YES you can still get Malware even if you aren’t logged in as Administrator!

I'm a firm believer that running with minimal privileges/rights is a good thing from a security perspective. The challenges of running legacy software without Administrator rights have faced most people who've embraced this approach. Aaron Margosis' blog contains many helpful suggestions as does the recording of his excellent session from TechEd.

I recommend replaying the recording of Mark Russinovich's Understanding and Fighting Malware session too as fifty minutes in he explains how User Mode API filtering works and later in the session he shows how this can be used by Malware to hide itself. User Mode API filtering provides the means for Malware to interfere with the messages being sent to user mode processes. Such Malware doesn't have to be running as Administrator.

That's not to say that running with least privileges doesn't help even in this case - at least if you are running as a regular user and accidentally trigger such Malware you have the option of logging in as Administrator to track down the tell tale signs that Malware is present and are able to remove it. Mark explains this whole area far better than I do and hence it's well worth replaying his session.


Comments (3)

  1. says:

    I’ve run Norton & MS anti-virus software, but apparently still have a bug. When I hit "2" or "1" then "Enter" the Microsoft Media Player pops up.

    I can’t figure out where the glitch is!

    Any suggestions?

  2. Steve Lamb says:

    I’ve not heard of that one. Sounds like some sort of keyboard shortcut/macro. I’m thinking about the software that works with keyboards which have extra keys.

  3. Matt Dickins says:

    I’m not even going to pretend I like Norton (or anyone else I know in computers), but I’d be with Steve on this one.

    Purely for malware (i.e. Spyware and Adware) I use MS, Spyware blaster, Spybot S&D and Ad-aware. Each picks up more stuff each time I scan. And I do use the internet ‘safely’.

    P.S. MS don’t make anti-virus software

Skip to main content