Slashdot Log In
Non-Technical Users Talk Malware
Posted by
Zonk
on Thu Jul 07, 2005 10:46 AM
from the from-the-horse's-mouth dept.
from the from-the-horse's-mouth dept.
swirsky writes "The Chicago Sun Times is running an article detailing the experiences of non-technical users after they were infected by spyware, malware, and viruses. We cluck our collective tongue and think that we'd never be so stupid, but this is a major problem that plagues personal computing." From the article: "The study found that spyware has disrupted the computer lives of 43 percent of surfers. That means an estimated 59 million people have spyware or adware on their computers, the study found. Adware is defined as tracking programs that come bundled with other software and that users knowingly download, although they don't necessarily want the adware."
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
Malware == Moolah (Score:5, Insightful)
I love malware. Malware removal acounts for probably 65-70% of the bottom line in my business. I'll tell you something else...the $129 average price tag quoted in the article is right on the money.
Personally, I hope nothing is done about the problem. I only wish I could protect my less-technically-inclined family members and friends more effectively, as I don't charge them for removal.
Re:Malware == Moolah (Score:3, Informative)
Re:Malware == Moolah (Score:5, Insightful)
But don't try to force them to make the switch, it will just lead to frustration when thing don't work out as expected because they can't play this-or-that game.
Just leave them with their malware problems and let them figure it out for themselves. Drop the odd hint about never having received a virus if you feel like it. Perhaps they'll get a Mac or something. It's a step in the right direction at least.
Parent
Re:Malware == Moolah (Score:5, Funny)
Bah, I could find an overseas resource to do the same thing for $12.
Parent
Re:Malware == Moolah (Score:5, Funny)
I downloaded a desktop assistant that does the same thing for free!
Parent
Re:Malware == Moolah (Score:5, Interesting)
I'm the mac tech so I don't see the spyware first-hand but I know it keeps the PC tech pleanty busy. Most entertaining aspect of spyware: when one of the other employees uses the PC tech's PC to web browse, and he comes in to find popups on his own machine. hehe..
Then there are the oh... 1 in 15 customers that can bring in their machine every two weeks to have us remove the spyware, again. Some customers just can't get "don't click the popup's close button" through their head. There ought to be a simple law that states that "any software installer must clearly label the buttons and other control areas in their installer, such that there can be no confusion or deception as to the function of each control, whereas a user could be tricked into allowing the installation without his consent."
Parent
Re:Malware == Moolah (Score:3, Interesting)
We have something like that in Germany... If sonmeone wants to install and run a dialer on your system they have to jump through several hoops - the dialer may not be installed without your con
Re:Malware == Moolah (Score:5, Insightful)
"War is good for the economy" is a fallacy that is true only for weapon makers. Everyone else pays the price. Fear is a motivator, but it produces less than it destroys. I guess some firefighters "love fire", but most would rather be barbecueing.
Parent
Re:Malware == Moolah (Score:3, Interesting)
Wow, I never quite realized what people are willing to pay for this. Personally, I usually do it for friends and family for the price of a good meal. At work, I support student owned laptops and do this as part of my job. I really need to reconsider going independent.
That said, yes malware is a huge problem, and one of the reasons I am employed. And for all of the preventative measures we take and t
Re:Malware == Moolah (Score:3, Informative)
I luckily don't have to deal with the family removal issues. The one family member that is constantly infecting her machine lives no where nea
Re:Malware == Moolah (Score:3, Funny)
And, if things go right, you'll be showing her your "Oh" face, right?
It's not just the non-technical users (Score:5, Informative)
Being a technical guy, familar with the registry, COM, and how windows works, I went about trying to kill this pesky snake. A few hours later, after saying some words I won't repeat here, I decided to wipe the machine and start over (it was a lighly loaded box, so no major loss)
I could have gotten SoftIce [windowsitpro.com] and gone into kernal mode to trap this bastard, but it was way beyond my effort vs. reward tolerence level. Spyware has gotten so complicated and sneaky nowadays: to me it is worse of a threat than virsuses ever were.
Now I run double anti-spyware programs in addition to my A/V and firewall. I think that we technical people are also misunderestimating the danger posed by this junk to our own machines.
