Spyware prevention: From user to admin

Spyware prevention: From user to admin

This tip originally appeared on SearchWindowsSecurity.com, a sister site of SearchCIO-Midmarket.com.

This tip is about understanding and applying best practices when it comes to dealing with spyware and adware, be it on a single desktop, a handful of machines on a home or small office network or at the enterprise level. It's best expressed as a series of admonitions on ways to make sure your computers (and users) are wise to the ways of spyware and know how to protect themselves against it.

Spyware prevention is a process that has many layers. Some roles are performed by users and some by the administrator. These bits of advice begin with the basics and move on to more advanced practices.

"Protect Your PC."
This is actually the title of an informative and useful Web page on the Microsoft website. When it first appeared, it advised everybody who visited to keep Windows up to date and use a personal firewall and current antivirus software.

These days it, exhorts visitors to "Use Microsoft Windows Security Center" (which covers all of the aforementioned bases), and to "Get antispyware software," which includes the excellent Microsoft AntiSpyware beta software package (still available for free; Microsoft links to Lavasoft Ad-Aware SE and to Spybot Search & Destroy in its antispyware

    Requires Free Membership to View

    Download Enterprise CIO Decisions for free after registering.

    After registering we will email you the latest issue as well as access to our archive of back issues. Get essential editorial insights that senior IT executives need to run IT operations effectively and efficiently.

    Get Enterprise CIO Decisions Now!

    By submitting your registration information to SearchCIO-MidMarket.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchCIO-MidMarket.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

pages as well, much to my amazement).

Use a spyware scanner/screener.
You won't be protected against spyware and adware unless you install an appropriate antispyware package (see TopTenReviews Inc.'s Anti-Spyware ratings on that software genre for pointers).

The first such package you install on your machine generally also works just like antivirus software. It will not only run at regular intervals and scan your machine, but it will also check all incoming files, messages, Web pages and so forth to look for and block spyware, adware and other malware from taking up residence on your machine. For that reason, the screening function is very important for spyware prevention because it provides real-time protection against potential infestation by malicious software.

Run one or more backup scans weekly.
Recent studies show that, unlike antivirus packages (many of which routinely achieve 100% effectiveness ratings in the virus handling department, as demonstrated by the Virus Bulletin 100% award), no single antispyware package can correctly identify or block all known spyware (not to mention new, unknown spyware).

Thus, best practices dictate that you install at least two antispyware packages on all machines. Use one for real-time screening and regular scans; use the other once a week as a backup scanner to catch spyware and adware that the other may miss. And, of course, it's essential to keep both (or more) such packages up-to-date to make sure they're scanning for what's really out there. It's also best to automate this activity to prevent human fallibility from allowing spyware to go undiscovered.

Understand clean-up: process and tools.
What antivirus software can do for viruses, antispyware tools can detect and clean up after most known forms of spyware infestation. Nevertheless, it pays to get to know powerful, general-purpose clean-up tools such as Hijack This!. You can download it from MajorGeeks.com, where you'll also find a great spyware, adware and virus removal tutorial that explains the general tasks and processes involved. The "official" Hijack This! tutorial also references other great sources of information and instruction on how to use it for detection and to help guide cleanup.

MajorGeeks' Spyware Tools page page is also a compendium of the most useful such tools. It's worth spending time exploring as well.

Use a rootkit detector.
There's another kind of malware making the Internet rounds these days. It's a special, extremely stealthy form of software that's designed to install and run itself as undetectably as possible.

Rootkits are special-purpose software toolkits that target specific operating systems (or families of systems, like all 32-bit versions of Windows) designed to mask intrusion and make administrator-level access available to intruders. Rootkits usually install on one or more systems and operate silently and stealthily in the background collecting user account names and passwords to facilitate further intrusion and compromise.

Although these tools often work and run by themselves (and are no less dangerous in that mode), they are increasingly incorporated into spyware and viruses by clever hackers. They may even be combined with Trojans to enable what they learn to be reported to remote locations across a network or the Internet. They allow keyloggers to capture account info, passwords and other sensitive data.

The real problem with rootkits is that most antivirus or antispyware tools can't detect them. A special class of tool, called a rootkit detector, is required to ferret out such malware. What's worse is that no automated clean-up tools yet exist to get rid of rootkits, so the only cure for an infestation is to wipe the drives clean and reinstall your system (and then restore your data files and software from a known clean backup).

To learn more on this topic and get pointers to detectors, visit rootkit.com, or read the book by that site's principals, Greg Hoglund and Jamie Butler: Rootkits: Subverting the Windows Kernel (Addison-Wesley, 2005, ISBN: 0321294319).

By following these simple steps -- and selecting the right software components to handle the various activities and protections described here -- individuals and organizations can achieve reasonable protection against malicious software. More on the details

Ed Tittel is the Series Editor for Exam Cram 2, and the author of The PC Magazine Guide to Fighting Spyware, Viruses, and Malware (Wiley, 2004, ISBN: 0764577697). He reports regularly on Windows certification, security, and development topics. Contact him at etittel@techtarget.com.


This was first published in November 2005

Join the conversationComment

Share
Comments

    Results

    Contribute to the conversation

    All fields are required. Comments will appear at the bottom of the article.

    Disclaimer: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.