Slashdot Mirror


Two Reviews of Microsoft AntiSpyware

jasondubya writes "PC Magazine released their review of Microsoft's Anti-Spyware Beta 1. While they agree with most that it has great potential, it has yet to take over their top spot. In an informal test, it removed about two-thirds of the spyware detected and blocked about fifty percent of the threats they attempted to install. After removal, they ran Webroot's Spy Sweeper 3.0. It was able to detect '900 traces of 48 distinct threats still present, including two keyloggers and three Trojans.' With that, it looks like Microsoft still has work to do before they are on top of the market." Several other readers sent in link to Mossberg's review in the WSJ.

52 of 203 comments (clear)

  1. I've used it by ikkibr · · Score: 3, Informative

    I've used it and ...
    I liked it! It scanned like 500 spywares in my computer, all of them due to Internet Explorer Bugs(hey, i've used it only for 2 days since I formated my computer). The software is fast, gives information about the spywares and asks you what you wanna do. If I had to rate it I would give 9/10.

    1. Re:I've used it by Anonymous Coward · · Score: 3, Funny

      2 days and 500 pieces of spyware already? One must wonder exactly what kind of sites you're browsing to get that kind of infestation.

  2. article quoted incorrectly by Triumph+The+Insult+C · · Score: 5, Funny

    need to make a correction there at the end ...

    With that, it looks like Microsoft still has a few more companies to buy before they are the market."

    --
    vodka, straight up, thank you!
  3. My experiences in brief... by ZiZ · · Score: 5, Informative

    MS AntiSpyware is /extremely/ fast - faster than anything else I've tried - but didn't catch any advertisement cookies in Mozilla Firefox and only caught a very small number of them from IE. It also complains loudly about a number of things I use on a regular basis - FTP server, VNC, even a copy of SoftICE (which, yes, I use legitimately to debug device drivers). Could be good with some work, though.

    --
    This flies in the face of science.
    1. Re:My experiences in brief... by papadiablo · · Score: 4, Insightful

      It also complains loudly about a number of things I use on a regular basis - FTP server, VNC, even a copy of SoftICE (which, yes, I use legitimately to debug device drivers).

      Yes, but you can tell it to ignore them every time, meaning it won't bug you about them.

      I agree it's extremely fast. It is also free and in beta mode so I wouldn't expect it to be as good as commercially released subscription based software. It would be nice if it continues to be free and I expect it to only get better over time.

    2. Re:My experiences in brief... by ad0gg · · Score: 2, Informative

      IE doesn't allow 3rd party cookies by default. So you don't have to worry about being tracked from site to site by banner ads. Though this don't apply for popup ads. To stop tracking cookies in firefox just disable 3rd party cookies.

      --

      Have you ever been to a turkish prison?

    3. Re:My experiences in brief... by Anonymous Coward · · Score: 2, Informative
      Cookie Detection and Removal.

      GIANT AntiSpyware detects and removes cookies from your computer. Because many Web sites require the use of cookies to enable a great user experience, Windows AntiSpyware (Beta) does not remove cookies.

      From: http://www.microsoft.com/athome/security/spyware/s oftware/currentcustomers.mspx

    4. Re:My experiences in brief... by Anonymous Coward · · Score: 2, Insightful

      It's not /supposed/ to bother you with ad cookies. These aren't really 'spyware'; listing every cookie is just a cheap way to inflate the number of things caught, making the anti-spyware software seem more valuable than it really is.

      OMFG, that SuperSpywareRemover found 781 peices of spyware on my computer! Wow, the net's so dangerous, I need to pay for SuperSpywareRemover and run it every day! OMFGoneoneone!

    5. Re:My experiences in brief... by RonnyJ · · Score: 4, Insightful
      It also complains loudly about a number of things I use on a regular basis - FTP server, VNC

      It *should* pick up on these two - if you're advanced enough to have a use for them on your system, you're quite capable of telling the program to always ignore them.

      If, on the other hand, a typical home user finds a FTP server or VNC on their system, who has no idea what it is, or why it's there, it's likely it's not been put on there for their use.

    6. Re:My experiences in brief... by JimDabell · · Score: 2, Informative

      IE doesn't allow 3rd party cookies by default. So you don't have to worry about being tracked from site to site by banner ads.

