Slashdot Mirror


Spyware on One in Twenty Computers?

SpaceDonkey writes "New Scientist reports that researchers at the University of Washington carried out a scan of the campus network for signs of spyware. They found spyware lurking on more than one in 20 machines and also discovered a serious vulnerability in two of the four spyware programs they looked for."

36 of 400 comments (clear)

  1. Spyware flaw by guacamolefoo · · Score: 5, Funny

    The flaw that they detected was undoubtedly that the spyware could be detected. Duh.

    1. Re:Spyware flaw by gid13 · · Score: 5, Insightful

      Funny, but makes you wonder how much was there that they didn't detect. And as much as I love Spybot S&D and to a lesser extent Ad-Aware, I wonder how much they miss.

    2. Re:Spyware flaw by OECD · · Score: 5, Funny

      It's not exactly a representative group, is it?

      New Scientist reports that researchers at the University of Washington carried out a scan of the campus network...

      The same researchers noted that 90% of all computers have an inordinate number of "Phish" MP3s.

      --
      One man's -1 Flamebait is another man's +5 Funny.
    3. Re:Spyware flaw by Chess_the_cat · · Score: 4, Insightful

      That's why I believe this 1-20 number. This is a relatively closed system monitored by an administrator and most likely governed by a usage policy. Perform the same study on machines found in copy shops or in homes and I'm sure the results would be quite different.

      --
      Support the First Amendment. Read at -1
    4. Re:Spyware flaw by Erratio · · Score: 4, Insightful

      I'd think the number would probably remain about the same (at least relatively). Pretty much every computer I look at now has been slowed down by Spyware/Adware, so it seemed low to me initially, but these are also all computers for people who are using Kazaa and other programs they download on the Internet. Virtually all of those people will be infected (except for the few who know better), but also considering business users and people who use the Internet little or not at all (or don't download programs) the number is lowered. Not to mention people that don't run Windows. The number's probably higher in college environments but relatively similar all things considered.

      --
      I don't try to be right, I just try to make people think
    5. Re:Spyware flaw by rixstep · · Score: 5, Interesting

      Something too many seem to find too easy to forget: there's a big world out there outside that Microsoft window...

      A. Most Unix systems won't get infected and cannot be infected. Not only is it more difficult, the spyware perps write this stuff specifically for Windows.

      B. There would seem to be an assumption here that 'all computers (in the world) run Microsoft Windows'.

      C. Ad-aware does as well as an automated tool can do (hopefully), but it cannot kill the latest spyware variant, the automatic cloning program. These programs are scheduled to make multiple copies of themselves with different names and be deposited in different directories and then look out for each other. Should any one of them disappear, the others will quickly clone and replace the missing file and launch it again. Further, they incessantly monitor Windows Registry activity, and as soon as their 'autostart' (in one of the 'Run' keys) is removed, they will immediately replace it. As Ad-aware cannot deal with spyware that fights back like this, Ad-aware cannot defeat them.

      D. A better estimate is not that one in ten Microsoft Windows computers is infected, but that a greater number are infected perhaps tens of times with thirty - forty spyware programs all competing for CPU. We recently had a customer completely oblivious to the issue until his XP idled at 100% CPU - that's how bad it becomes, through Windows being so easily exploitable, and through the average Windows Joe being so clueless.

    6. Re:Spyware flaw by glk572 · · Score: 4, Insightful

      Way more than one in twenty. I would conceder my parents to be typical home users. I visit them every couple months, and when I do I give their computers a check up, part of this is running ad aware, and every time I do I find something. Last time I checked my mom's pc I found over 200 items, from almost a dozen pieces of spyware. She had so much crap that she had actually stopped using her computer because of all the pop ups. I'm usually pretty cautious, but will occasionally find spyware on my system, even though I have an antivirus that supposedly block's it.

      If I were to guess at a number I would say that at any given moment that more than half of home computers running windows have some kind of spyware/adware running. This comes from helping out many friends with spyware related problems.

      UW found so few instances because I'm sure that they limit users? ability to install software on their lab computers. As for dorm computers, many types of spyware can't be detected by a port scan, the only way to pick them up would be through a carnivore type system, even then not all of them would be found.

      The only way to stop spyware is to start prosecuting the companies who make it; it should be pretty easy under one of the laws for protecting children on the internet. After all if opening popup windows advertising porn with every page load isn?t illegal under these laws what is?

      --
      Well art is art isn't it, but then again water is water; and east is east; and west is west; and if you take cranberries
  2. Type by GabeK · · Score: 5, Funny

    Isn't that supposed to be 1 in 20 WITHOUT spyware?

    --

    [sig] 10 + 10 = 100 [/sig]
    1. Re:Type by spikev · · Score: 5, Funny

      Yeah, because it's about 1 in 20 that don't run windows.

