Microsoft AntiSpyware: Is it worth bothering with?

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

ANALYSIS

The anti-spyware software recently announced by Microsoft is now mature enough to evaluate so I downloaded a copy and ran it head-to-head with a free utility: Lavasoft's Ad-Aware SE (Personal Edition). There is no word yet on whether Microsoft plans to charge for the product once it is out of beta.

Although Microsoft's AntiSpyware isn't intended to do exactly the same thing as Ad-Aware, the goals are similar -- to locate and quarantine software that can capture information from your computer and transmit it to others without your knowledge or agreement. Most of these are relatively harmless cookies used to monitor advertising hits, but the same technology can be hiding code that captures keystrokes and harvests other critical information from systems.

Without the use of some tool it is very difficult for Windows users and administrators to detect these programs and know what they may be doing.

You can only obtain AntiSpyware, which is about 6 MB in size, as a download from Microsoft's Web site. The beta version won't be made available on CD-ROM. Installation went smoothly, although while trying to view some options it did lock up, and I had to kill it via Task Manager. The program started right up again when I tried it. I already had Ad-aware on my machine, but if you want a copy it can be downloaded from ZDNet UK's download area.

I ran both utilities on an older 2-GHz P4 Dell with 512MB of RAM and running XP SP2. Both took about 12 minutes to complete a deep file scan but the results were significantly different.

AntiSpyware reported scanning 2398 memory processes, 18,973 files, and 8693 registry keys, finding no problems. I had just purged the system an hour earlier with Ad-Aware. There are few details provided about just how the software works so I don’t know why a later automatic scan reported checking 33970 files.

Immediately after running the Microsoft program Ad-Aware scanned 2564 process modules, and 157,212 "objects", the term Ad-Aware uses that approximates files. The important difference was that the Lavasoft utility found five data-mining objects, including one from trafficmp.com and another from doubleclick.net. It’s a rare system that doesn’t have some doubleclick data mining objects, but AntiSpyware apparently isn’t intended to detect them.

AntiSpyware is more than just a spyware scanner; it also provides some management tools and provides real-time protection by watching for more than 50 ways spyware can insinuate its way onto your system. I’ve seen reports that this works pretty well, although it failed to block or notify me of six new tracking cookies installed on my system in a half hour online. Ad-Aware found them on a "smart" system scan while AntiSpyware failed to do so even on a deeper scan.

One AntiSpyware tool, Security Agents, monitors program and Internet activity as well as system changes.

System Explorers, another tool, provides a simple method to manage ActiveX, running processes, startup programs, IE settings, and other features that can be fine-tuned to make your system work the way you want it to.

The Running Processes tool is especially useful because it makes it easy to learn just what the processes do in considerable detail -- far more than you get with Task Manager -- although you still need TM to see what CPU time is being allocated to each process. One shortcoming is that additional information beyond some fairly basic data such as file path and version isn’t available yet for many processes, but bear in mind that this is a beta program.

Talkback

Is it worth bothering with? You bet!

I use Ad-Aware and Spybot (always with the latest adware dictionaries) on a regular basis, and when I saw details on ZDNet of MS's new AntiSpyware beta I naturally thought I'd give it a go, out of curiosity. Thank god I did.

I ran Ad-Aware & Spybot first, on 2 PCs. Both machines were found to have an assortment of the usual tracking cookies but nothing nasty. I then let the MS tool loose and was horrified when it found a keystroke logger embedded on my corporate laptop and an ad displayer on the other machine, a corporate desktop.

So what if it isn't designed to root out pesky tracking cookies? These aren't really a threat, though they irritate the heck out of me. The MS jobbie saved my bacon and I have recommended all my colleagues to try it.

God knows how long that malware was on those machines; as a supposedly savvy consultant I pride myself in running clean machines. Much like Firefox users, I felt that any tool offered by MS would be grossly inferior to the excellent Ad-Aware & Spybot, but it turns out that their aquisition of Giant Software was a bloody smart move.

I hate to sound like an MS flunky, and if they charge loads for this once it's out of beta then I take it all back, but for now I am bloody thankful they released it.

via Facebook 25 January, 2005 13:56
Reply

Chris, strange that your anti-virus software didn't detect the keystroke logger. Which keystroke logger was it anyway? And was it a confirmed find or a false positive?

via Facebook 26 January, 2005 22:09
Reply

Not sure how it got past AV, I think I may have turned On Access Scan off for a couple of hours while trying to find why McAfee hogs CPU. So partly my fault.

