Anti-Spyware Protection ? Holes in the Shining Armor

Looking at all the ads which promise to get rid of all spy programs, one may wonder why there is still plenty of them everywhere and the situation is by no means getting better. So let me spoil the advertisers' mood and show some of the "holes" in the majority of software products we expect to protect our data.

Speaking about drawbacks of anti-spyware, let's take the word "spyware" in the narrow sense for a change and call "spyware" only software products that really spy, i.e. steal valuable information you want to keep private. Let's leave aside adware -- this motley crew of advertising stuff; information that some of them "steal" isn't valuable enough. It is keylogging programs that we should associate with the term "spyware" first of all. This breed is exceptionally dangerous -- such threats as flourishing online bank fraud and the recent outbreak of keylogger-containing Trojans prove this.

Generally speaking, most anti-spyware works like that? Don't stop reading, please. Don't skip over the paragraph. Do you think that if you are not a tech person, it is none of your business? You don't write this software, you just use it -- so what? You haven't made the car you are driving, either (well, there may be some exceptions?). But you do know (at least in general) what makes it move -- and you won't forget to fill up its tank or have it serviced from time to time. You know what will happen if you don't. For the same reason you'd better know a bit about anti-spy software installed on any PC you use.

We all should know it to realize what exactly to expect from all these anti-spy products with cool names. Their creators and sellers promise you that these software products will "kill all spyware on your PC" (or something like that). First, is absolute protection possible? Second, what should we expect from a typical anti-spy program and what it is simply unable to do? To answer these questions, we should understand how it works.

Generally speaking, most anti-spyware works like that: it scans the operating system in search for suspicious bits of code. Should the program find any, it compares these suspicious pieces with bits of code (they are called signatures), which belong to already detected and "caught" spy programs. Signatures are kept in so-called signature base -- the inseparable part of any anti-spy program. The more signatures it contains, the more spyware such program will detect, so your PC will be protected more effectively. As long as you update your anti-spy software regularly and the system doesn't come across some unknown spyware product, everything is going to be all right.

As for me, this pattern looks pretty like police records and works like them, too. But?the problem is just like the one with police records ? the fact that all included there are criminals doesn't at all mean that all the criminals are included into the records.

Well, what about the criminals (spy programs) that are not included into the records (signature bases)? There are lots of such programs -- more than that -- some of them will never be in any signature base. Just like with criminals -- some of them haven't been caught yet, and some will never be caught ? because of their "right of inviolability". Anti- spy products based on signature base analysis will never be able to protect against these spies. Don't expect them to.

Let's take a quick look on these elusive spy programs.

Group 1. Those which hasn't been caught yet, because they are:

1. brand-new ones. They are being constantly written, released, used (for a very short time), detected and, finally, included into signature bases. Anti-spyware developers are now in the vicious circle of endless "spy hunt", trying to include as many spyware signatures (pieces of code) into the bases as possible - and fast! Faster, to outrun the competitors; faster, for new spyware - which is being written and released all the time ? not to spread like a wildfire. That's the way a signature base grows.

2. written to be used only once.

These "tailor-made", or should we say, "custom-made", keyloggers are extremely unlikely to be ever detected. As soon as they have done their jobs (stealing data, of course ?often from the particular computer) they simply disappear, never to be seen again. Here belong keyloggers made mostly for such tasks as espionage.

The main problem: keylogging software is relatively simple and not too difficult to compile. Even an average computer programmer can write a simple keylogger in a couple of days. More sophisticated one will take longer to make, of course, but not too long. Hackers often compile source code of several keyloggers (it's easy to find them in the Web--for those who know where to look for) -- and get a brand-new one with an unknown signature even faster. If a keylogger can be installed remotely without the victim's knowledge, it gives the hacker great possibility to steal any information he pleases. If there is an opportunity, there always will be one to use it. The period of time when a new spy already exists, but the updates have not been released yet, is the very time when hackers make their biggest profits. Trying to catch them all is a hopeless idea; it looks too similar to catching fleas one by one.

Group 2. "Sacred cows".