      Actually, Internet Explorer allows third-party cookies, just as long as there's a P3P policy to go along with it.

    7. Re:My experiences in brief... by Harker · · Score: 3, Informative

      I ran it with similar results. RealVNC was detected, but the default was to ignore it, so at least it realizes that this app could be legitimate.

      It also searches based on text strings, such as file and folder names. I have two bookmarks for crack sites in my IE bookmarks. The scanner reported the folder name, as well as one of the two sites listed as high warnings, recommending removal.

      It is very fast, and I noticed no slowdown of my machine when it ran the other night, regardless of being online playing world of warcraft at the time.

      I do have to question the applications trying to reach the internet while doing nothing else thoguh. My Sygate firewall reported it trying to access the internet several times. There is no option for scheduling updates or even to stop it from doing so, or to schedule it for a set time.

      All in all, it's become a good addition to my spyware arsinal. I will even reccomend it to clients, if they wish some sort of real-time protection.

      I have not yet tried installing any spyware infested applications to see how it handles them. I'm keeping my fingers crossed that it will detect and prevent (or at least offer to prevent) such installations.

      Eric the Grey

      --
      When VCR's are outlawed, only outlaws will have VCR's.
    8. Re:My experiences in brief... by adiposity · · Score: 2, Informative

      Complains loudly? VNC is considered a "low" (2/5 I think) threat and the default action is to "ignore" it. I'd hardly call that complaining loudly.

      I have yet to have it suggest I remove something I actually wanted.

      -Dan

    9. Re:My experiences in brief... by gad_zuki! · · Score: 2, Insightful

      No, it shouldn't. First off VNC and FTP are not spyware. Period.

      Secondly, look outside your slashdot bubble and you'll see people who share computers. Not everyone has three or four boxes laying about. One person (or the admin) may put a VNC server on there and then another person may remove it because they trust the MS app and don't know any better.

      Stick to spyware. Seriously. On one machine I tested it, it couldnt remove a common spyware browser helper object. MS cant remove stuff from their own browser? Yep.

    10. Re:My experiences in brief... by JThundley · · Score: 2, Interesting

      Does anyone else think that they achieve their amazing speed from secret system calls?

    11. Re:My experiences in brief... by LO0G · · Score: 2, Insightful

      First off, it's only been a MS product for a month - hard to rewrite it in that time.

      Also, that article seems to indicate that the undocumented APIs are somehow "faster" than their documented equivilants, but it doesn't cite any evidence of that...

    12. Re:My experiences in brief... by ImpTech · · Score: 2, Insightful

      Gotta disagree. Case in point, I've got VNC installed on some of my relatives' PCs so I can help them when they have problems. Now, these are willfully computer-ignorant people who forget what they're supposed to click so I can access their computer (the "VNC server" icon I put on their desktop). Chances are if Microsoft's program found the VNC executable and brought up a warning, they'd follow whatever action it said without thinking. And next time they have a problem, we spend hours trying to figure out what happened to VNC.

      Oh, and I'll bet AntiSpyware doesn't even peep if you have XP's remote desktop "feature" enabled...

    13. Re:My experiences in brief... by _Sprocket_ · · Score: 2, Insightful

      IE can be used to spy on a computer too (cookies, installing software, etc). A fileshare could be used. And, assuming you have the right version of Windows, so could Remote Desktop. Are these being flagged too?

      I doubt it. Not because of a nefarious Microsoft plot - but simply because it's NOT spyware. Neither is FTP nor VNC.

      I understand the concept of why one would choose to flag VNC, an FTP daemon, etc. But when it comes down to it, that's a rather agressive and more than likely incorrect interpretation. This isn't a vulnerability scanner. It's an anti-spyware app.

      On a somewhat related note, I still don't understand why "spyware" isn't included within the normal run of malware definitions for common antivirus while "elf bowling" is.

    14. Re:My experiences in brief... by Mycroft_VIII · · Score: 2, Informative

      Actually many banner ads are in frames that load from 3rd party sights. You can still get the cookie. Unless some very recent update fixes this (I stopped using IE before SP2 so It's possible) it's still a valid issue.
      Also IE does allow third partie cookies for some other instances. If they have a privacy policy, not if the have a GOOD privacy policy, just if they have one, it could easily be "what privacy, you get no privacy here". That and no personal info is in the cookie. Assuming IE can (correctly) tell what that info is.
      So for joe user, IE doesn't really block third party cookies except on uncommon cases where he gets lucky, or the third party cookie sight is run by idiots. I'm shure sites like doubleclick and such have no problem getting thier cookies on most machines running IE.