    2. Re:Type by gid13 · · Score: 4, Informative

      Upon reading the article, it says that they only tested for 4 specific programs: Gator, Cydoor, SaveNow, and eZula. And got 5.1% positives. So yeah, you're probably right.

    3. Re:Type by _Sharp'r_ · · Score: 4, Interesting

      I routinely see over 10% of windows users show up with spyware on my anti-spyware page, and that's just what can be detected with a simple javascript utility over the web, so the actual total must be even higher than that.

      --
      The party of stupid and the party of evil get together and do something both stupid and evil, then call it bipartisan.
    4. Re:Type by miu · · Score: 4, Interesting
      For technical reasons, the automatic-detection feature on this web page can only work with IE/Win, with "Active scripting" and "Run ActiveX controls" enabled.

      10% seems very low, since your script can only diagnose users who allow ActiveX and scripting from the public internet I'd expect 50%+ of such users to be infected.

      --

      [Set Cain on fire and steal his lute.]
    5. Re:Type by Anonymous Coward · · Score: 4, Insightful

      The truly scary thing is they don't care. The also have about 40 programs running on their systray, so it takes 15 minutes for their insanely fast computer to boot up, and its swapping out to disk constantly despite the fact they have 512 meg of ram!

      I've noticed certain people will complain and tinker with their computer all the time, no matter how well it is currently running. Most others will just *ACCEPT* popups, spam, spyware, crashing, viruses, and so forth. I have called people to let them know they have a worm (but i call it a virus for them, so they dont get confused), their computer is constantly spamming everybody with virus laden email, blah blah blah. Sometimes they say "So?" These people should not own computers. Hell, they should not be allowed to reproduce

  3. Ad-Aware by amembleton · · Score: 5, Informative

    Download yourself a free copy of Ad-Aware from here. I ran it on my computer the other day and it found 22 infected files, that it cleaned up for me :)

    1. Re:Ad-Aware by amembleton · · Score: 5, Funny

      Not sure if this is the norm, but a fresh XP SP1 install followed by installing Spybot S&D from CD normally yields at least 10 problems. This is before the computer has been online.

      What do they count as spyware?


      Windows XP

  4. That seems like a low percentage by Lotek · · Score: 5, Informative

    I'm a tech for a medium sized publishing company, and I find that the first thing I do when I get complaints of slowness and random unexplained crashes is to run spybot. In roughly half of the systems I check, I can find some kind of spyware.

    1. Re:That seems like a low percentage by wfberg · · Score: 5, Interesting

      Here's a quick test. Ask the user if they've ever heard of SpyBot or AdAware. If the answer is unsatisfactory, they've got spyware. That includes your mom.

      5% is WAY low. Even I got infected (an app on tucows was listed as freeware, but turned out to be ad/spyware), even if you don't coun't cookies and GUIDs..

      Did I mention that AOL Instant Messenger now comes with spyware? That re-installs itself? And adds "free.aol.com" to IE's "trusted zone" so new stuff installs *without a prompt or warning*.

      --
      SCO employee? Check out the bounty
  5. Only one in twenty? by DarkFencer · · Score: 4, Insightful

    Going by my former help desk experience at a college, and by experience with friends and families computers I'd expect three in twenty would be more accurate.

    Though I tell people when I fix their computers from spyware, that I will do it once, put Spybot on their computers, along with Mozilla Phoe^H^H Fireb^H^H Firefox on their computers.

    If they get more spyware from using IE over Firefox, then I'll charge them to take it out next time.

  6. And this just in by ferralis · · Score: 5, Funny

    In a totally unrelated story, it appears that at least 4 out of every 50 computer users surveyed have had an encounter with "spam" emails in the last two years.

    Stay tuned for the next ground-breaking story about the near 100% mortality rate suffered by humans and animals exposed to di-hydrogen monoxide!

    --
    Any generalization is a stupid one.
  7. Spyware? You mean data collection? by Anonymous Coward · · Score: 5, Funny

    Cookies are spyware.

    Dont accept cookies. Ever.

    That is all.

  8. Were the other 19 turned off? by Rahga · · Score: 4, Interesting

    I'm sorry, but that number is way too low.... I'm in a bit of a hospital/nursing town, and I'd say that at least half of the nurses-in-training I know have experimented with Kazaa and other music piracy services, and are usually loaded down with 5 to 10 bad (at least gator-level) spyware installs.
    The only thing that has infected that "community" around here worse would be smoking habits.

  9. 1 : 1 by JediDan · · Score: 4, Insightful

    If you run windows there are registry keys used to track your usage of windows media player (unless you remove them) thus, the ratio is a lot closer to 1 : 1 of every windows computer out there, more so with more recent windows OSes.
    It's not the only program either, use a firewall and don't install software that you don't need.

