Zeus Trojan Spreading Through Drive-by Download

by PCSentry on 12/02/2009

This SCMagazine article illustrates how computers without all their applications updated can be infected:

“The malicious website contains an IFRAME that points to another website containing obfuscated JavaScript code that points to yet another page where a PDF file attempts to exploit known — but patched — vulnerabilities in Adobe Reader to download and execute a Zeus variant.”

This illustrates the importance of keeping applications up-to-date on computer systems.  Many technical people may use the argument that limited user accounts will prevent this type of attack, but this has not proven to be the case with all drive-by download attacks. 

Don’t get us wrong, using limited user accounts is a good idea, as are antivirus, firewalls, web content filtering and other defenses against computer attacks.  We’re just pointing out that PCSentry is a pretty good solution to add to the multiple layers of defense required to remain safe on the Internet.  PCSentry includes regular software vulnerability scans, reports of known vulnerable software, and updating of common applications.