How to fix spyware

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

COMMENT
Christmas comes and Christmas goes, a time of family, friends and tradition. There is one new tradition I would happy convert to Buddhism to avoid, however: the festive deinfestation of the computers. Seeing as you're here, Rupert, my Dell's running a little slow. Here's a mince pie, try not to get the crumbs in the keyboard. And what's with the rude pop-ups?

The latest spyware is smart, subtle and hideously tenacious. It hooks into multiple parts of the Windows start-up sequence, and intercepts attempts to edit files such as the registry. Its filenames are invented anew each time it installs itself: it monitors its own components and replaces them if they're deleted. It is impossible to remove this stuff unless you boot up with an uninfected copy of the operating system: even then, a high order of surgical skill is necessary to unhook each of its tendrils from around your computer's heart.

It used to be simple to boot up a computer with a clean copy of the operating system: you kept a prepared, write-protected floppy disk to hand. Put it in, restart the computer and the universe begins anew. These days, XP is far too grand for mere floppies – assuming you could read such fossils in the first place – and it can't run directly from CD, so you have to do a system restore and hope that catches the nasties. Or you can back up your data, reformat and reinstall your applications, a painful and error-prone process.

So why have no anti-malware vendors produced a fully featured, bootable scanner and spyware-removal tool? Trying to base one around Windows would be a bad idea. I don't know how much money Redmond wants to license a run-time version of the OS to distribute with your software, but it won't be peanuts. It won't be easy to cut it down to fit portable media, either.

You don't need Windows to read and write a Windows-format hard disk, though. There's no reason a perfectly good scanner and disinfector can't be written to run under one of the open-source operating systems – with the bonus that you can easily create your own version of the OS with just the bits you need. Boot your PC from that, and the OS will see the infected drive as just another device full of data. The malware hasn't got a chance. If I could carry that around on my USB keychain -- and a credit-card-sized CD in my wallet for those PCs which can't boot from USB -- my holidays would be a lot less stressful.

This would be an excellent open source project with plenty of opportunities for revenue, were it not for the need to have a permanent team of highly skilled threat analysis monkeys on tap. Malware evolves at a terrifying rate, and any respectable product has to keep up. Writing the software is one thing, keeping the database current is quite another.

In an ideal world, the researchers from the various anti-malware companies would publish and share their databases. There is no chance of this happening. Not only do they see this information as their crown jewels, they actively prosper from the fact that no one company has a perfect record. Read any anti-malware review, and you'll see the recommendation that you run at least two products, just to be sure – thus doubling the size of the market. Too tasty to give up just for the sake of the users.

There are several possible ways to bypass this sorry state of affairs. Microsoft should have no interest in profiting from problems it has at least some responsibility for. It's already bought Giant Software and started giving away the product in mute acknowledgment of problems it has a duty to fix. By publishing its threat database it would encourage a healthier environment. Alternatively, threat analysis by skilled volunteers could be coordinated online just as any other project: for something that has such advantages for everyone in the IT community, employer support should be forthcoming.

Whatever it takes, there has to be a step change in the protection the community wants to give itself. There are plenty of good anti-malware products, but none is good enough. The products are reactive, not innovative: the market has painted itself into a lucrative corner. And I -- and countless other IT problem-solvers around the world -- would like our Christmases back, please.

Talkback

how do i fix slow start up on my dell lap top taking 10 mins to start also slugish removel after click cheers.

via Facebook 13 January, 2005 13:38
Reply

Just reading your article, I have been using a product now for some months, its very effective in removing any spyware or viruses which infect my system. Actually its 100% effective but it doesn`t seem to be known much. I don`t know why. Its a little PCI card called Juzt-Reboot it recovers and backs up my system instantly and I had the chance to put it to the test recently with a virus I was infected with....in seconds my system was virus free - worth its wait in gold.

via Facebook 14 January, 2005 03:22
Reply

I never have problems in this regard. Generally, this is because friends & family tell me that they're getting a PC for Christmas, and ask for advice. I find that prevention is easier than cure. To avoid headaches after the yuletide, simply issue this simple statement beforehand.

"Buy a Mac!"

via Facebook 14 January, 2005 13:37
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

UnderINK

I agree with the previous commenter wholeheartedly. I couldn't say it better myself. This is very 'Big Brother'. And while I agree with protecting...

