Online malware - Compromised Computers Host an Average of 3 Malware Families - eWeek Security Watch

Compromised Computers Host an Average of 3 Malware Families

Written By
Brian Prince
Brian Prince
Sep 4, 2009
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Why take one when you can have a baker’s dozen?

Unfortunately, we are talking about infected files and not doughnuts. According to security company ESET, the average compromised machine is home to 13 infected files as well as malicious programs from three different malware families.

ESET based its findings on scans of more than a half-million PCs using the free online scanner on the company’s Website. In their own way, the results may demonstrate the way attackers are working together to tag-team vulnerable users.

According to ESET, the presence of multiple malware families is the result of the “pay per install” phenomenon, in which cyber-criminals are pushing out malware to computers under their control.

“Multiple malware families do not have any propagation mechanism built into their code,” blogged ESET Senior Researcher Pierre-Marc Bureau Sept. 3. “Instead, these pieces of malware are distributed and installed on computers by criminal gangs.”

Some good examples of this are campaigns to push out rogue anti-virus programs, he continued.

“Rogue anti-virus scams typically do not copy themselves to external drives, nor do they propagate through a network,” Bureau wrote. “Their operators simply pay other criminal gangs every time a copy of their rogue software is installed on a PC.”

Those familiar with the Conficker worm will remember that earlier in 2009 Conficker infections were linked to the installation of the Waledac worm. Waledac in turn installed a bogus anti-virus program.

In a conversation with me in April, RSA security pro Uri Rivner said attackers are increasingly buying subscriptions to fraud services to install data-stealing malware on machines they control. Subscriptions can cost $300 a month, potentially a drop in the bucket when compared with the profits that can be reaped from the theft of data such as banking credentials.

ESET’s findings also show that there isn’t always a one-to-one relationship between malware and infected files. Many files on an infected computer can be corrupted by the same piece of malware, Bureau wrote.

“This number can be explained by the comeback of file-infecting viruses, which were considered almost extinct a couple years ago,” he blogged. “Modern malware families such as WMA/TrojanDownloader.GetCodec infect multimedia files, and playing any of these files will result in an infection of a system. For example, if you have 500 songs on your computer and you get infected by that threat, you will have more than 500 malicious files on your PC. …

“To sum up, we are seeing more malware per infected computer and also more malicious files on each of them. Our virus lab receives over 100,000 new pieces of malware every day. There are more malware authors than ever and their technologies are getting better to rapidly create new variants of malicious code.”

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.