Quantcast
PC World: Technology Advice You Can Trust
Find a Review
Free Newsletters
Receive the latest reviews, how-to's, news, and more.
Security & Privacy
Weekly Brief
Windows Vista
WiFi Finder
Locate wireless services by a specific address, city, state, country, airport, or zip code.
RSS Feeds
Get our latest content via convenient RSS feeds.
Latest News
Today @ PC World
Become a PCW Member
Join the community and start enjoying the benefits:
  • Get tech advice from thousands of PC World Members
  • Rate and recommend the latest tech products
  • Share your thoughts in blog and article comments
  • Get free excerpts and exclusive discounts on Super Guides

AOL Security Tools Raise Adware Questions

Consumer advocates criticize AOL's free Active Virus Shield antivirus software licensing agreement.

Robert McMillan, IDG News Service

Thursday, August 17, 2006 7:00 PM PDT
Recommend this story?

SAN FRANCISCO -- Just days after posting details of searches made by hundreds of thousands of subscribers, AOL is in hot water again with consumer advocates. This time the issue is with the company's Active Virus Shield anti-virus software, released last week.

At issue is the software's licensing agreement, which authorizes AOL to gather and share data on how the software is being used and permits AOL and its affiliates to send e-mail to users. "If you go through the installation, just as any normal user would, there is not the slightest hint of any advertising functionality or data gathering of any kind," said Eric Howes, director of malware research at anti-spyware vendor Sunbelt Software.

Active Virus Shield uses Kaspersky Lab's well-regarded anti-virus software, and comes with an optional security toolbar that blocks pop-up ads and manages passwords. The software is available for free to anyone who wishes to download it.

Concerns

Although security experts, including Howes, say that Active Virus Shield does not behave in a malicious fashion or serve up unwanted ads, some are concerned that the product's end user license agreement (EULA) would allow AOL to send spam or serve up adware at some point in the future. "If it actually does any of the things stated in the EULA, we would actually flag it as spyware," said Christina Olson, a project manager with Stopbadware.org.

The Active Virus Shield agreement gives AOL much broader rights to collect information and then to share that information with third parties than typical EULAs, observers said.

A prohibition against blocking ads also caught Olson's attention. "If you have any ad-blocking software up, you're basically violating their EULA, which is ridiculous," she said.

AOL in the News Recently

AOL's licensing problems come at a sensitive time for the company. Earlier this month the Internet service provider weathered a public relations disaster after an AOL researcher inadvertently exposed data on about 19 million Web searches performed by 658,000 users.

After being contacted by IDG News, AOL said it now plans to alter the licensing agreement. "We are updating the EULA to address any concerns," said Andrew Weinstein, a company spokesman. "We are reserving the right solely to send periodic marketing e-mails that users will have the choice to opt out of."

Adding to AOL's troubles is the fact Active Virus Shield's security toolbar is based on a product with a questionable reputation. An earlier version of this software, known as the Softomate toolbar, is flagged as adware by Kaspersky's own anti-virus products.

"We don't use the earlier code because it was used by a malware provider," Weinstein said. "That's why Kaspersky looks for it."

Similar to Sony Rootkit Issue?

While AOL's toolbar is not considered to be adware, observers say that AOL, which prides itself as a fierce opponent of adware and spyware, could have based its own toolbar on a better product. "I don't understand how a legitimate company like AOL provides software that can be classified as rogue," said Aviv Raff, a security researcher based in Israel.

After examining AOL's toolbar, Raff discovered a flaw in the software that would allow hackers to change the toolbar's configuration options. While the flaw does not in itself present a security risk, it could be used in combination with other types of malicious software to do things like pop up bogus search results, he said.

"The problem is similar to the Sony rootkit issue," Raff said referring to Sony BMG Music Entertainment's notorious copy protection software, which was found to be the source of security issues late last year. "A big company chose an external company's software and rebranded it as their own, later to discover it might be bad after all," he said.

Erik Larkin of PC World contributed to this story.


Recommend this story?

Comments
HP Ink Center
Bring improved color and brilliance to your printed material. Visit the Resource Center for more info...
CDW Solution Center
Deliver speed and scalability in your storage systems. Find out how at the CDW Solution Center.
Asus Notebook Center
Ultra-fashionable thin and light notebooks with SmartLogon Face Recognition. Find out more at the Asus Resource Center.
Intel Processor Technology
Which Intel Processor is Right for You?Centrino, Core 2 Duo, Core 2 Quad, Core 2 Extreme? Check out the Intel Technology Center for more info...
Are you a gamer?Visit the Intel's Gaming section for the latest downloads, hottest gaming events and to learn about Intel & Gaming.
See what Intel can do for Vista...Discover how Windows Vista technology work in the benchmarks with Intel Centrino processor technology.
VoIP Web Demo
Join Altigen for a Live Web Demo and learn how VoIP technology can improve your business communications.
The Future Sales Force - A Consultative Approach
This white paper discusses the challenges of selling complex products and services, and the new skill sets sales professionals must employ.
Latest News
A software glitch that crept into a massive system integration project at Japan's Bank of Tokyo Mitsubishi UFJ left thousands... 12-May-2008
Apple's iPhone will be available from more than one mobile operator in Australia and India later this year, further signs that... 12-May-2008
An earthquake registering 7.8 on the Richter Scale knocked out mobile phone service in the western Chinese city of Chengdu... 12-May-2008
Advanced Micro Devices is shipping B3 versions of its low-power Quad-Core Opteron processors. 12-May-2008
Taiwanese hardware maker Micro-Star International's upcoming Wind laptop can be preordered starting from US$560. 12-May-2008
Database maker Vertica Systems is moving its technology to Amazon's Elastic Compute Cloud infrastructure (EC2), hoping to... 11-May-2008
The public will get its first chance Monday to test a search engine from start-up Powerset that eschews conventional keyword... 11-May-2008
Research in Motion's sleek new BlackBerry Bold 9000 will support 3G networks worldwide, as well as Wi-Fi and GPS. Will it be able to withstand a 3G iPhone challenge? 11-May-2008
The ICT (information and communications technology) industry needs to do its part to help alleviate the current food crisis... 11-May-2008
A crafty site allows you to schedule a call to your own phone and get you out of bad meetings. 11-May-2008

PC World's Marketplace

PC World's Free Whitepapers

Name City
Address 1 State Zip
Address 2 E-mail (optional)