    --
    - Dan
  10. Suggestions by Anonymous Coward · · Score: 4, Informative
    Windows can be secure. Some suggestions:
    • Use Firefox. No need to worry about ActiveX spybars.

    • Get AVG Anti-virus. Keeps out the trojans and viruses.

    • Use Ad-aware. Say goodbye to malware.

    • Above all else, use a personal firewall. You won't have to worry about programs calling home without your permission.
  11. I manage a 50-user corporate network. by daviddennis · · Score: 4, Informative

    Spyware makes it on to 100% of the computers in my network. I have taught my users to put in, use and update ad-aware, but I think even with that there is spyware it's not recognizing. I come to this conclusion thanks to erratic behaviour in many of my machines that is not due to viruses.

    Some of my users like spyware. Hotbar is a good example of a program that's actually liked by a number of people. But the programs that seem to do the most harm are the ones that try to stay invisible.

    There are two computers on my network that never have spyware problems. One of them is the Mac I do all my web surfing on, and the other is the PC I do no web surfing on at all.

    Any company I found is going to be Mac-only. There's little point in tolerating the huge overhead associated with running a Windows network.

    D

    1. Re:I manage a 50-user corporate network. by daviddennis · · Score: 4, Informative

      Two points:

      * Spyware is created for purely commercial reasons. It is not commercially viable to create this kind of software for a platform with a 5% market share. I don't expect spyware to become a problem under MacOS X unless something happens that pushes its market share radically higher.

      if 99.99% of virii and spyware are writen for Windows, the Mac and Linux are far, far safer. That's not "security through obscurity"; it's pure, hard-headed commercial reality.

      * Most of the tricks used for "drive-by installs" of Spyware work because Internet Explorer is integrated with the operating system. In other words, you use Internet Explorer + an ActiveX DLL to install updates to Windows. Therefore, you can use the same combination to do Bad Things.

      On the Mac, there is no such integration, so the only way to install software is to, well, install it. Period.

      You pointed me to a spyware removal tool for the Mac, but I have yet to hear of any Mac spyware. Until proven otherwise, I consider that program bogus.

      D

  12. I'm not surprised. by Bistronaut · · Score: 4, Informative
    I would say that the 20% number is way lower than what you'd find on cross-section of average home users' computers. I'll bet that they only came up with 20% because:
    • University students and staff are probably more computer-savvy than the general population.
    • They were only searching for four of the who-knows-how-many spyware programs out there.
    If you're running Windows, you should have Spybot Search and Destroy and Ad-Aware. Not to mention a virus scanner and firewall. And run Windows Update for goodness' sake! Just more proof that Windows isn't ready for the average user yet. (Sorry, had to get a cheap jibe in there. :-)
  13. Spyware is in everything now by mrshowtime · · Score: 4, Interesting

    I cannot believe how many new programs are coming with spyware now. Worst yet, the spywares are not just cookie trackers, but keyloggers and much worse. Even some games install a scanner to scan your hd for any "virtual drives" and will not load the game if any are detected.

    --
    "Jeremy, you need to get to an internet cafe and cut and paste some appropriate sentiments about me from the world wide
  14. Re:Excuse me for speaking the obvious by Syrrh · · Score: 4, Insightful

    Damn, people need to get tough on this shit.

    That's really it.

    Why the hell are antivirus companies so reluctant to add anti-spyware functions? I mean, boo-hoo that Gator got so upset when they were accused of making spyware, but calling it anything less than a trojan is a lie.

    Firewall products have been offering popup stoppers and activity reporting for a while now. It's really time for the AV publishers to step up and do their part by keeping these things from getting a foothold. It's not like they can get in any legal trouble for blocking someone's program, since it's up to the user whether they trust McAfee or HotBar more.

  15. Re:That's likely and understatement by FreeLinux · · Score: 4, Interesting

    That may be a little on the high side but, 1 in 20 is way too low. Spyware is as out of control as spam is but, most people aren't aware of it, as they are with spam, so it doesn't get as much mention.

    I have always thought of spyware as a virus. Perhaps not as destructive but, a virus none the less. Thus, I have always felt that the commercial anti-virus companies should make their software to detect and remove spyware just as they do viruses. As yet they do not but, there is a major need for it.

    Now, many people will start rattling off the plethora of spyware detectors and adware look alikes but, the fact is that none of these programs is capable of detecting all of the various spyware in the wild. Additionally, since they are all small companies or free projects they aren't and will not be able to keep up with the flood of new spyware as it comes out. Only the major players like the present anti-virus companies will be able to do it effectively with frequent updates to catch the latest bugs.

    Of course, the immediate solution is to not use Windows but, that is not going to happen and even if it did, there would be spyware for Mac and Linux after a while. It's getting to the point that the little voice in my head keeps screaming at me to block off all port 80 traffic.