I don't recall the malware's name byt Microsoft AntiSpyware gave full details, one of the best reports from a tool such as this I've seen yet. Using it I went on-line and checked out the keylogger and found it was a professional version used by corporations to monitor staff, but also available as Shareware. Worryingly it also had the capability to remotely view my screen!

Whether my fault for disabling AV for a short while or not, only the MS tool found this hideous system invader. It gets top marks from me!

via Facebook 27 January, 2005 09:25
Reply

Interestingly Spybot detects "Avenue A, Inc" attempting to install itself when accessing this web site!

via Facebook 27 January, 2005 12:23
Reply

Try runnning it on a PC that's been connected to the Internet with 'Ordinary Users' hammering it for years and you'll see the Microsoft one wins hands down,
Most of the machines Browsers have been hijacked and the Microsoft Utility allows you to resert the Hijack easily. Just hope they don't charge.

via Facebook 27 January, 2005 12:53
Reply

I am a techie, and manage about 500 customers. The reviewer did the scan on a relatively clean machine used by an advanced user. This is is thus an inaccurate review.

What he shoudl have done is load it on a novice users pc. It worked a dream and most importantly continued to run in the background. It also has a great anti hijack facility.

For advanced users don't bother and just keep running ad aware. if you are a novice (like most of my clients) who don't know what to do with ad aware then install it now!!
Great tool for novices but techies and advanced users don't bother

By the way the tracking cookies that lavasoft finds are regenerated within a day and they are watching you again! thus even lavasoft is not very effective!

via Facebook 27 January, 2005 15:37
Reply

I installed the Beta MS anti spyware on Jan 9, and it was runnign smoothly until i had an auto update from MS on 2-10, when the MS antispyware was then unable to access the internet for updates. My experience is that the MS anti spyware did get malware which Adaware and Spybot missed, and this is matches Eric Howes from Uof Illinois in his test of popular anti malware tools. He said that of 134 "planted" malware items, the MS found 100, while spybot only found 40. Adaware I think was at 70's and Spysweeper in the 80's.
Meanwhile, I did a system restore to B4 the MS update, as I am not a techie and want the protection of the updates...I'm attempting to put a link the the eweek article showing the test results here: http://www.eweek.com/article2/0,1759,1731474,00.asp?kc=EWRSS03129TX1K0000614
Ashwin

via Facebook 11 February, 2005 21:20
Reply

Well, I've seen this Microsoft AntiSpyware in action.

First of all, I have my doubts about the License Agreement that comes with this product but then I'm not a laywer.

Also, on a perfectly clean machine (checked by pro's) it claimed to have found XferPro based on nothing but registry keys (no executable found) that have nothing do with XferPro.
That's not hopefull but then this is still beta software. But that might be a reason why Microsoft AntiSpyware finds things that others do not.

Other then that this Microsoft AntiSpyware seems no better then the more proven solutions already available out there. With the exception that Microsoft AntiSpyware falls into the category of nagware as far as I'm concerned because it keeps on popping up questions for as long as the user doesn't comply with what the program thinks is best. As such I wouldn't recommend putting beta software into production. Certainly when there are more experienced and proven solutions out there that don't nag as much.

via Facebook 17 February, 2005 23:19
Reply

This "review" was so lame i laughed!
it was good in the sense that he wanted to compare them but the article sounded rushed.

I used both earlier today, Adaware == 9 spywares

MS Antispyware.......14254

what a difference. the MS antispyware was the correct one!! adaware fell a long way short!

via Facebook 22 February, 2005 19:00
Reply

I tried the BETA for about 2 weeks and was unimpressed. The thing deleted my Kazaa registry keys so now Kazaa is useless even though I have taken the files out of quarrantine. I mean the program did what it was supposed to do but as pointed out i nthe article some spyware was missed and well I just think that a combination of spyware and adware ttols would be better, personally I use Spyware Blaster, Spy Bot S&D, and Ad-Aware and with these 3 I am very impressed with the amount of protection my computer has.

via Facebook 24 February, 2005 17:08
Reply

This post has been removed by a moderator.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Jack Schofield

@openhgs Windows users have had multiple desktops since Linus started writing Linux. They just haven't shipped as standard because not enough...

9 hours ago by Jack Schofield on Windows 8 could speed multi-monitor uptake
Jack Schofield

@Phil at Cloud4 What, Microsoft gets £1,200 per PC and £1,622 per server? Gosh, I'm amazed....

10 hours ago by Jack Schofield on 6 million wasted licences and £1,200 PCs: welcome to government IT
craigsc

You guys have no idea what is going on at Autonomy. Autonomy could have been a much more profitable organization. The sales operations at Autonomy...

11 hours ago by craigsc on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Moley

How does this impact on dual or multi booting? Seems to me to more or less prohibit this, from Windows 8 anyway. Will Grub 2 recognise Windows 8,...

11 hours ago by Moley on Windows 8 start-up speed forces USB boot workaround
apexwm

I don't understand why there cannot be a slight pause during the boot process so the user can press a key. Many operating systems do this, even if...

13 hours ago by apexwm on Windows 8 start-up speed forces USB boot workaround
Gavin Goodman

You can now buy the Xi3 modular computer in the UK at http://www.ocdistribution.com . This can be bought with the Tand3m software, pricing and...

13 hours ago by Gavin Goodman on CES 2012: Xi3 microSERV3R
Phil at Cloud4

I agree: Mike Lynch can clearly build a business and manage strategy. I suspect the exit of Mike is more likely the end of a planned handover...

16 hours ago by Phil at Cloud4 on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Phil at Cloud4

This is unbeleivable government wastage with only one winner... Microsoft 1 - Tax payer Nil!

17 hours ago by Phil at Cloud4 on 6 million wasted licences and £1,200 PCs: welcome to government IT
Mispam

So what do you do when you can't boot into windows? Why can't I just hold Shift while I power up instead of having to boot into windows and click a...

17 hours ago by Mispam on Windows 8 start-up speed forces USB boot workaround
apexwm

I've also seen that Mac OS X for Intel machines is supposed to run in VirtualBox, which would also be a nice solution. I've never tried it though.

19 hours ago by apexwm on xTreme Triple Booting: Linux, Mac & Windows
dave heasman

What I wonder is why when companies are caught bang to rights in not providing contracted services, people bend over to smear the customers? Surely...

19 hours ago by dave heasman on Virgin throttles broadband for high-speed customers
pjc158

Strange statement from HP regarding Mike Lynch and not capable of scaling a company. Autonomy was a $7bn purchase which started as a small company...

20 hours ago by pjc158 on HP cuts 27,000 staff as Autonomy chief Lynch leaves
lojolondon

Or - possibly, they will destroy business by ensuring people do not invest where there is no return. Another socialist idea, well beyond it's...

23 hours ago by lojolondon on Open Data Institute will act as biz incubator
J.A. Watson

Good stuff Jake, very interesting. Thanks. jw

23 hours ago by J.A. Watson on xTreme Triple Booting: Linux, Mac & Windows
openhgs

"the cost of a second LCD screen is about the same as one day of an office worker's time, so this should soon be recouped in extra productivity."...

1 day ago by openhgs on Windows 8 could speed multi-monitor uptake
Thomas Gellhaus

I also installed the KDE version; I also will probably try out razorqt since I really haven't had a chance to before. I'm looking forward to the...

1 day ago by Thomas Gellhaus via Facebook on Mageia 2 Released
francisabigail

Acquiring when reinvention/cannibalization is too challenging for a large organization can be an excellent strategy- still, so many mergers stumble...

2 days ago by francisabigail on Ariba buy parks SAP on Oracle's cloud turf
apexwm

All of the feedback regarding using a touch monitor for a desktop PC is right on. Several months ago, we installed a "demo" multitouch all-in-one...

2 days ago by apexwm on Windows 8 could speed multi-monitor uptake
191706

anyone wanting to triple boot *their* own Mac

2 days ago by 191706 on xTreme Triple Booting: Linux, Mac & Windows
SoapyTablet

Cont.. Biggest Bugbear: Win7's stop-animate-go approach to work, you develop a staggered (not in the above alchohol sense of the word) approach to...

2 days ago by SoapyTablet on Windows 8 could speed multi-monitor uptake