No signature base will ever have their signatures. Here belong mostly monitoring programs, which can be used for spying as well. First, the ones created by (or for) government agencies ? such as the famous Magic Lantern (the brainchild of the Cyber Knight project). No product which uses a signature base will protect against it; an ordinary anti-spy will never detect such a program. The same situation with other monitoring software, which certain agencies utilize. These monitoring products simply "don't exist" for signature-base-using anti-spyware (though they can well exist on any PC--yours included)

If you think I'm painting it too black let's recall what happened when code of D.I.R.T. (a covert spying tool developed by Codex Data Systems) leaked out couple of years ago and was found in the Web (merely by accident, by the way). Once a top-secret project, it did become an open secret -- but the signature of this powerful monitoring software hasn't been included in any signature bases. That's what worries me the most; after this information leak nobody knows for sure WHO can be using it --and WHAT FOR. What if some other government monitoring program trickles into the Internet, too?

Monitoring programs for parental control or workplace surveillance are very common and easily available from the Web. However, they can be used not only for those absolutely legitimate purposes. Any monitoring program is actually a double-edged sword because it almost always contains a keylogging module. It is up to an end user to utilize them--perhaps for spying. Legitimate monitoring programs are sometimes not included into signature bases, so one can use an anti-spy program and be spied on anyway.

Now the last (but not the least) threat -- spy modules incorporated into viruses and Trojan horse programs. Unfortunately, all malware, including viruses, Trojan horses, worms and other fauna, "evolves" (due to their malicious creators). There already are so many hybrids between one another that it's hard to find, say, a "pure" virus like ones used only several years ago. Lots of this fauna can contain a keylogger -- like MyDoom (sure you remember this virus). They multiply and evolve, becoming more and more malicious.

So, what conclusions could we draw out of this entire story (sorry if it turned to be too pessimistic)?

Is absolute anti-spy protection possible? With existing anti-spy software which uses signature bases - no.

However, there is a relatively new trend in software development -- not to use signature base analysis at all. This approach is rather promising; it means that such software--it already exists--can counteract even brand-new and custom-made spies. You may read more about it if you follow the link in my signature.

What should we expect from an average anti-monitoring or anti-spy program? It does protect from spy software which it "knows". If it has the particular signature in its base, it protects your PC from this particular program. If anti-spyware uses a signature base, it will never "kill all spies on your PC--"whatever the salesperson promises you. Don't expect complete security-- there is no such thing anymore.

The only hope is for entirely new technologies. If developers can't succeed in fighting spyware, they should try something else.

Alexandra Gamanenko currently works at the Raytown Corporation, LLC -- an independent software developing company. Visit its website http://www.anti-keyloggers.com

cleaning service near Park Ridge ..
In The News:

Hotel TV privacy risks go beyond forgotten passwords when you sign into Netflix or other streaming apps on shared devices you don't control.
Apple's iOS 27 Visual Intelligence now lets your iPhone search objects directly on screen, but Samsung Galaxy and Google Pixel have a head start.
x47.c Windows malware uses xAI's Grok to maintain persistence on infected PCs while stealing passwords, browser cookies and API keys from victims.
Frankie LaPenna fought three robots in a cage, including two modified EngineAI T800 humanoids that can kick with up to 850 pounds of force..
MacSync malware hides malicious commands inside iCloud calendar events to download additional payloads onto infected Macs without raising suspicion.
Joseph Holycross dismissed his racing heart for nearly two years until his Samsung Galaxy Watch detected atrial fibrillation and changed everything.
Home title fraud begins when criminals forge your signature on a deed. Here is how to check your own property records and set up free alerts.
Jeffrey Ladish, a former Anthropic security team member, warns AI agents are colluding and hacking with no reliable solution to keep them in check.
Instinct Concierge and Meta Muse can now place phone calls to businesses on your behalf, but the privacy and data access tradeoffs are significant.
Olivia Moore spent $100 to create a fake RushTok influencer using ChatGPT and MiniMax, and thousands of Bama Rush fans couldn't tell the difference.
RatHat Android malware uses AI to steal banking credentials, intercept two-factor authentication codes and reconstruct your PIN from touch inputs.
The Fox News AI Newsletter covers the latest artificial intelligence technology advancements, including the challenges and opportunities AI presents now and for the future.
Apple and Google password managers can flag compromised, weak and reused passwords on your phone before credential stuffing attacks can strike.
Researcher Peter Garrigan says Moonshot AI's Kimi model was manipulated into providing instructions for biological weapons and assassination plans.
iPhone, Google Pixel and Samsung Galaxy phones now offer call screening that asks unknown callers to identify themselves before your phone rings.
Ransomware can lock your irreplaceable photos and documents in seconds. A tested backup strategy and stronger cybersecurity habits are your best defense.
ShinyHunters claims it breached FBIJobs.gov and stole Social Security numbers, home addresses and sensitive assignment details of FBI personnel.
Find My iPhone, Google Find Hub and Samsung Find have critical tracking settings to enable now, before your phone ever goes missing or stolen.
The FTC proposed a new enforcement policy on personalized pricing, warning companies that hide how personal data shapes the prices shoppers see.
The $250 million Apple Siri AI settlement is now accepting claims, with eligible iPhone owners potentially receiving up to $95 per device.
ShareAScan turns T-shirts into scannable digital business cards with QR codes that link to profiles the owner can update anytime they choose.
BragJack research reveals how a single malicious browser extension could hijack Gemini, Perplexity Comet and Edge AI agents with zero clicks.
A phishing campaign impersonating OpenAI uses fake ChatGPT billing emails with a convincing login page to steal credentials and payment details.
Startups are helping modernize America’s defense industry with new technology and innovative ideas as the War Department diversifies its inventory.
New account fraud victims jumped 31% in 2025, reaching 5.4 million. Criminals open accounts you may never see on your regular bank statements.

