What is SpyWare?

Spyware is a generic term typically describing software whose purpose is to collect demographic and usage information from your computer, usually for advertising purposes. The term is also used to describe software that 'sneaks' onto the system or performs other activities hidden to the user. Spyware apps are usually bundled as a hidden component in mis-labeled "freeware" and shareware applications downloaded from the Internet--a spyware module may be active on your computer at this moment without your knowledge! These modules are almost always installed on the system secretively, suggesting that spyware companies know how users feel about such software and figure that the best/only way to ensure its widespread use is to prevent the end-user from discovering it.

Comsumer Privacy Implications
Advertising-supported software, if done properly, is a unique and viable business model in which software developers can make money without requiring the end-user to pay for the software. However, the key words are if done properly, which is often not the case. While it may come as no surprise that adware uses your 'Net connection to download ads, you would have good reason to be concerned about the large amounts of data flowing in the other direction. Several adware applications have been known to secretly snoop around areas of your computer they don't belong, including your browser history.

As much as current spyware modules do to steal away users' privacy, they have the potential to to even more. Spyware exists as an independent, executable program on your system, and has the capability to do anything any program can do, including monitor keystrokes, arbitrarily scan files on your hard drive, snoop other applications such as word-processors and chat programs, read your cookies, change your default homepage, interface with your default Web browser to determine what Web sites you are
visiting, and monitor various aspect of your behaviour, "phoning home" from time to time to report this information back to the spyware's author. It can even notify the spyware company of any attempts to modify or remove it from the system. All the information obtained by the spyware can be used by the spyware author for marketing purposes, or sold to other companies for a profit.


In short, spyware can spy on any aspect of your computer use, and is not limited in the ways Web sites are when it comes to gathering personal data. While a Web site can gather limited demographic and statistical data automatically provided by the Web browser and Internet protocols, and read cookies set by its own domain, spyware can "see" and disclose any data on, entering or exiting your computer. This information can then be used for just about any purpose, even sold to the highest bidder!

User-Hostile Behaviour
Many adware apps install seperate advertising components on your system, that run--downloading ads and wasting sytem resources--even if you're not using the software that installed them. Often, these components remain installed and continue to perform their unsightly duties even after the associated app has been uninstalled! Some adware companies have even gone so far as to create "Advertising Trojan Horses", virus-like software programs that stealthily install themselves on your computer to perform unwanted advertising functions and violate your privacy whether you've installed the advertising-supported software or not. Advertising trojans make clandestine connections to adservers behind your back, consume precious network bandwidth and may compromise the security of your data. The latest versions of these "ad-viruses" operate in full stealth and are nearly impossible to detect without advanced knowledge of the system environment. These include theTimeSink/Conducent TSADBOT and the Aureate advertising trojans described in the Adware section. One spyware module has been known to spoof a Windows system process so that it cannot be terminated and does not appear on Windows' End Task (Ctrl-Alt-Del) dialogue.

Spyware modules have been implicated in computer problems including system slowdown, Illegal Operation errors, browser crashes, and even the "Blue Screen Of Death". While normal system stability has usually returned when the interfering spyware modules were deleted, one spyware product in particular will disable your Internet access if you try to delete it!

Potential Violations of Child Protection Laws
Most spyware-infested software is targeted toward adults. However, the user that sits down at the computer can be of any age, and the spyware modules have no good way of knowing who is at the machine and what legal protections are provided to him or her. In particular, laws in the United States prohibit the collection of personal information from children under 13 without the written permission of a parent or guardian. However, most spyware does not make any provisions for users whom they are not legally permitted to collect data from, a huge potential problem when it comes to laws such as the U.S. Child Online Privacy Protection Act (COPPA).

Security Issues
Again, since a spyware program is an independent executable program residing on your PC, it will have all the privileges of the user that installed it. On the majority of single-user systems, including Windows 95 and 98, these privileges allow software to read, write and delete files, download and install other software, change your default homepage, interrogate other devices attached to the system, or even format the hard drive. While multi-user systems such as Windows NT can limit the spyware's abilities somewhat, it can still do anything the user who installed it can--a scary thought indeed if an application containing spyware was unknowingly installed by someone with Administrator privileges.

Some spyware modules include a number of insecure features, including so-called AutoInstall or AutoUpdate functions that can secretly download and install ANY arbitrary program on the user's system. This opens the door for further abuse of the system by malicious crackers or additional spyware programs! In particular, competent security experts including Gibson Research Corp. have proven how simple it is for a malicious user to hijack this capability to upload and run ANY program on a user's system!

Do I have SpyWare On My Computer?