Home > Ask the Security Experts > Application Security Questions & Answers > Can one antivirus program be used to get rid of spyware?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Can one antivirus program be used to get rid of spyware?

Michael Cobb, featured expert EXPERT RESPONSE FROM: Michael Cobb, featured expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Enterprise IT tips and expert advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


>
QUESTION POSED ON: 03 January 2009
I've heard experts recommend using two or three programs to locate and get rid of spyware. Is this necessary? Can any one package be trusted to allow program-level monitoring of outbound traffic while also watching for known spyware activity?

>
Although the term spyware first appeared in 1995, it wasn't until the early 2000s that it started to become a security issue affecting everyone. Antivirus programs became reasonably sophisticated by this time and their use fairly widespread. However, the dramatic surge in the number of spyware programs being written, and its growing malevolent goals, caught security vendors off guard. Spyware writers made full use of social engineering techniques to get their programs installed -- free software, amazing offers, and enticing emails to name just a few. Almost overnight, computer users, both business and home, were reporting slow machines, odd behavior and a drop in Internet connections speeds, all results of spyware hogging the computer's resources and bandwidth.

The big antivirus vendors were slow to react, partly because this was a different problem to tackle. Looking for a virus signature is one challenge; deciding whether an FTP program is genuine freeware or actually spyware simply masquerading as freeware is a completely different one. The gap in the market for a product to ease the growing headache for homes and businesses led to various companies launching antispyware programs. Some were good, some OK, and some were even spyware camouflaged as antispyware!

In these early days of the battle to get rid of spyware, the antispyware vendors struggled to keep up with the number of new spyware programs and the growing number of guises used to cloak a program's true intentions. When people started to review and compare the different antispyware offerings, they found that none could really find and successfully remove every infection. This is why many experts started to recommend people run two or three different antispyware programs in order to increase the chances that every malicious program would get detected.

Over the last few years, running antispyware software has become a widely recognized element of computer security best practices, and as a result, the bigger players in security have all developed their own antispyware programs, most of which come as part of their desktop security suite. As computer users have become more aware of the dangers of spyware, and vendors have developed a better understanding of how to tackle the problem, it is now probably safe to run just one antispyware program. (I used to run three antispyware programs myself only a few years ago.)

One disadvantage of choosing a security suite with an antispyware component is that the suite's firewall and antivirus protection may be quite good, but its antispyware may not be. The obvious alternative to a multifunction desktop security suite is to deploy various point products, each of which mitigates a particular type of risk. Deploying and managing separate applications, however, is complex and can prove inadequate if each is operated in isolation. Many enterprise network administrators feel they have too many applications to manage already. They all require staff to understand and maintain them, as well as time to analyze the data they produce. An integrated suite has a big advantage here when trying to get rid of spyware: information can be pooled to create more informative reports, while centralized administration allows policy rules and parameters to be set in one go, a far easier task than trying to enforce each policy across several different devices.


BROWSE BY TAG
Application Security,   Malware, Viruses, Trojans and Spyware,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Application Security
Do Facebook URL security concerns justify blocking social networks?
Is there a way to block iPhone widgets that bypass Web filters?
Should enterprises be concerned with Twitter in the workplace?
Are there still Google Desktop security problems?
Can an IP spoofing tool be used to spam SPF servers?
Will an application usage policy best control network bandwidth?
How can URL-shortening services be manipulated?
Is my security program ready for Web application firewall deployment?
How to ensure the security of a shopping cart application
When to use the service features of the Metasploit hacking tool

Malware, Viruses, Trojans and Spyware
Schneier-Ranum Face-Off: Is antivirus dead?
Modern malware, stealthy botnets, adapt quickly, expert says
Computer worm infections up, scareware antivirus down, Microsoft says
Web-based attacks skyrocket, pirating sites surge, security firms say
Mini guide: How to remove and prevent Trojans, malware and spyware
Kaspersky system analyzes malicious URLs on Twitter for malware
Silon malware intercepts Internet Explorer sessions, steals credentials
Breach forces payroll service provider PayChoice to shut down again
RSA research underscores problem tracking cybercriminals
Conficker analysis finds P2P coding limited, less sophisticated

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
bot worm  (SearchSecurity.com)
directory traversal  (SearchSecurity.com)
government Trojan  (SearchSecurity.com)
Kraken  (SearchSecurity.com)
man in the browser  (SearchSecurity.com)
polymorphic malware  (SearchSecurity.com)
RAT (remote access Trojan)  (SearchSecurity.com)
RavMonE virus  (SearchSecurity.com)
RFID virus  (SearchSecurity.com)
Rock Phish  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Find Security Solutions for Your Business
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts