Scanning for Malware Should Be an Outside Job
A few days ago, at WashingtonPost.com Brian Krebs blogged about businesses that had money stolen from them courtesy of malware on their computers.
One of the companies was Slack Auto Parts in Gainesville, Ga., which lost nearly $75,000 when "cyber intruders used malware planted on the controller's Windows PC .. [to] ... break into the company's bank accounts, create new user accounts at the bank, and then wire payments to money mules around the country."
What makes this particulary interesting is that after the fact, the anti-virus software used by the company (which Krebs did not identify) failed to find any malware. So too a "hired cyber security expert" gave the infected machine a clean bill of health. It wasn't until the company sought a second opinion was the keystroke logging "Clampi" Trojan horse program detected.