Run With the Bulls, Swim With the Sharks [whattofix.com]
Re:It's not just the non-technical users (Score:4, Funny)
I think we technical people are "misunderestimating" our own grasp of the English language.
Parent
It's your own fault (Score:5, Insightful)
I can understand why non-technical users surf with Internet Explorer.
I can understand why technical users use Internet Explorer for Windows Update and a small selection of trusted websites (e.g. online banking) for compatibility.
But I have no sympathy whatsoever for technical users who should know better that continue to use Internet Explorer to visit websites that are in no way trustworthy.
Parent
Re:It's not just the non-technical users (Score:5, Insightful)
If you were using Mozilla, you would have had 5 clicks and a double click: Click on the page, then click "Save to Disk" then point to a location, then minimized your browser, then double-clicked the EXE. That's a big accident!
Firefox lets you set a default download location, so that's down to 4 clicks.
Maybe you were using Internet Explorer 6 and had the default operation for EXE files to be to open them. You are down to 3 clicks. You could have clicked the web page, clicked OKAY to the prompt to open the EXE. Then maybe you accidentally clicked OK to the prompt about installing an application from the web that shows in a big warning box telling you about signed and unsigned applications.
Or maybe you were using an old version of Internet Explorer (IE 4? 5?) which doesn't prompt for anything if you have that set as the default. That seems highly unlikely for someone smart enough to know COM and the registry.
Okay, sorry if I am sounding like a jerk. I really just want to know how this can happen!
Parent
Re:It's not just the non-technical users (Score:5, Informative)
You somehow assume that you actually have to "click" a link and "save to disk" to download a file through IE. This is not so. Sites can use IE to install software on your computer, without your knowledge, even with all the preventative measures you mentioned. This is possible with what are known as "exploits" in the system. The insecurity of IE is not so much the default settings, as it is that changing the settings means practically nothing. That is why IE is flawed and broken beyond belief with critical security vunerabilities [secunia.com].
If you want to see how easily a PC is infected without you clicking, saving, or knowing ANYTHING, this series of articles will help: http://isc.sans.org/diary.php?date=2004-07-23 [sans.org]
Parent
I have to ask ... (Score:3, Insightful)
I use FF exclusively, unless there's a good reason to view a page in IE. And I always have the latest S&D immunizations for IE. But I'm curious if I'd be just as vulnerable despite these protections.
Re:It's not just the non-technical users (Score:3, Informative)
You're not going to want to hear this, but anyway
You could have *_avoided_* all of that if you just ran your box as a user, and elevated to admin when needed.
Mor info on the non-admin experience [msdn.com]
Re:It's not just the non-technical users (Score:5, Funny)
Parent
EULAs, Bill Riders (Score:4, Insightful)
Because for legal purposes, they're implicitly required to make you agree to a license agreement, which in most cases does state that, by default, or sometimes as a requirement of the license, they'll be installing the adware on your system.
By contrast, there's no requirement for a company to offer a "feature set" on their website, or anywhere else. I suppose you're proposing something like a Surgeon General's warning on cigarettes, but that seems like overkill to me, and I do hate ad/malware.
But more importantly, this sort of thing is exactly how the legislative branch of the US government works: "Sure, you can have this bill, but we're going to tack on some of our own additions that you probably haven't had time to read." Adware in EULAs Riders on bills. While again, I do hate adware, I really suggest we rout this process from our respective lawmaking bodies before we concentrate on [wah, wah] consumer electronics.
Parent
Re:It's not just the non-technical users (Score:3, Funny)
I'll take Insanely Obscure Analogies for $400, Alex.
Claria (Score:4, Insightful)
Claria and HomeSec (Score:5, Informative)
Gator, er, Claria, is not spyware.
Gator CPO at the Department of Homeland Security [slashdot.org].
Legitimized by Microsoft and with representation on HomeSec DPIAC, Gator is now officially securityware, Citizen!
And if you've got some sort of problem with that, take it up with the boss, namely HomeSec's Chief Privacy Officer. She's none other than Nuala O'Connor-Kelly [com.com], formerly of Doubleclick.
What's with the head-on-desk-thumping motion? I'm not demented enough to make this shit up!
Parent
Securityware (Score:4, Insightful)
Seriously though, your post is interesting - I hadn't heard of the term 'securityware' being used before, especially not for malware. I guess that Microsoft will try to spin this into a good thing, if they can't keep it quiet.