      Mycroft

      --
      https://signup.leagueoflegends.com/?ref=4c3ed6600b6ea
  4. Typical.... by SpyHunter99 · · Score: 3, Insightful

    Anything good about this program is attributed to Giant and anything bad is attributed to Microsoft.

    1. Re:Typical.... by TedTschopp · · Score: 2, Insightful

      Now what is typical, Microsoft acting this way, or someone on Slashdot basing Microsoft?

      --
      Fantasy remains a human right; we make in our measure and in our derivative mode... -- JRR Tolkien
    2. Re:Typical.... by winkydink · · Score: 2, Insightful

      I don't know that they've had it long enough to contribute much good or bad, unless you have something against the way it's branded, I guess. At this point, it's pretty much a rebranded Giant product. It will be interesting to see how it evolves in beta.

      --

      "I'd rather be a lightning rod than a seismometer." -Ken Kesey

    3. Re:Typical.... by detlev409 · · Score: 2, Interesting

      You may have a valid point someday, but at this point, that's where the credit deserves to go. The truth is, the program known as Microsoft Antispyware is just Giant with a facelift. To see just how superficial the change is, install the program and then check your registry. The program still registers under Giant Software. As of right now, what's under the hood has very little to do with Microsoft.

      --
      Howdy.
  5. My experience by yfmaster · · Score: 5, Interesting

    I've tried it and it found some stuff that ad aware didn't even pick up. It also correctly identified tight vnc as a possible spyware app, but labeled it as low priority. I was more then happy with it.

  6. For the pirates... by StevenHenderson · · Score: 4, Informative
    Just an FYI to all the pirates out there:

    Even though it says you need to "validate" Windows, it prompts you after you click the download link, and then you can click "no." Good news for me^H^Hthe pirates out there with illegitimate XP copies.

    1. Re:For the pirates... by Zocalo · · Score: 4, Interesting

      This is also useful for getting updates and other stuff from Microsoft's website site using alternative browsers like Firefox, which obviously won't run the ActiveX control this validation requires. I make a point of avoiding using Windows Update (which requires IE) and manually getting any applicable Windows patches each second Tuesday using Firefox, and I'm pretty sure I'm not alone in this. Hopefully someone at Microsoft is paying attention to their webserver reports and realises that making sections of their websites require IE isn't going to be very popular. How many legitimate Windows users are they willing to annoy just to make it a smidgeon harder for people with unlicensed copies of their software and/or privacy concerns to get updates and so on?

      --
      UNIX? They're not even circumcised! Savages!
    2. Re:For the pirates... by the+angry+liberal · · Score: 2, Insightful

      Why do you care about using IE to connect to M$? I just let it connect and check for, download, but not install updates. Then, I flip through them to make sure they are applicable to my system before installing.

      Are you really that frightened they will PWN you? Please visit my ebay store. The special this week: Tin-foil hats, half price!

    3. Re:For the pirates... by imemyself · · Score: 2, Informative

      I've validated my copy of XP Pro VLK that is definately not legal. Serial was generated and it validated just fine(atleast when I tried a few months back).

      --
      Every time you post an article on Slashdot, I kill a server. Think of the servers!
  7. Three things by RM6f9 · · Score: 4, Interesting

    1. Does it work well? (not as well as many others)
    2. Does it uninstall cleanly? (HA!)
    3. How much does it cost for support (Better put, IS support even reasonably AVAILABLE for it?)

    No thanks, I'll stick with what I've got.

    --
    Take the 90-Day Challenge! http://rwmurker.bodybyvi.com/
  8. For a more unbiased approach..... by Anonymous Coward · · Score: 3, Informative

    While these articles are mostly true, they seemed still to be biased against microsoft. Although i value /. and go along with its beliefs against a certain company, there are more balanced views out there...

    http://www.flexbeta.net/main/articles.php?action =s how&id=84

    In the articles here, they only say that some stuff was not removed by antispyware. But they never said if microfsoft antispyware picked up stuff others missed. Article above does this test.

