Solved

The return of macro viruses

Posted on 2016-08-08
3
21 Views
Last Modified: 2016-08-27
Macro viruses used to be widespread around 2003-2008. Then, they seemed to disappear.  Now it seems in the last year or two that they are back. What was the driver for this?
0
Comment
Question by:furuno
  • 2
3 Comments
 
LVL 80

Accepted Solution

by:
David Johnson, CD, MVP earned 500 total points (awarded by participants)
ID: 41747797
actually the largest growth has been in ransomware virus's as the payload. Anti-Virus detection is pretty good these days and a macro that can access .net runtime can be scanned forever and nothing untoward will be found. One must always be vigilant about any macro enabled document and ensure that it comes from a known safe sender or safe location. Macro Execution is disabled unless the file is from a trusted location and you have had a chance to 'enable macros'.. I've turned off script execution in adobe reader/acrobat for years by default for this reason as well. Not many pdf's need to execute scripting.

The last major macro virus was Melissa in 1999 and due to the security policies in effect at that date it was on a tear and Microsoft had to shut down incoming email to try and stem the tide.

Many experts here on EE will not run any macro enabled documents.
0
 
LVL 2

Author Comment

by:furuno
ID: 41747923
Thanks David for that helpful response.

"Anti-Virus detection is pretty good these days"

Why do you say that?
0
 
LVL 80

Expert Comment

by:David Johnson, CD, MVP
ID: 41772820
FWIW, the anti-virus community is pretty proactive and updates are daily or more often.  The problem being that most ransomware sends out unique payloads so the # of uniques is on the rise. Unfortunately this defeats signature based AV
0

Featured Post

The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In a recent article here at Experts Exchange (http://www.experts-exchange.com/articles/18880/PaperPort-14-in-Windows-10-A-First-Look.html), I discussed my nine-month sandbox testing of the Windows 10 Technical Preview, specifically with respect to r…
Recently, I read that Microsoft has analysed statistics for their security intelligence report. It revealed: still, the clear majority of windows users do their daily work as administrator. An administrative account is a burden, security-wise. My ar…
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question