Parent
Re:Claria (Score:5, Insightful)
So you think that it's ok that when you visit your favourite site, all their adverts are replaced by adverts of Microsoft's choice, and your favourite site gets none of the revenue? And when your favourite site ends up having to shut down due to lack of funds, will you still argue that spyware/malware does not affect you?
Parent
I thought I was immune too (Score:5, Insightful)
Imagine my surprise when I ran AdAware just today and discovered 7 infections.
The real problem is not that there is a bunch of computer illiterate grannies opening every attachment they receive. While that is a factor, the real vulnerability is in the hubris of "power users" who think they can't get infected because they take all the precautions. But as I learned today, sometimes even that is not enough to be completely protected.
Re:I thought I was immune too (Score:5, Informative)
Parent
Re:I thought I was immune too (Score:3, Insightful)
-matthew
not a big surprise, but it's ominous for future (Score:5, Insightful)
One small but not insignificant piece of the problem is just that, the attitude among techies that if only the "lusers" would stop being so stupid, they wouldn't have so many problems.
I've predicted this before, I'll stand by the prediction, (unless there are quick, effective, and transparent solutions) people eventually will become so fed up with this they will collectively begin to unplug (not necessarily a bad thing) and move on. I have in the last few years established my uneasy peace with Microsoft Windows on my dual boot machines now that XP has reached reasonable stability, but have gotten to the point where I rarely go there anymore because it has ceased being a "boot into" endeavor and instead is almost always a boot, then reboot, and sometimes yet another update and reboot. So much for transparency. I have programs I like to use in Windows I've actually begun to offset by creating my own similar linux functionality (thank Goodness I can code) just because I can't stand the 15 minute preamble to getting up and running in Windows.
On the other hand, my Dad, whom I've spent countless hours coaxing and helping learn Windows and how to use his computer called the other day and said he had disconnected it, and didn't care to ever use it again. I can't blame him.
WTF? (Score:3, Funny)
No spyware, malware (Score:5, Funny)
...not to mention the ones who don't even know (Score:4, Insightful)
Spyware & Windows (Score:4, Informative)
The "Trust Gap" (Score:3, Interesting)
Wow, what insight!!! You could apply this statement to how people relate to today's government, media and advertising.
The bottom line is that people need to be vigilant about security in whatever they are doing. The computer software manufacturers need to stop spyware and adware as a built-in feature, not as a free download from an obscure website. But then again, who is profiting from all this spyware and adware? Most likely it includes some of the same people who are trying to stop it.
It does provide a need for tech workers to fix these problems ---- as its only bright side.
I just don't get it (thanks dog) (Score:3, Interesting)
A consultant got banned after his laptop got infected from a connection at a hotel while getting his mail and some crap got through when he connected to the bank.
There are over 20k boxes at the bank and they take a bird if any of them would ge anything that would behave like spyware. They might monitor your keystrokes but they would hate like hell if somebody else did it. Its their equipment after all.
Non-techies don't care (Score:3, Interesting)
My mother got a new PC about Feb last year, it had XP installed on it (not by me) and since her Internet access would be coming through my PC through NAT, I asked her to install Mozilla on it to stop her getting malware. She immediately told me she didn't want "any of that Linux crap" on her PC.
Fast forward a couple of months. She was complaining about, among other things, porn popups and the fact that her PC was slowing down to a crawl. She and my brother had installed, among other things, lots of casino programs, Kazaa and had been using only IE to browse the web. A quick scan with Ad-Aware revealed 1000 infections. This time I set Ad-Aware to run a scan at every system startup, removed access to IE and told her to use Firefox. This time, she went schizo and I had to shout her down and get someone else involved to point out to her that using IE was a bad thing.
Normal users don't care. End of.
Re:Non-techies don't care (Score:3, Interesting)
The web browser is only half the problem. The fact that people will happily run any
You're absolutely spot on about normal users not caring. They'll happily let their system turn into a spyware-infested zombie,
Re:Non-techies don't care (Score:4, Insightful)
Wow, that's industrious, and she should be commended.
Ignore it, and get on with your life. The CORRECT answer is, as always, that computers just get old, and slow down. There are SPECIALIZED shops that can give them a tune-up, and you don't have the equipment.