    -SystemERRor

  9. How is this "new software"? by jaymzter · · Score: 3, Interesting

    Let me get this straight, Microsoft buys another company, does a badge job on the product to slap their logos all over it, and suddenly it's something new and exciting? We might as well be reading the last review of Giant's software.
    I guess it's news because it's Microsoft, just like a divorce is news if your name is Brad and Jennifer or whatever...

    --
    If thou see a fair woman pay court to her, for thus thou wilt obtain love
  10. Why Microsoft's product will not dominate by fleener · · Score: 2, Insightful

    Their anti-spyware software doesn't work on older versions of Windows. Poor ol' me with WinME will continue to use measures that work on older versions of Windows.

    1. Re:Why Microsoft's product will not dominate by GeorgeMcBay · · Score: 3, Funny


      Their anti-spyware software doesn't work on older versions of Windows. Poor ol' me with WinME will continue to use measures that work on older versions of Windows.


      Don't worry about it, it is getting to be so difficult to target older versions of Windows with the new APIs and development tools that even the adware guys will probably just throw up a dialog asking you to upgrade to XP before they can install their spyware. So you'll be sittin' pretty with your WinME install!

  11. The WSJ article is very biased. by sllim · · Score: 4, Insightful

    Problems with these reviews:

    1. It really isn't fair to issue a review of a product in its beta form. Yes it can be argued that Microsoft throwing out this software in the public domain pretty much gives people the write to issue opinions on it, but it seems to me that in a respected news source like the WSJ should take there ability to influence people to heart and wait for a final version before issuing reviews.

    2. The reviewer faulted this tool for not finding cookies. Big whoop. Seriously, cookies are highly overrated. Ad-Aware is a pretty good tool, but its insistance in clearing out all my cookies causes me to have to redo passwords and such for websites that I would have rather left alone. This utility ignoring the cookies is a good thing.

    3. Resets hijacked home pages to MSN. Buyer beware? Oh thats right this software is free. The problem with hijacked home pages is that there is a script that keeps resetting them to the hijacked page, you can't get rid of it. I haven't tested this, but I imagine that the Microsoft tool simply resets your home page to MSN. You are free to change it back to whatever you want. I imagine it would be a simple enough thing for Microsoft to reset it back to what it was originally, but that requires that your home page wasn't hijacked when the tool was installed. All in all if Microsoft want's to make MSN the default home page with this tool, and the tool is free, I say we got what we paid for. Let them have it.

    4. Doesn't support Firefox. Let me get this straight. Microsoft offers a product for free that a good many of us would be willing to pay for and they don't offer support for there competing web browser? Say it aint so!
    Let me be the first to say that if you wan't Firefox support then maybe you should look at an open source solution or possibly a pay client that supports Firefox. As long as Microsoft is giving this thing away faulting them for this is bias pure and simple.

    1. Re:The WSJ article is very biased. by bogie · · Score: 3, Insightful

      A few counterpoints

      1. Its not a Beta. Its a Final finished product that Giant has been shipping for some time. If someone bought Photoshop CS from Adobe and then called it "My Photo Editor Beta" would you really consider it a Beta product? I agree that some consideration should be given to the fact that MS may actually do some work on this before they call it final, but this really isn't a Beta in the true sense and should be able to stand up to some scrutany.

      2. Well cookies were really the first form of spyware. Not finding them is a flaw. I like you think ignoring them might be a good idea, but the option should be there and its a mark against MS's product that it can't do whats expected from a modern spyware product these days.

      3. Good that it can find hijacked homepages, bad that they don't give you the option to set your own homepage if the program really does think your page was hijacked. That's a no-brainer and something MS should have fixed already. Saying "well its Free isn't it?" is a total copout.

      4. I agree asking MS to support a competitor let alone an OSS one is too much to hope for. But if Firefox becomes a popular browser for many Windows users then they need to keep an open mind.

      --
      If you wanna get rich, you know that payback is a bitch
  12. Re:Heh by NetNifty · · Score: 2, Insightful

    Yeah, like this story here that doesn't exist, for instance... oh wait.

  13. Does not remove Back Orifice by siliconjunkie · · Score: 4, Interesting

    Just a note: I have a copy of Back Orifice 2K on my laptop for running some chores on several machines on my home network (the boPeep plugin is very handy) which is detected by NAV2004, and Spybot as a trojan (it can be) but it is not detected by MS Anti-Spyware. Interesting.

