It comes via a “dropper” Bob. Same as with MS Trojans. The user has to click something. This is why I use NoScript for websurfing. It reduces the chance of loading malicious scripts and droppers from websites, the other methods are already known as safe practice to prevent it.
“A dropper is a small helper program that facilitates the delivery and installation of malware. Spammers and other bad actors use droppers to circumvent the signatures that anti-virus programs use to block or quarantine malicious code. It’s much easier to change the dropper, should its signature become recognized, than it would be to rewrite the malicious codebase.
“Droppers, like many of their larger Trojan horse counterparts, can be persistent or non-persistent. Non-persistent droppers install malware and then automatically remove themselves. Persistent droppers copy themselves to a hidden file and stay there until they complete the task they were created for.
Droppers can be spread by people who:
Open an infected e-mail attachment.
Pick up a drive-by download on an infected website.
Click on a malicious link in an email or on a website.
Using an infected flash drive.
Sometimes droppers are bundled with free utility programs (such as ad blockers) to avoid detection by antivirus software. When the free program executes, the dropper will first download and install malware before it unpacks and installs the legitimate utility.”
https://www.techtarget.com/whatis/definition/dropper
Thanks- i never c.ick stuff that pops up when browsing, but accidents could happen I suppose. R,someone else using the computer could click unaware.
[[Pick up a drive-by download on an infected website.]]
This is the one that worries me. A few years ago windows using explorer jnternet, I woild constantly go to what should have been safe sites, and get auto atical.y redirected, or have some file start downloading automatically. I had to run a program called “Rollback Rx” which would do a complete system restore (not partial like windows system restore utulity), and it would do,it when booting up, not from desktop, so it would activate before viruses could stop it. Whene ver I hit a site that redirected me or saw soe thing down,oading, I stopped immediately and did a rollback.
It was happening a fee times a month for awhile there, then things seemed to calm down a bit, then I switched to Firefox, and don’t get it anymore, but a,so,I use Linux, so thatnis added level of protection if it hits a site that downloads an .exe