Keep repeating that. You KNOW you can't win this battle.
Ratboy.
Parent
welcome? (Score:3, Funny)
$129 to fix (Score:3, Insightful)
Pffft.. (Score:3, Insightful)
Malware - Love it AND hate it (Score:4, Informative)
On the other hand, I get paid to do that. I just did one small company with 5 computers that was literally shut down because they couldn't do anything on their systems. Spyware is a problem on just about every single "joe average" computer that I have seen lately. The problem, of course, is going to get worse as long as Windows continues to allow users to run with privileged access by default.
I don't feel like going into a Microsoft rant - I'm sure it would be preaching to the choir anyway. I would like to share effective tools in my warchest for cleaning out spyware -
Ad-Aware [lavasoftusa.com] - My favorite anti-spyware program right now. Gets about 95% of baddies.
HiJack This! [spywareinfo.com] - Cleans up anything that Ad-Aware may have left behind. It scans all startup regkeys, services, and BHO IE extension keys and lets you select which ones to nuke. BE CAREFUL, it lists both the good and the bad. If you don't know what a process is, google for it before you remove its key.
There are many other useful tools on this download page as well, like LSPFix. This program will fix the mess left by programs that mess with your TCP stack, such as New Net, [cexx.org] whos manual removal can disable your Internet access completely.
Pocket KillBox [bleepingcomputer.com] - You know those processes that come back from the dead after you kill them? Can't delete the EXE because it's locked in both normal and safe modes? Pocket Killbox is what you need. If it can't delete the file outright, it can temporarily end the Explorer task and try it that way. If that doesn't work, it can use Windows' replace-on-reboot function to swap the EXE with a dummy file on the next reboot. Very handy for getting rid of the most nefarious of processes.
Spyware Blaster [javacoolsoftware.com] - Pre-emptive spyware prevention. The interesting thing about this program is that it doesn't remain resident in memory. Instead, it writes files and regkeys to your system that prevent the spyware from installing. Adding and removing protection can be done in one click.
The strange thing about this article (Score:5, Insightful)
How can someone "report" (I use that word loosely) on this problem and tiptoe around the huge elephant in the room? In spite of the overall fraction of users that are having problems, spyware is not normal. It is almost entirely contained within one single very specific homogenous portion of the population. To say that computer users suffer from spyware is like saying that Sol 3 lifeforms suffer from tobacco mosaic virus. Yes, it's technically true if you want to get pedantic, but it's hard to believe that a "reporter" (*cough*) could so egregiously overly-generalize unless they intended to mislead.
Fear of spyware changing online habits (Score:3, Informative)
For those interested, here is another article [nwsource.com] just popped up in the Seattle Times [nwsource.com] on the very same thing. I think the claims on "reaction" to spyware are a little more gentle (e.g., being more vigilant... what the heck is that?, and what added benefit does it really bring?). Regardless, enjoy... it's a good enough read to take a look.
Re:Just buy a Mac :-) (Score:4, Insightful)
Macs are not immune to viruses, we just haven't seen a virus or spyware author take the time to exploit it, yet. Why? Because it isn't profitable RIGHT NOW.
When you see the Mac userbase hit a decent number (and I don't pretend to know what that is) then you'll see spyware and viruses for it. Fact. Until then, stop being a mactard and just deal with the situation at hand: there is a lot of spyware out there and something needs to be done now. That something is not ignoring the problem until it swims up and bites you in the ass.
Parent
Re:Just buy a Mac :-) (Score:3, Informative)
Re:Just buy a Mac :-) (Score:3, Informative)
(Below is a paste of my post from above.)
Apache has > 60% marketshare, yet IIS has more vulernabilities.
The whole "windows gets infected more because more people are targeting it" argument doesn't hold up - otherwise, apache would have more security problems than IIS.
Re:Just buy a Mac :-) (Score:3, Insightful)
Re:Ironic (Score:3, Insightful)
Rubbish.
When is the last time you changed the windows kernel and recompiled it? What disk is the Windows source code on? Remind me again what compilers Windows comes with? Oh sorry, market share is the ONLY factor that makes linux cool...
Re:Survey results skewed (as always) (Score:4, Informative)
Parent