Q. I received a warning sign from a Microsoft Windows Explorer message that I might have infected files. So I followed the direction to download Spyware Stormer, scanned my disk, and found out that I have 105 infected files. Spyware Stormer advised me to register to clean the disk for $29.95. I am wondering if this program is as advertised. Or do you have any suggestions?
A. Nobody knows how many scam artists, business hustlers and outright thieves have joined the rush to cheat people using bogus anti-spyware and anti-adware programs, but I fear that the situation is horribly confusing.
You apparently got snared by a pop-up ad using the Microsoft Windows Messenger Service, part of the operating system designed to let network operators send text notes to individual machines. These messages look like they come from Microsoft Windows, but they are just ads by people who found the vulnerability of the messenger service.
Readers can get a look at the problem at a Web site called SpywareWarrior.com, which includes reports by volunteers who try to keep track of the always-changing situation. Read their reports and you’ll agree that surfing around the Internet looking for a trustworthy tool to combat spyware and adware is like trying to decide which guy selling watches on the sidewalk is telling the truth.
Head to www.spywarewarrior.com /rogue(underscore)anti-spyware.htm#products and you’ll see what I mean. But don’t think that you can simply read that report on rogue protection programs and find one that works.
Don’t be too paranoid, but remember that some adware schemes have included planting programs on people’s machines that serve up pitches for spyware protection software when they point their browsers to sites that try to help.
Nobody has a clear picture of what is good and what is bad and so I’d be very leery of any outfit that isn’t well-known–complete with a street address, the names of corporate officers and overwhelmingly favorable mention in Web postings and media reviews. If you use a search engine like Google with the name of a program as the keyword you can usually get a feel for the quality of the outfit in question. Even then be careful.
For an example of how a reputable company handles this dangerously shaky situation, check out the Web sites of Intermute Inc. (www.intermute.com) and Lavasoft (www.lavasoft.de), probably the top two players in the area.
The problem is that every day brings new hacker schemes and the big companies don’t always cover everything that’s out there. Scams like browser hijacks, for example, often prove impossible to crack with Lavasoft and Intermute products, which is one reason there are so many outfits offering to fix software.
I know my advice sounds like telling you to only buy a watch from a guy in Times Square if he shows you his driver’s license. But the only advice beyond sticking with the establishment companies is to rigorously check out sellers of anti-spyware and anti-adware software before considering their offers.
8/28/2004
Q. I have Windows 2000 Professional running on a Dell machine. I am concerned about ID theft. I bought a software package called XoftSpy, which it appears was a mistake.
My question: What is the best approach to protecting me from ID theft and related activities? Will a software package such as the one offered by Norton work best, or must I go to a hardware firewall? I appreciate any help you might provide.
A. There is a new firewall included in the Windows XP Service Pack to handle your problem, but you’ll also need a reliable software firewall to keep your computer from sending information back to whichever vandal infested it with spyware.
Most folks who get serious about this issue use the free version of Zone Alarm or buy the more robust pro version. Norton’s firewall, along with those of its competitors, also handles the job. In all cases, the idea is that the firewall software pops up a warning every time something tries to leave your computer and move onto the Internet.
Unless you are actively downloading stuff or sending e-mail, chances are anything trying to broadcast data from your machine is not your friend.
This is how spyware sends its owners data about what’s on your computer, how keyboard loggers transmit text files showing every keystroke you made in the past day, and how those “zombie” e-mail schemes start using other computers to blast out torrents of e-mail to others with accounts.
Keep in mind that even the rudimentary firewall in Windows is highly effective in keeping one protected from getting infected with these nasty broadcasting spyware attacks, and so going further can be overkill.
As to XoftSpy, this is one of a number of untested and possibly dangerous programs offered for free download with the promise of ferreting out spyware. I checked its Web site and found that it holds all kinds of promises but doesn’t mention the name of a single living, breathing person or give any address except e-mail to things like “support.”
Please, folks, make it a rule to never download software unless you know the identities of the sellers and that they have a street address. Even then remember that this, too, can be false.
8/18/2004
More Top Picks Best New Balance Shoes For Flat Feet
Q. As soon as I connect to the Internet, I start getting an error message “Iexplore–This program has performed an illegal operation and will be shut down.” If I click on the details button it further states “IEXPLORE caused an invalid page fault in module
unknown …” This message will pop up every few minutes.
Additionally, if I do a Ctl + Alt + Delete, the program box will show that this program is listed multiple times (up to 10). It slows the machine down terribly, and eventually I reboot. I’ve been on the phone with Microsoft three times and my Internet provider once. I’ve reloaded Internet Explorer 6.0 and have run Spy Bots and Ad-aware software. Nothing seems to work. Any thoughts?
A. You are in the right church using anti-spyware tools like Ad-aware but maybe not in exactly the right pew.
Your PC has been riddled by one of the so-called browser hijack schemes that are being foisted upon home computer users by a growing collection of nasty people. Makers of the various anti-spyware tools try to keep track of them all, but every one of these booby traps is different and many slip through the cracks.
Makers of software like Ad-aware continually add fixes for new schemes, but there are an overwhelming number of attacks being launched.
The problem is that this Trojan-horse software scatters many different bombs around one’s hard drive. These bombs get triggered by changes the hacker makes to the system registry and other core files. These multiple bugs on your computer create those multiple instances of the Windows Internet Explorer software.
Perhaps the ultimate tool to attack these cluster bombs is HijackThis, a system that requires some serious study but that lets a user scan the complete hard drive and find the booby traps one by one. I hesitate to recommend this because HijackThis presents a user with long lists of items that could be booby traps.
There is a danger that one will remove something desirable, and a typical HijackThis log can include maybe 100 possible changes.
I hate to end this way, but there are three possible moves when this hits us. First we can wait for the repair programs to publish a fix. Second, we can take a shot at fixing things with HijackThis and similar tools. Third, of course, we can just muddle through it all.
See www.spywareinfo.com, where you can get help and details about the complex HijackThis tool and other possible preventative moves.
7/24/2004