Hello
1.
Malware that would: delete a file or make changes to a file, without the user knowing.
Would AVG, Malwarebytes etc. detect this kind of malware?
Or could this type of malware stay undetected, if it was new and advaned?
2.
Could that kind of malware access a Windows OneDrive folder, or does Microsoft scan their OneDrive cloud-system for malware?
Thank you
So, people ask about this a lot. Can your antivirus, like AVG or Malwarebytes, really catch this stuff? And what about OneDrive?
My take is, yeah, for the most part, your AV is designed to detect this. But it's not how it used to be. It's less about matching a "signature" of a known virus.
The real magic now is "behavioral detection." Your AV is basically watching for suspicious actions. Think about it, a brand-new piece of malware that no one has ever seen before still has to do something, right? If it suddenly starts trying to delete or encrypt thousands of your files all at once, well, that's not normal behavior. Your AV sees that action, throws a red flag, and (hopefully) shuts it down.
But, and this is the big "but", it's not perfect. It's a constant cat-and-mouse game. Brand new, "zero-day" malware is often specifically built to be quiet and try to get around this behavioral detection, at least temporarily. It's a huge problem. They might evade it just long enough to do the damage before the security companies catch on and push an update. So, yeah, I'd say it's good protection, but I'd never, ever rely on it 100%.
And this brings us to OneDrive. This is where things get really sticky.
Yes, malware on your PC can absolutely access your local OneDrive folder. You have to remember, that "OneDrive" folder on your computer? It's just a folder. As far as your PC is concerned, it's no different than "My Documents." Any program, including malware, can read, write, and delete files in it.
The real danger here isn't just that it trashes your local files. The danger is that OneDrive will then sync those harmful changes to the cloud. The malware encrypts your local files, and OneDrive just thinks, "Oh, a bunch of file updates! Time to sync!" and it faithfully uploads all that garbage, writing over your good cloud copies. It's honestly just doing its job, but it's a huge vulnerability.
Luckily, Microsoft knows this. They have two main defenses, but only one of them really matters, in my opinion.
1. OneDrive scans files for known viruses when they're uploaded. That's fine. It'll catch the common stuff. But like we just discussed, it's pretty much useless against a brand-new, zero-day attack.
2. This is the big one. OneDrive has "Ransomware Detection." If it sees a massive, catastrophic file change (like your whole drive getting encrypted), it will alert you. But more importantly, it gives you the power to restore your entire OneDrive to a point in time before the attack happened. I think you can roll back up to 30 days.
This File Restore feature is, for me, the single most important part of the whole system. Your AV is your first line of defense, but the restore feature is your last. It's the "undo" button for a total disaster.