    I would HATE to have BO2K on my machine without knowing it.

  14. Can't they just buy Gator? by BestNicksRTaken · · Score: 2, Insightful

    MS have the money, instead of wasting it trying to do what Spybot S&D and Adaware haven't managed to do in years, why don't they just buy up and close down some spyware companies - that's what they usually do to threats.....

    Personally I hope this product doesn't work, as Spyware/viruses are currently the main reason people I know are moving from Windows to Linux.

    --
    #include <sig.h>
  15. The other way round.. by shird · · Score: 3, Insightful

    Running spy sweeper afterwards and detecting traces of spyware still on the machine does not mean that you should assume that spy sweeper can detect all the stuff that MS anti-spyware has already detected and removed.

    Youd be better off running the two products on identically infected machines and see which detects and removes the most etc. If you were to run spy sweeper first and then MS anti-spyware, youd probably see similar results. (ie, MS anti-spyware detecting stuff that spy sweeper missed).

    --
    I.O.U One Sig.
  16. Re:I like it. by Anonymous Coward · · Score: 3, Informative

    "[Few] seem aware that chopsticks originated in American mining communities" because it didn't - chopsticks have been in use in China for at least 4000 years.

    Get a clue.

  17. Works good so far. by Deathlizard · · Score: 2, Interesting

    I've been testing this thing against some of the worst laptops students can put in front of me and it does a great job so far.

    It's beating Spybot pretty much every time I've put them head to haed. It's still got a way to go against Ad-Aware but generally speaking it's not bad and it does a much more through job then just about every other automatic scanner I've used. I'm finding much less residue with hijackthis with MSAS than anything else so far. With a little more work on their definitions this could easily be a top notch antispyware utility.

    The on demand scanner is really through. If on demand virus scanners were written with a system similar to this it would be really impressive against viral attacks. It checks just about every startup point I can think of where spyware hides. MS definitly didn't waste money by buying this impressive scanner Giant Developed.

    The only problems I see is that it's questionable if MS is going to keep this program free and MS is a huge Lawsuit target. I can see every Spyware company suing the holy crap out of them for removing their product Screaming "Monopoly" and "Antitrust" all the way to the Judge.

  18. It's not bad... by gordgekko · · Score: 3, Informative

    I'm not the world's biggest fan of Microsoft -- I've pretty well shorn myself of everything but XP and Word -- but I have to admit that it's not bad. Caught some minor stuff after I hadn't done a scan with Ad-Aware in a while and cleaned them up. Not the best, nowhere near the worst.

    Interestingly, one service still says "GIANT Antispyware Data Service". I guess they didn't rebadge it all yet.

    --
    You want to know who isn't running Firefox 2.x? They spell it "definately" and "rediculous".
  19. A bandage on a turd by EllynGeek · · Score: 2, Interesting

    I guess taking some of those billions and building a good, secure operating system isn't part of Microsoft's business plane. Funny how all those Linux and BSD hippies did it without billions of dollars to play with.

    --

    we will end no whine before its time

  20. Fallacy by fm6 · · Score: 3, Insightful
    After removal, they ran Webroot's Spy Sweeper 3.0. It was able to detect '900 traces of 48 distinct threats still present, including two keyloggers and three Trojans.
    Means nothing, unless you're sure that Spy Sweeper doesn't do false positive. And it fact, that product seems to do a lot of them. Right now, it's insisting that I have the 2nd-thought and Slackbot trojans. But those guys are pretty well documented, and I can't find the slightest trace of either.
  21. Re:Lop? by Elminst · · Score: 2

    two words...

    format c:\

    Seriously. Ghosting a drive to save data and reloading windows takes 1.5 hours or less. If you find yourself taking more than an hour fighting spyware, bite the bullet and wipe the machine. You'll save time and money in the long run.
    Unless you're one of those people who installs every program ever written and then loses the CD's...

    --
    No unauthorized use. Trespassers will be shot. Survivors will be shot again.
  22. Too soon to tell... by writermike · · Score: 3, Insightful

    Largely, this beta is little more than a rebranded GIANT Antispyware, which was already pretty good to being with. (Yeah, it doesn't support 95/98/ME any longer, but GIANT's software was a little flaky there.)

