CyberArmy University | Open Source Institute | CyberArmy Intelligence & Security | CyberArmy Services & Projects

[Software Reviews] Product Review: AdAware SE Personal


[Reply] [View by Thread] [Help]
[Back To Article Discussion Forum]

Posted by Author 1746 On 2007-04-29 10:02:19




View and vote on the article here: Product Review: AdAware SE Personal 1.06


Product Review: AdAware SE Personal 1.06

Category
Software Reviews
Summary
Adware, spyware, and malware: computer users are faced with an ever increasing attack by programs designed to show us advertisements we don't want, invade our privacy by tracking the sites we visit and steal our passwords and financial information if they
Body
Adware, spyware, and malware: computer users are faced with an ever increasing attack by programs designed to show us advertisements we don't want, invade our privacy by tracking the sites we visit and steal our passwords and financial information if they can get away with it. In some cases, these programs may attempt to place your computer under someone else's control.

In addition to being annoying and invasive, these programs can slow your computer down to a crawl as each of them steals a share of your processing power to do its dirty work.

One way to fight back is to download and run AdAware, a free Anti-Spyware application from LavaSoft. The current version is called SE Personal, and is available in fifteen languages for the following platforms:
Windows
* 98/98se/Me/NT4 Workstation/NT4 Server/2000 Pro/2000
* Server/2003 Server/XP Home/XP Pro/XP
* (Home/Professional)/XP 64-Bit Edition/Terminal Services

Scanning

OK, you've downloaded AdAware and you're ready to start. Simply click on the "Start" button on the lower right. You will be asked to select a "Scan mode", and I suggest the "Full system scan" with "negligible risk entries" and "Low risk threats" ticked to make sure everything on your system is found. Click "Next" and the scan begins.

AdAware scans fixed and removable drives, memory and Windows registry for traces of known spyware and adware. It compares your files against a list known as a definitions file and through a process known as Code Sequence Identification (CSI), AdAware detects known and unknown variants of malware.

When the scan is complete, you are presented with a log and a summary of the results. Part of the information included is the category in which the object has been assigned based on LavaSoft's Threat Assessment Chart (TAC), which is intended to let you know how dangerous the object is.

If anything is found on a scan, you are offered a choice of removing or quarantining the object. Quarantine can be useful if the object turns out to be a component of a software application you want to keep despite its malicious nature.

AdAware is primarily known as an Anti-Spyware application, but it also offers protection from known data-mining, aggressive advertising, trojans, dialers, malware, browser hijackers, keyloggers, and tracking components. While it does scan for some well know virus, trojan, and worm content, it is not an anti-virus or anti-trojan solution so it is important to make sure that you have a specific solution installed on your system and/or network.

A scan will disclose something called MRU. As LavaSoft states: "This is a listing of the Most Recently Used lists stored in your registry. They are harmless and consist only of things such as the most recent document you opened. They are included in Ad-Aware due to requests from users and to highlight the fact that they are harmless where some antispyware applications will list them as being potentially harmful in an attempt to appear to detect more content than they actually do."

It's important to mention that a user needs to update the definitions files frequently, and AdAware can be set to do this automatically.

Plug-ins

LavaSoft offers a number of add-on plug-ins to extend protection or functionality for users.

* VX2 Cleaner V2.0
VX2 is one of the most problematic applications to remove from your computer. While Ad-Aware SE effectively deals with most VX2 variants, there are a few that none of today's available anti-spyware application can detect or remove.

* Tweak SE
Tweak SE allows you to alter and "tweak" settings as well as make GUI alterations. It also allows you to flag all alternate data streams, and encoded URL references.

* Messenger-Control
Allows users to shut off the Windows Messenger Service which is an Internet server that's up and running on your machine by default, leaving it open to anyone who wants to connect to it when you're online.
On October 15th, 2005, Microsoft released Security Bulletin MS03-043 regarding Messenger Service. "An attacker who successfully exploited this vulnerability could be able to run code with Local System privileges on an affected system, or could cause the Messenger Service to fail. The attacker could then take any action on the system, including installing programs, viewing, changing or deleting data, or creating new accounts with full privileges."
As LavaSoft says; "Turning off Windows Messenger Service also has the added benefit of freeing up a little extra RAM and CPU cycles. If for no other reason than to shut off spam it's worth the few seconds it takes to turn it off."

* HexDump
"The HexDump extension for Ad-Aware lets you view a hexadecimal version of a file turned up in a scan, along with an "English" translation of the hex code. This can provide you with additional information you may find handy such as the URL of the originator of a cookie." (1)

* LSP Explorer
"Layered Service Providers (LSP) are small pieces of software that can be added or inserted into the Windows TCP/IP handler by other software. Data outward bound from your computer to a legitimate destination on the Internet can be intercepted by an LSP and sent somewhere other than where you intend it to go. LSP Explorer lets you view active LSP and Name Service Providers on your system, along with detailed information about each so you can determine whether or not they're legitimate." (1)

* ARIES Rootkit Remover (Sony Rootkit)
ARIES allows a user to remove the DRM (Digital Rights Management) software called XCP, developed by First4Internet. This application is currently in Beta, but LavaSoft is encouraging anyone infected with the Sony Rootkit to access the application by registering first as a Beta tester at Lavasoft Beta Application Testing Registration.
For more information, see;
http://www.lavasoftresearch.com/betaprogram/rootkit.php

Conclusion
In my opinion, AdAware is one of the most powerful and versatile tools you can have in your safety and security arsenal and I highly recommend it. This useful application can be very educational as well. You can now figure out what sites are violating your rights.

I also recommend becoming a BetaTester for AdAware, as it's very easy and allows you to be notified when a new definitions file is about to be released to the public. By running AdAware with the Beta definitions files, you are assured of "up-to-the-minute" protection, and you're also helping LavaSoft stay on the cutting edge of the malware battle.


1746



Sources and links:

For further information and to download, go to LavaSoft (1) at:
http://www.lavasoft.de/

If you would like to change the look of AdAware, go to AdAware Skins at:
http://www.adawareskins.com/



This article was imported from zZine. (original author: 1746)


There are no replies to this post yet.



Guest:
Subject:
Message:
Signature:
Optional Image Link:
http://

CyberArmy::Forum v0.6
Generated In 0.02900 seconds


About Us | Privacy Policy | Mission Statement | Help