Windows Defender Lets Spyware Slip onto Vista PCs
Tests with the program showed it missed 84 percent of 25 samples of spyware and malicious code.
Paul F. Roberts, InfoWorld
Users who put their faith in Vista's new security features and Microsoft's Windows Defender antispyware product may find themselves under attack from spyware all the same, according to the results of a study by Webroot, a leading antispyware vendor and Microsoft competitor.
On Thursday, the company released the results of what it claimed was a two-week study of Windows Defender that showed the product missed 84 percent of a sample set of 25 spyware and malicious code samples. The programs that slipped by were a mix of spyware, Trojan horse programs, and keyloggers. While many were not Vista compatible and simply crashed, others were able to install on Vista systems, said Gerhard Eschelbeck, Chief Technology Officer at Webroot.
Technical staff in Microsoft's Security Business Unit weren't able to respond to requests for comment on Webroot's claims.
Mostly Adware Caught
Eschelbeck identified variants of common malware programs like DollarRevenue Trojan, PeperTrojan, and Playboydialler that made it by Windows Defender. Some of the variants were recently released, though others dated back to 2006, he said. Of the four programs Windows Defender did stop, most were non-malicious adware, he added.
"We wanted to validate the strong claims out of the industry that Vista was going to be a security solution for everybody and everything," Eschelbeck said.
Webroot picked the malicious code samples from tens of thousands of samples collected on its Phileas spyware scanning network. Webroot's Spy Sweeper product spotted all of the samples.
When asked, Eschelbeck acknowledged that 25 samples was a tiny fraction of Webroot's database of tens of thousands of malicious code samples. He also acknowledged that it may be possible for Microsoft or other competitors to pick samples of malicious code that would evade Webroot's Spy Sweeper product, given advanced knowledge of how Spy Sweeper's detection features worked.
"Nothing's impossible," Eschelbeck said.
The purpose of the study wasn't to make invidious comparisons between the two products, Eschelbeck said, but to raise questions about the detection capabilities and management of the Windows Defender product as Microsoft expands its profile as an enterprise and consumer security software vendor. "It's important to leave the interpretation up to individuals," he said. "People need to make their own conclusions about it."
Weekly Updates Not Enough
Eschelbeck said Microsoft updates Windows Defender's spyware definitions weekly--far too infrequently for the fast-moving malicious code scene.
Webroot, which is venture-funded, was an early pioneer in the antispyware software space and is one of the leading sellers of antispyware software to consumers. However, the company's prospects have been hurt by Microsoft's entry into the desktop and enterprise security business and the company's decision to offer Windows Defender as a free download.
The Webroot study is just the latest in a salvo of company-sponsored studies that seek to undermine the credibility of competing security products.
In September, a Microsoft-sponsored study by 3Sharp compared antiphishing toolbars by Google/Firefox, AOL, EarthLink, Geotrust, McAfee, and others and found the Internet Explorer antiphishing technology the most accurate. The Mozilla Foundation fired back in November with a competing study by SmartWare that found the Firefox antiphishing technology better than that of Internet Explorer. A subsequent independent study by Carnegie Mellon concluded that few of the available anti-phishing products are very reliable.
For more IT analysis and commentary on emerging technologies, visit InfoWorld.com. Story copyright © 2007 InfoWorld Media Group. All rights reserved.
With HP wireless printers, you could have printed this from any room in the house. Live wirelessly. Print wirelessly.
PCW Download Guide
A Guide to Business IT
Related Security Articles
- When the Watchdog Is the Underdog In data security, many of the toughest challenges have nothing to do with the bad guys.
- Data Mining for Terrorists Is Futile Report, commissioned in part by the DHS, also warns of potential privacy problems.
- Security Software Performs Poorly in Exploit Test Security software suites are doing a poor job of detecting when a PC's software is under attack, according to Danish vendor Secunia.
- What's the Best Way to Backup What I Need to Backup? David Edelbaum wants to know the best techniques and programs for backing up his PC.
- Six Essential Apple iPhone Security Tips Security is a tech manager's top concern when it comes to mobile devices--here's how to use them to your advantage with minimal risk.
Best Prices on Security Software
Norton Internet Security 2009Price: $25.49
Norton Internet Security 2008Price: $13.98
Internet Security 2008 - 3-User (Full Product, PC)Price: $11.49
Norton 360 2.0 ( PC)Price: $44.99
Kaspersky Internet Security 2009Price: $25.95
Internet Security Suite 2008 - 3-UserPrice: $14.95
- HP LaserJet Printers Satisfy your needs by combining fax, copy and scan capabilities with high-quality laser printing. Visit the Resource Center for more info...
- Lenovo Laptop Showcase Find out how Lenovo IdeaPads and Thinkpads balance performance and portability. Visit the Lenovo Resource Center for more info...
- CDW Security Center Is your data protected? Visit the CDW Security Center Learn where you may be vulnerable and how to address those risks.







"Windows Defender Lets Spyware Slip onto Vista PCs" Comments