YAVT: Slick new virus: Sends zip with password in email

Page 2 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

Heifetz

Golden Member
Oct 9, 1999
1,398
0
0
It shouldn't matter if the virus is in a zip, because most anti virus programs are set so that it scans anything that is created on the drive, or executed. In order to get infected, one has to execute the virus executable, but that should be caught by the virus scanner as long as it has the virus' signature.
 

neutralizer

Lifer
Oct 4, 2001
11,552
1
0
Originally posted by: Heifetz
It shouldn't matter if the virus is in a zip, because most anti virus programs are setup so it scans anything that is created on the drive, or anything that is executed. In order to get infected, one has to execute the virus payload, and that should be caught regardless of where it was originally placed.

Yeah, but the virus is in a password protected zip so AV cant scan it and it also disables AV updaters.
 

Heifetz

Golden Member
Oct 9, 1999
1,398
0
0
Originally posted by: neutralizer
Originally posted by: Heifetz
It shouldn't matter if the virus is in a zip, because most anti virus programs are setup so it scans anything that is created on the drive, or anything that is executed. In order to get infected, one has to execute the virus payload, and that should be caught regardless of where it was originally placed.

Yeah, but the virus is in a password protected zip so AV cant scan it and it also disables AV updaters.

Like I said, it shouldn't matter if the virus is in a zip, because in order to get infected, you need to open the zip and run the virus executable. But as long as your virus scanner is set so it scans all executables that are within its mask, then it should still catch it. It just won't catch it initially when the zip is created on your pc.



 

jjones

Lifer
Oct 9, 2001
15,424
2
0
Wow, an e-mail zipped attachment virus with a password. That's almost as tricky as those darned .exe viruses that I'm so tempted to open.
rolleye.gif
 

neutralizer

Lifer
Oct 4, 2001
11,552
1
0
It won't catch it if the AV updater process is disabled. However, if you already have the definition files, no worries.