I have a question regarding the "monitored time" between the infection with an unknown malware and detection by webroot community and final removal and reversal of infected objects.
I keep seeing on WILDERS PREVEX forum the reply that even though SA might not detect an unknown threat in time, the SA package will MONITOR all activates performed by the new Threat and once the Threat gets identified as threat than those activities are reverted back.
Now assume this scenario:
System gets infected with an unknown strain, the user then logs into a bank account, logs into World of Warcraft, any other non-browser entity. What is the new strain allowed to see? I understand that the new strain might get blocked from seeing the bank account login since the user is using a browser that is behind the SA screen capture protection. However, can the new strain see the WoW login as it's being typed? How about anything else?
What if the new strain is a rootkit and it attempts to plant itself into the system folder and hide on reboot? Will the SA allow the strain to deposit itself into system folder and what happens when the system is reboot and the rootkit takes hold? Will SA be able to remove the Rootkit once the definitions are added?
How long does the program stay in monitored mode? I mean it's been said that SA determines if the program is malicious or not after a specific amount of time. So what happens if it's determined that the program is not malicious after x amount of days? Are all the tracks deleted?
Sorry just the idea of relaying on a rollback feature of the detection algorithm as opposed to superb detection algorithm frightens me a bit.
I know it's better to have the rollback feature then not having anything at all, the main problem is: How truly effective is the rollback feature in today's world?
Questin regarding the wild time between infection and detection.
Login to the community
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.