4 hours ago by UnderINK on European e-identity plan to be unveiled this month
Simon Bisson and Mary Branscombe

Nice to see that Turing's idea of a general purpose computer doing once-hardware-powered tasks in software is now universal ;-) Mary

9 hours ago by Simon Bisson and Mary Branscombe on Software with everything
Jason Burchell

seriously now. I've only bothered to read a small bit of the comments. do me and the rest of the world a favour. stop saying it does not work or...

13 hours ago by Jason Burchell via Facebook on Music industry negotiating over 24-bit downloads
Philip Charles Cohen

Read about it and weep, John Donahoe ... In addition to Visa’s V.me, there is now MasterCard’s PayPass digital wallet soon to arrive; another...

17 hours ago by Philip Charles Cohen via Facebook on PayPal takes phone-based payments to the high street
apexwm

Leslie Satenstein : Where have you ever seen Mozilla even mention this? Firefox is the most popular browser in the GNU/Linux OS, so I don't see...

18 hours ago by apexwm on Firefox rapid release improves Fedora Linux
songmaster

SHleG: Do you remember building a clockwork scorpion kit (I'm pretty sure I have a photo of it somewhere) — I think it was called something like...

19 hours ago by songmaster on Software with everything
Chris Wortman

Good I love Yahoo! Their search engine is getting better than Google as of late. I find more of what I want on the first page, and usually within...

20 hours ago by Chris Wortman via Facebook on Linux Mint 13 ramps up for KDE release
PatrickG

openhgs has made the point for Windows 8 multiple monitors without realising it! With Windows 7 you have to switch the mouse and so your focus...

22 hours ago by PatrickG on Windows 8 could speed multi-monitor uptake
Leslie Satenstein

Mozilla has threatened to stop supporting Linux. I guess that UBUNTU is going with another browser. I indicated that if Mozilla stops supporting...

23 hours ago by Leslie Satenstein via Facebook on Firefox rapid release improves Fedora Linux
Andy Bolstridge

Much as I abhor Microsoft's licensing practices, this is almost certainly down to purchasing IT equipment via 3rd party consultants - you get the...

23 hours ago by Andy Bolstridge via Facebook on 6 million wasted licences and £1,200 PCs: welcome to government IT
Jack Schofield

@openhgs Windows users have had multiple desktops since Linus started writing Linux. They just haven't shipped as standard because not enough...

2 days ago by Jack Schofield on Windows 8 could speed multi-monitor uptake
Jack Schofield

@Phil at Cloud4 What, Microsoft gets £1,200 per PC and £1,622 per server? Gosh, I'm amazed....

2 days ago by Jack Schofield on 6 million wasted licences and £1,200 PCs: welcome to government IT
craigsc

You guys have no idea what is going on at Autonomy. Autonomy could have been a much more profitable organization. The sales operations at Autonomy...

2 days ago by craigsc on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Moley

How does this impact on dual or multi booting? Seems to me to more or less prohibit this, from Windows 8 anyway. Will Grub 2 recognise Windows 8,...

2 days ago by Moley on Windows 8 start-up speed forces USB boot workaround
apexwm

I don't understand why there cannot be a slight pause during the boot process so the user can press a key. Many operating systems do this, even if...

2 days ago by apexwm on Windows 8 start-up speed forces USB boot workaround
Gavin Goodman

You can now buy the Xi3 modular computer in the UK at http://www.ocdistribution.com . This can be bought with the Tand3m software, pricing and...

2 days ago by Gavin Goodman on CES 2012: Xi3 microSERV3R
Phil at Cloud4

I agree: Mike Lynch can clearly build a business and manage strategy. I suspect the exit of Mike is more likely the end of a planned handover...

2 days ago by Phil at Cloud4 on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Phil at Cloud4

This is unbeleivable government wastage with only one winner... Microsoft 1 - Tax payer Nil!

2 days ago by Phil at Cloud4 on 6 million wasted licences and £1,200 PCs: welcome to government IT
Mispam

So what do you do when you can't boot into windows? Why can't I just hold Shift while I power up instead of having to boot into windows and click a...

2 days ago by Mispam on Windows 8 start-up speed forces USB boot workaround
apexwm

I've also seen that Mac OS X for Intel machines is supposed to run in VirtualBox, which would also be a nice solution. I've never tried it though.

2 days ago by apexwm on xTreme Triple Booting: Linux, Mac & Windows