Fight back against spyware

By Brien M. Posey MCSE, TechRepublic
04 October 2004 09:00 AM
Tags: security, spy, spyware, winsock
It never ceases to amaze me just how hostile the Internet really is.

As if fighting with things like spam, pop-ups, and viruses wasn't enough, keeping spyware off of users' computers has practically turned into a full-time job. The reason why keeping spyware at bay is such an ordeal is because there are so many different types of spyware, and because spyware authors go to great lengths to ensure that you won't be able to get rid of the various spyware modules. Using these techniques, you can get spyware under control in your organization.

What is spyware?
In case you didn't already know, spyware is a generic term usually applied to what I like to call -browser parasites." In most cases, spyware gets installed onto your computer without your knowledge when you visit a malicious Web site. In a way, spyware is actually sneakier than most viruses because most e-mail viruses get sent to you and don't actually activate unless you open an infected attachment.

Most spyware modules install without you having to do anything other than visit a malicious Web site. Furthermore, visiting such a site is easier to do than you might realize. How many times have you accidentally mistyped the name of a common site into your browser and unintentionally landed on another site? Often sites that capitalize on common misspellings of popular site names are the most notorious for distributing spyware.

So what does a spyware module do once it's installed onto your system? It varies because there are many different types of spyware. Some spyware modules monitor your browsing habits so that they can flood your computer with pop-up ads based on the types of sites that you visit. Others look for things like credit card numbers and transmit them to some unknown destination across the Internet. Still other spyware modules hijack Internet Explorer, resetting the home page and filling your Favorites list with Web sites of the author's choosing.

Why is spyware so hard to get rid of?
So far, you have seen that spyware has virus-like qualities, so you might be wondering what makes spyware so much more difficult to get rid of than a virus? Traditionally, controlling spyware just hasn't been as much of an issue as controlling viruses. Think about it for a second. Almost everyone has some sort of antivirus program installed, but how many non-IT people do you know that have programs installed for preventing spyware?

Although a lot of the antivirus manufacturers are starting to scan for spyware along with viruses, in most cases, the only way to really get rid of spyware is to use an anti-spyware program, such as Lavasoft's Ad-Aware, shown in Figure A.

Figure A

Ad-Aware does a good job of getting rid of spyware and is free for personal use.

In case you aren't familiar with Ad-Aware, it is, in my opinion, one of the better utilities for cleansing your computer of spyware. One of the best things about it, though, is that it is completely free for personal use. You can download the personal version of Ad-Aware from Lavasoft's Web site. Lavasoft also makes a professional version that will continuously monitor your PC for spyware.

If Ad-Aware works so well, you might be wondering why I don't just end this article right now and save you some reading. It's true that Ad-Aware works very well when it comes to removing spyware. The problem is that, depending on the type of spyware that's infecting your system, your system may not work correctly once the spyware has been removed. This problem is not specific to Ad-Aware, but is common among spyware removal programs.

When spyware breaks Windows
Typically, when spyware removal breaks Windows, the symptoms look a lot like a DNS error. You might be able to ping a favorite Web site by IP address, but not by DNS name. When you attempt to access the site, Internet Explorer typically displays a message stating that the page cannot be displayed.

Advertisement

Talkback 3 comments

    Hi Brien, Loved your article b ...Anonymous -- 05/10/04

    Hi Brien,

    Loved your article but....

    Windows XP Pro SP2 does not have linkages via Control Panel/Performance And Maintenance to carry out the processes to remove Gator as outlined in your article.

    Would love an update for SP2!

    Graham

    Hhmm, it said "Click here ...Anonymous -- 05/10/04

    Hhmm, it said "Click here for the full story"!

    I have no doubt that you are aware, but neglected to mention, that one single anti-spyware app is not sufficient, due to the incredibly large variety of malware there is.

    No single app gets them all, not even close, you therefore must scan regularly with several if you wish to remain malware free.

    There are many available, some free, some that cost. I use the Adaware you mention & it is a good program, however they cannot be relied upon as they have twice in the past ceased providing updates without advice to users, even those performing unknowingly futile update checks on a regular basis.

    I also use the following -

    Widely acclaimed as the best one, which I'm sure you're aware of, is the free Spybot Search & Destroy - http://www.safer-networking.org/en/
    an excellent program & I urge users to make a small donation to this good cause.

    Pest Patrol charges but has also been good to me, their online database of pest info is very comprehensive, but already with the new owners there has been a change that I'm less than impressed with, reserving further judgement at this stage.

    Spyware Blaster is also free & will stop many pests from downloading in the first place, without even the need to be running in the background, very cool trick - http://www.javacoolsoftware.com/

    Firefox Browser has come a long way in recent years, is widely compatible & will also stop many pests from loading in the first place, it also does not have the amount of vulnerabilities of IE - http://www.mozilla.org/products/firefox/

    Thunderbird Email client, very good but still in late beta stage, not prone to the same amount of vulnerabilities as Outlook & Outlook express - http://www.mozilla.org/products/thunderbird/

    Better quality Anti-virus & Firewall also play a big part in my defences -

    Nod 32 Anti-virus will also stop a number of pests from downloading - http://www.nod32.com.au/

    Like all better Firewalls, Outpost takes a bit of configuring for you particular system, a pain compared install & forget. The pay off is much better protection though, & Outpost includes a "Program Component Control" that will detect any other app trying to hook into your browsers or email client...or any program for that matter. This works exceptionally well , you just need remember to turn Component Monitoring off when you are installing/upgrading software. - http://www.agnitum.com/products/outpost/

    You can download trial versions of the above 2 apps from this aussie url - http://www.antivirus.com.au/

    Time to take back the web from the scammers, it can be done.

    I don't know how to say thank ...Anonymous -- 07/10/04

    I don't know how to say thank you to whoever wrote the WinSocFix program. I had tried everything, including the manual deletion, but could not fix the problem I had of not being able to "see" a particular website.
    I downloaded the program, ran it once & got my website back. Very simple, very effective.
    Spyway tools are great except when they cause problems like this.
    Thank you

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • Array Cyberwar: What is it good for?
    In this week's episode, Cyberwar. What is Australia's place in the world of digital warfare? What are the implications for the NBN?
  • Array Is wholesale-only backhaul just a pipedream?
    The potential acquisition of Pipe Networks by SP Telemedia has raised the question about whether vertically integrated backhaul providers will mean higher wholesale prices for ISP customers.
  • More blogs »

Tags

Back to top

Featured