  16. Study Flaw by DynaSoar · · Score: 4, Insightful

    At least in terms of the conclusion drawn: "One in twenty computers with an internet connection may be harbouring unwanted "spyware" programs..."

    Their sample was computers at a college. You've got a highly wired place with people using them for all sorts of things, and comparatively little training on what and what not to do. Plus you've got younger users, many of which aren't old enough yet to not know everything, and feel free to ignore the warnings and admonishments (mark it flamebait if you like; I've taught such people and run a computerized lab. I know what they do and how they think, and so did I back then). Plus, you've got installs and re-installs (the common fix for everything Windozish) often being done by student workers with as comprehensive training in system security as they have in nuclear reactor operations.

    How about a major ISP asking customers to allow them to scan for them? How about running a similar study on a large corporate system where downloading and installing external software is far more likely to be noticed, and results in far more than "Geez, we told you not to".

    Biased sample, bad result. It may be right, but without better data, it's still bad.

    --
    "I may be synthetic, but I'm not stupid." -- Bishop 341-B
    1. Re:Study Flaw by lrucker · · Score: 4, Insightful
      You've got a highly wired place with people using them for all sorts of things, and comparatively little training on what and what not to do.

      That also describes most sales & marketing departments, even at high-tech companies.

    2. Re:Study Flaw by El+Volio · · Score: 4, Insightful

      You've got a highly wired place with people using them for all sorts of things, and comparatively little training on what and what not to do. Plus you've got younger users, many of which aren't old enough yet to not know everything, and feel free to ignore the warnings and admonishments...

      That sounds like a pretty common representation of the average user to me. Although many users outside of education may not be "younger", many of the characteristics hold. In fact, I would say such a user might even be more common than locked-down corporate environments. And if a major ISP ever were able to do such a scan on their customer's hosts, it wouldn't be much different.

      Is that a "biased" sample? Depends on what population you're comparing against. If you're extrapolating to corporate environments, then systematic differences from the true mean may very well exist. But if you're comparing against the population of all Internet users a potentially far more interesting and useful population to study, though more difficult as well then the bias is more difficult to measure.

      --

      "You can never have too many elephants on your team."

  17. Re:the obvious question here is by daviddennis · · Score: 4, Insightful

    Because for better or for worse, I'm not a corporate drone. I believe users are people, not abstractions, and so I believe in giving them as much freedom as I can.

    And I really, really don't like being called every time the clock drifts on one of the PCs and someone wants me to fix it.

    I have better things to do than fixing it or installing software. So I delegate the power, and as much of the responsibility as people can bear, down to the users.

    And users love me, because they know I have respect and sympathy for them.

    I'm never going to be a Nazi-class administrator, even though I know it would solve a lot of my problems -- by, no doubt, creating newer and more frustrating ones.

    D

  18. The actual article by El+Volio · · Score: 4, Informative

    New Scientist is just carrying their little summary; one of the authors has the paper available on his site in HTML, PDF, and PostScript forms. It's to be presented at NSDI '04.

    --

    "You can never have too many elephants on your team."

  19. Way low. Way, way low... by ktakki · · Score: 4, Funny

    One in twenty? More like one in five or worse. Of course, UW only looked for four pieces of spyware. IIRC, the latest Spybot definition file has over 12,000 entries (not all of which are covered by the strict definition of "spyware", but still...).

    My current job is doing graphics and web work for a small computer services company, but at least once per week I go out on service and maintenance calls for our clients. At one place, the spyware infection rate was closer to 80%: Gator/Claria, Bonzi Buddy, Vomit Cursor, HiWire, IGetNet, BestWeb, Bargain Buddy, etc. One machine had 477 separate pieces of spyware and browser hijackers. Another had 25 instances of the same pr0n dialer. Even the ones that were relatively "clean" still had crapware like Webshots or WeatherBug that brought these commodity PCs to their knees. And don't get me started on Kazaa...

    When I started doing this, I'd cut the users a lot of slack, letting them keep their Webshots or Benadryl Desktop Allergy Alerts. But after a month, the BOFH-nature possessed me. I have become an IT fascist: NO WEATHERBUG FOR YOU! NEXT!!!

    Gah. Now I'm pissed. I think I'll go in tomorrow and schedule scandisks and defrags for 9AM Monday morning. That'll learn 'em.

    k.

    --
    "In spite of everything, I still believe that people are really good at heart." - Anne Frank
  20. Effective combination... by Fez · · Score: 5, Informative
    I work at a computer repair shop, and nearly every single computer I work on has some degree of spyware. The best combination of tactics to kill spyware that I've found is as follows (All in Safe Mode, of course):

    There's not a lot to be missed after that. Process Explorer is also good for finding processes running that might not be of obvious origin.