internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Internet Explorer 8

Most Popular Software Downloads
Mozilla Firefox 3.0
Ad-Aware 2008 Free
Internet Explorer 7
QuickTime for Windows
Paint Shop Pro
Mozilla Firefox Portable Edition 3
AVG Anti-Virus Free
Windows XP Service Pack 3
Ashampoo WinOptimizer
Adobe Flash Player
Windows Live Suite

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

New Means to Root Out Malware
Spy Sweeper Enterprise 3.0 Debuts with New Smart Shields
Andy Patrizio

Malware (define) continues to be a problem for customers, with many users unaware their systems are infected with some kind of hidden "bot" that steals their personal info or hijack's their computer.

"A lot of people have no protection, and even people who have protection, it isn't complete," said Peter Firstbrook, research director for information security and privacy at Gartner. "The software doesn't address known threats, and at best they catch 80 percent of spyware."

One reason many antivirus and antispyware tools fail is because they don't perform kernel-level (define) detection. This makes the Windows a safe harbor for many viruses and rootkits (define) to hide. Only Kaspersky and Symantec's antivirus offerings look into the kernel, McAfee and Trend Micro, plus a lot of the smaller players, do not, said Firstbrook.

But now add Webroot to the list of anti-spyware (define) products to offer kernel-level protection and more in Spy Sweeper Enterprise 3.0, released today.

This is done though direct disk scanning technology to bypass the Windows API’s that control disk access. A common trick of rootkits is to obfuscate the files from the Windows API, so Spy Sweeper simply skips the Windows API.

New in Spy Sweeper Enterprise 3.0 are real-time Smart Shields, a set of intelligent spyware detectors. These include an ActiveX Shield that protects ActiveX components, a Spy Communication Shield that blocks communications to known spyware threat sites, a BHO Shield to block the installation of Browser Helper Objects (BHOs) unless specifically approved by the administrator and IE Trusted Sites Shield to prevent spyware from modifying Internet Explorer security-zone settings.

Also new is the ability to scan compressed files, improved scalability performance and configurable SNMP alerts for detected spyware at the conclusion of sweeps. Administrators can now also throttle CPU usage for both the memory and file scans to minimize impact on the CPU during sweeps.

"Webroot's done a really good job. I think they're the best product from a spyware perspective," said Firstbrook. But Webroot has the problem of being a small player in a market with a few dominant players and many contenders, he said.

Firstbrook estimates McAfee, Symantec and Trend Micro have 75 percent of the security market, which leaves Webroot, Sophos, Kaspersky, Eset and many other firms to fight for the remaining 25 percent.

"People don't want another scanner. You want one engine, one distribution mechanism, one update engine, one management console," said Firstbrook. "Incumbent vendors have such a leg up and no one wants to move vendors, so little guys have a hard time making inroads in the enterprise. In the enterprise space, [IT] will just turn to their current vendor and say 'Why don't you do this?'"

At least enterprise customers are taking precautions. Gartner estimates that at the most, around 10 percent of corporate computers are out-of-date when it comes to patching security holes and keeping their malware scanners current.

But that's a lot better than the general population, where the firm estimates as much as 70 percent of the computing population does not use some form of virus/spyware/malware protection. Judging by a report from Microsoft this week, those risk-takers are getting off easy.

Since releasing the Windows Malicious Software Removal Tool (MSRT) in January 2005, it has been used on at least 270 million unique computers and removed 16 million instances of malicious software from 5.7 million unique computers over the past 15 months, according to a report issued Monday by the software giant.

That's just two percent of the population, but that two percent does a lot of damage. Of those 5.7 million infected computers, 62 percent were running backdoor Trojans, mostly "bots," applications that relay spam or fire off cyber attacks. Mostly, though, it's spam.

More than 70 percent of the spam that clogs our inboxes comes from these kinds of bots that most people don't even know are running on their computer in the first place, said Firstbrook.

He also said there's no excuse for it, that nothing should be firing off email except the email client. "Why would I want my PC to send SMTP (define) mail from anything other than Outlook?" he said "A simple rule would be don't send SMTP mail unless it comes from Outlook."

But Windows machines aren't locked down in this manner. Firstbrook blames software vendors (including Microsoft) that want machines to be as open as possible for automatic software updates via the Internet.

"Application developers have this sense they can do whatever they want to our PCs as long as it's good," he said. "The problem is all the tools they use to keep their programs up-to-date are the same tools malware writers are using to download malicious software onto our PCs." Another loophole in spyware catchers is that legal keystroke loggers aren't detected, only illicit ones, he said.

The issue of using some kind of virus and malware protection isn't new, nor is the attention to the lack of protection. The bottom line, said Firstbrook, is he's not surprised at the stats from Microsoft, and thinks the User Account Control (UAC) feature in Windows Vista is necessary.

"It's gotta happen. Seventy to 80 percent of malware won't run properly on a Windows machine if you're not running with Administrator rights. UAC disconnects a lot of user rights from manager rights," he said. As for user complaints the UAC is too cumbersome, he responded that Macintosh and Unix have similar features "and you don't hear them complaining."

News courtesy of internetnews.com

June 14, 2006

Download Spy Sweeper Now!Download

View All Anti-Malware Software

View All Anti-Virus Software

Contents:
1. Spy Sweeper Enterprise 3.0 Debuts with New Smart Shields


Additional Articles:

  • Webroot Adds Antivirus Detection
  • Webroot Updates, Renames Antispyware for Business




  • JupiterOnlineMedia

    internet.comearthweb.comDevx.commediabistro.comGraphics.com

    Search:

    Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

    Jupitermedia Corporate Info


    Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

    Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

    Solutions
    Whitepapers and eBooks
    IBM eBook: Planning a Service Oriented Architecture
    IBM eBook: Choosing the Right Architecture--What It Means for You and Your Business
    Microsoft Article: Will Hyper-V Make VMware This Decade's Netscape?
    Avaya Article: Using Intelligent Presence to Create Smarter Business Applications
    Intel Go Parallel Article: Getting Started with TBB on Windows
    Microsoft Article: 7.0, Microsoft's Lucky Version?
    Avaya Article: How to Feed Data into the Avaya Event Processor
    IBM Article: Developing a Software Policy for Your Organization
    Microsoft Article: Managing Virtual Machines with Microsoft System Center
    Intel Go Parallel Article: Intel Threading Tools and OpenMP
    HP eBook: Storage Networking , Part 1
    Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
    MORE WHITEPAPERS, EBOOKS, AND ARTICLES
    Webcasts
    HP Video: StorageWorks EVA4400 and Oracle
    HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
    Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
    MORE WEBCASTS, PODCASTS, AND VIDEOS
    Downloads and eKits
    Red Gate Download: SQL Toolbelt and free High-Performance SQL Code eBook
    Iron Speed Designer Application Generator
    MORE DOWNLOADS, EKITS, AND FREE TRIALS
    Tutorials and Demos
    Silverlight 2 App and Walkthrough: Leverage Silverlight 2 with SQL Server and XML
    IBM Article: Enterprise Search--Do You Know What's Out There?
    HP Demo: StorageWorks EVA4400
    Microsoft Article: The Progress and Promise of Deep Zoom
    Microsoft How-to Article: Get Going with Silverlight and Windows Live
    MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES