On CNET: The new Lara Croft: More agile than ever

Get rid of malware with these free tools

Tags: Spyware, adware & malware, Cyberthreats, Viruses and worms, SECURITY, tool, Jonathan Yarden, malware, spyware, computer

  • Save
  • Print
  • Digg This
  • 0

Takeaway: IT managers and security firms have pegged spyware as 2005's biggest threat to networks. In addition, malware is proving more and more difficult to remove. Jonathan Yarden recommends three free tools for making sure your systems are free of malware.

Want more advice for locking down your network? Stay on top of the latest security issues and industry trends by automatically signing up for our free Internet Security Focus newsletter, delivered each Monday.

Regardless of how well-protected and maintained your computer systems are, chances are good that—at some point in time—something installed on your computer without your knowledge. Better known as spyware or malware (the more inclusive term), these secretly installed programs are becoming an increasing concern for organizations—even surpassing the annoyance of spam. In fact, IT managers and security firms have pegged spyware as 2005's biggest threat to networks.

Recognizing the problem

While the U.S. government currently debates the growing problem of spyware, the rest of us have to deal with it on our own terms. Hundreds of different malware variants are on the loose, comprising spyware, adware, keystroke loggers, and anything else that attempts to collect or track your activities on the Internet.

Legislation isn't going to fix the issue of spyware and other malicious software lurking on your PC anymore than it's solved the spam problem. Rather than waiting for a legislative answer that may not even be a solution, it's time to take some action yourself.

By its very nature, malware doesn't want to reveal itself, so users typically have no idea anything has changed on their computers. And average computer users aren't the only ones who fall victim to malware.

Like antivirus-disabling worms and viruses, malware is proving more difficult to remove. Because of consumers' growing awareness about spyware and other malicious code, the people writing malware are starting to behave much like the criminals that write viruses and worms.

In fact, malware in the form of Browser Helper Objects (BHOs) show up installed in Internet Explorer, even on otherwise secured computers. One malware called WinTools even manages to repair itself if it detects someone is trying to remove it.

Getting rid of malware

Dozens of Windows tools are available to help identify and remove spyware, adware, and other malicious code from computers. However, the most powerful ones are not for the faint of heart. Some of my personal favorites—mostly because they're free—are HijackThis, Spybot Search & Destroy, and BHODemon. In addition, there are many commercial alternatives, including Ad-Aware, Giant AntiSpyware, and Microsoft's Windows AntiSpyware beta.

HijackThis is an excellent tool to identify and remove malware from Windows computers. When used properly, HijackThis can rid a computer of malware, but in my experience, it works best in combination with other tools specifically designed to remove malware. HijackThis quickly scans and displays the various startup programs and services for a Windows system, as well as BHOs and areas of Internet Explorer typically used by malware.

This tool has been around for quite a few years, and most seasoned Windows administrators are already familiar with it. While I generally don't recommend HijackThis to average computer users, it can help a more seasoned administrator determine what's going on with a malware-infested Windows PC. One typical use of HijackThis is to disable BHOs and startup items that it identifies as malware and reboot the Windows machine.

Keeping malware from coming back

After disabling malware, cleaning it up and taking steps to keep it from coming back are the next steps, and this is a job for Spybot Search & Destroy and BHODemon. Similar to commercial adware and spyware tools, Spybot also includes features that allow it to "immunize" a computer from malware. After running Spybot Search & Destroy and removing malware from a computer, I use the "immunize" feature, reboot the Windows computer, and scan it again to see if the malware came back.

Teatimer is a companion program to Spybot Search & Destroy, which you can use to stop malware that attempts to resurrect itself by monitoring running processes and registry changes. However, in my experience, Teatimer is generally not as useful once you've completely removed the malware.

To get rid of and prevent malicious Internet Explorer BHOs, I use BHODemon. While Windows XP Service Pack 2's Internet Explorer includes a similar offering under its Manage Add-ons feature, I prefer BHODemon. Not everyone uses Windows XP, and, more important, BHODemon prevents BHOs from installing and activating.

BHODemon displays whatever Spybot Search & Destroy doesn't remove, and you can choose which BHOs to enable or disable. After installation, BHODemon starts up automatically, preventing hostile BHOs from installing in real time and closing the door on adware and spyware code that might have piggybacked onto other software installations.

These three tools can help you close the door on dangerous malware. However, keep in mind that they're also quite powerful, capable of causing extensive damage if used improperly. Because of this, I don't recommend offering these tools to a novice user who doesn't understand a computer's inner workings. Some malware requires expert surgery to remove, and these are powerful tools to clean malware from Windows systems.

Jonathan Yarden is the senior UNIX system administrator, network security manager, and senior software architect for a regional ISP.

  • Save
  • Print
  • Digg This
  • 0

Print/View all Posts Comments on this article

Javacool SpywareBlastercbiltcliffe@...  | 04/01/05
About SpywareblasterInfo-Safety, LLC  | 04/01/05
If it's not resident in the background, iti cannot ..deepsand  | 04/01/05
it doesn't have to run in the backgroundsimplyshaman  | 03/27/06
Question.deepsand  | 05/26/06
Spyware Removal Checklistblack_eyed_pea  | 04/04/05
Great task listblouwagie  | 04/12/05
While that is an excellent ideapapasmurf457  | 04/18/05
What do you do, then?Hardware Queen  | 04/18/05
What I do varies...revver  | 04/18/05
That makes senseHardware Queen  | 04/21/05
By itself, Spy Sweeper alone catches only approx. 48% of malware.deepsand  | 04/18/05
Not a fan myself, but.....Vetch_101  | 04/18/05
On Eric Howe's research re. effectiveness of existing countermeasures.deepsand  | 04/18/05
That's the one...Vetch_101  | 04/19/05
Prevention rather than cureVetch_101  | 04/19/05
Prevention AND Cure.deepsand  | 04/19/05
There is only 4 things I use..Most effective for memadcow9597  | 03/27/06
forget waiting for HT log posts!50THZ  | 12/01/06
you don't have to wait for HT log posts! forget that ...50THZ  | 12/01/06
This is nice but...kurdon@...  | 12/27/05
This is nice but...kurdon@...  | 12/27/05
Broken LinkAGERanger10  | 04/04/05
Try this onepdirico@...  | 04/04/05
that's the ONLY good link for Spybot S&D, here's why50THZ  | 12/01/06
2nd on Javacool - Should be REQUIRED ! !m0le  | 04/04/05
WheresJames free StartupManager is other key toolblouwagie  | 04/12/05
Considering Trend Micro!sconnell@...  | 04/27/05
Minor Nuisance?????Vetch_101  | 04/28/05
A very good Anti-Spyware application with teathzczc2311@...  | 12/27/05
Try Hitman Pro2grbrown@...  | 03/27/06
spywareblastermobycol@...  | 04/01/05
Spy bot 1'st but CounterSpy is a MUST!!!mjohnson@...  | 04/04/05
Agreedtetonbob@...  | 04/04/05
Tried Panda Free, seems - OK but...MWRadio@...  | 04/06/05
Run a HEAP of anti everything!youdnever@...  | 04/18/05
CounterSpytryten  | 12/20/05
Once clean...thomas.dalton@...  | 04/04/05
Local AccountVetch_101  | 04/04/05
Would love toFinite_SA  | 04/04/05
RunAsAdminVetch_101  | 04/04/05
MoveOnBootmoira@...  | 04/05/05
For best results...mudgie  | 05/11/05
??????deepsand  | 05/12/05
FascinatingDr Dij  | 05/16/05
FireFox may be gaining market share too rapidly.deepsand  | 05/16/05

What do you think?

Article Categories

Security
Security Solutions, IT Locksmith
Networking and Communications
E-mail Administration NetNote, Cisco Routers and Switches
CIO and IT Management
Project Management, CIO Issues, Strategies that Scale
Desktops, Laptops & OS
Windows 2000 Professional, Microsoft Word, Microsoft Excel, Microsoft Access, Windows XP,
Data Management
Oracle, SQL Server
Servers
Windows NT, Linux NetNote, Windows Server 2003
Career Development
Geek Trivia
Software/Web Development
Web Development Zone, Visual Basic, .NET
advertisement
Click Here