    (It would be interesting if one could go back in time, send the same software to the reviewer with the GIANT brand and see if the name, "Microsoft," somehow changed the review, but I digress.)

    I am less concerned with Microsoft's changing the underlying structure of the product than I am with their ability to keep up with the threat. Malware demands that an anti product get updated very, very often, sometimes daily. Microsoft, to date, has never demonstrated that they can keep up with the threat. How are they going to go from releasing one to two security updates every couple of weeks to keeping up with a threat that can change hourly.

    Sure, it'll piss us all off if Microsoft -- who presumably has more knowledge of and access to Windows' under-pinnings -- doesn't live up to this challenge, but the worst that will happen to it is this nice product they bought will quickly become irrelevant. And the community (or communisits, I'm not sure which) will, again, rise up to fill the vacuum.

    m

    --
    If Nalgene water bottles are outlawed, only outlaws will have Nalgene water bottles.
  23. Re:Heh by jasondubya · · Score: 2, Insightful

    I would have to say that the review was quite favorable. If anything, it put them one away from the top and pointed out that the program is still in Beta. With that in mind, the review was very favorable.

  24. hostfiles and the beta anti-spyware by artifex2004 · · Score: 2, Interesting

    I'm using a special hostfile I got online, that helps me avoid a lot of ad servers, etc. The anti-spyware beta really dislikes this, however, and every time I run it picks ONE server it tells me is maliciously redirected. I can't easily tell it to just ignore that one component of the search, and when I ask it to ignore an individual server entry, it gives me warnings like I'm going to be really sorry I didn't let MS do what it wants.

  25. The Best Microsoft AntiSpyware... by eomnimedia · · Score: 4, Funny
  26. My problem with this review..... by King_TJ · · Score: 3, Informative

    I have to say, I'm basically at a loss to explain why there's been a lot of positive press about Webroot's Spy Sweeper 3.0 recently. This PC Mag. review is just the latest in "shoot-outs" and reviews I've read that gave Spy Sweeper top (or near top) honors.

    My personal experience, doing on-site PC service calls for a living, is completely different. I've cleaned literally hundreds of spyware infested PCs for customers in the last year or so, and I *often* find they have Spy Sweeper already installed and running, despite all their problems.

    People occasionally ask me if Spy Sweeper is "any good" since companies like Gateway like to try selling it to them over the phone when they call with problems. I've been advising to save the money and skip it.

    It may have a nice interface and claimed "feature set" - but from what I've observed, it doesn't really seem to be that effective at keeping spyware out, or detecting it after the fact.

    In the past, I've been an advocate of the SpyBot and Ad-Aware SE combo, but the new Giant/MS Anti-Spyware solution has done an impressive job for me so far. Just last night, I had a PC that both SpyBot 1.4 beta (w/latest update sigs) and Ad-Aware SE with latest update sigs. reported completely clean of spyware problems. Despite that, ads were randomly popping open in IE windows every 15 seconds or so. MS Anti-Spyware completely cleaned it up.

  27. Re:Lop? by Mr.+Flibble · · Score: 2, Informative

    Believe it or not the makers of the LOP provide their own removal tool.

    http://lop.com/new_uninstall.exe


    Checked it out - Antivirus software goes insane: It detects 2 trojans within the exe. Both newer versions of lop...

    --
    Try to hack my 31337 firewall!
  28. Microsoft's had anti-spyware software forever. by Mostly+Harmless · · Score: 2, Insightful

    format c:

    --
    "`Ford, you're turning into a penguin. Stop it.'" -Douglas Adams, THHGTTG
  29. Good source of consolidated information by kooshvt · · Score: 2, Informative

    It might not be the best anti-spyware program, but its other features are nice. I run Spybot, Ad-aware and SpywareBlaster and decided to install the MS program as well. It didn't find anything, I didn't think it would with the combined efforts of the other 3 programs, but I was impressed by the consolidation of information it presents. In one place I can see the current running processes, startup applications, LSPs and installed activeX apps. It will make troubleshooting family members computer problems easier once they install this. I can just direct them to one app to answer most all my questions, instead of having them dig through the registry, downloading other obscure programs and goggling every unknown process they currently have running. I will still install the other 3 apps on the computers I am called upon to troubleshot and will definitely add this program as well for ease of information.