Device Driver Basics

Most people understand that the "hardware" part of their computer... Read More

Five Reasons for Using an O/R Mapping Tool

So, why should you use any O/R mapping tool? I... Read More

COSMIC: A Small Improvement on the Symons Method

The COSMIC FP (function point) software quality metric, is no... Read More

Managing Stress in the Computer Industry - Five Steps to a Stress-free Life

It would be easy to think, like most people apparently... Read More

MultiNational Corporation ERP Implementation ? Microsoft Business Solutions Great Plains

If you look back to the history, you will see... Read More

Lotus Domino: Application Integration ? A Programmer View

There are two approaches for application integration:? Programmer's approach ?... Read More

eConnect: eCommerce Development for Microsoft Great Plains

Microsoft Business Solutions Great Plains has several options to enable... Read More

SQL: Querying Microsoft Great Plains ? Overview for Database Administrator/Developer

Looks like Microsoft Great Plains becomes more... Read More

Microsoft Navision Database Selection: C/SIDE or MS SQL Server - Overview For IT Specialist

There are certain pluses and minuses in both cases and... Read More

Microsoft Navision Customization and Reporting ? Tips For Programmer/IT Specialist

C/SIDE (Client/Server Integrated Development Environment) - The core of... Read More

Microsoft Business Solutions VAR/Partner Selection ? Overview for IT Director/Manager/Controller

Microsoft Great Plains and Microsoft CRM become more and more... Read More

Huddle Up; Groupware on Three

It could just be me, but my experiences with document... Read More

Great Plains DOS Support ? Notes for Consultant

Great Plains Accounting, accounting package for mid-size and small companies... Read More

Crystal Reports - Microsoft SQL Server

Microsoft SQL Server is the leader for inexpensive and middle... Read More

Google Brings the Earth to Your Desktop

Google Inc. has launched a new software package that allows... Read More

Introduction To ISDN, Part II

In the previous ISDN article, we looked at how and... Read More

.Net Charts and Graphs Interact with Businesses and Customers

Bar charts, bar graphs, and any other chart or graph... Read More

Navision Attain Database access via C/ODBC in ASP.NET Application

Navision Software was purchased by Microsoft and now it is... Read More

Microsoft Great Plains: Interest Calculation Example ? Stored Procedure for Crystal Report

This is intermediate level SQL scripting article for DB Administrator,... Read More

RFID: Strengthen the Position for SAP; United States

SAP Inc., a global leader in client/server enterprise application software... Read More

Microsoft Great Plains Customization Recovery & Upgrade for Large Corporation

At the end of XX century, in the late 1990th... Read More

SSH (SCP) Send Files from Windows to Your Linux Box

Not all of us have the luxury of working both... Read More

Selecting Microsoft Great Plains Partner/VAR/Reseller: ERP Implementation & Customization ? Overview

In the case when you represent mid-size or mid-size-to-large business,... Read More

Spyware, Adware, etc. -- Terms and Common Sense

When reading an article where some term is used often,... Read More

IT Strategy for Large Corporation: ERP/MRP/CRM, Unix/Linux/Windows, Microsoft/Java

Combining Microsoft Business Solutions Great Plains ERP with non-Microsoft Business... Read More

house cleaning near Des Plaines ..