java are big offenders also, so keep flash up-to date and unistall Java when not using it.

On the anti software part i find using Security Essentials + Malwarebytes its more then enough.