Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


April 2005

Spyware Hunters

5 enterprise antispyware weapons protect you from bombardment
RSS
Subscribe to Windows IT Pro | See More Antivirus Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
SideBar    Not Ready for Prime Time, Microsoft’s GIANT Potential

I'm responsible for maintaining the reliability and security of a fleet of corporate PCs, and spyware is the new bane of my existence. Of course, spyware is only one of a handful of new threats to my sanity and the systems I support, and the very term spyware encompasses a variety of threats—including adware, snoopware, and malware, as Joseph Kinsella describes in "Put a Stop to Spyware," March 2005, InstantDoc ID 45268. For the sake of simplicity, in this comparative review of enterprise-ready antispyware tools, I'll use the term "spyware" to refer to all non-virus system intrusions that form this class of threats. To participate in this review, products needed to offer antispyware functionality including but not limited to automated client-agent deployment, centralized management and reporting, and automated threat scanning and removal.

In this comparative review, I take a look at five enterprise-ready antispyware tools—Computer Associates' (CA'S) eTrust PestPatrol Anti-Spyware Corporate Edition, FutureSoft's DynaComm i:scan, Omniquad's AntiSpy Enterprise Edition, Sunbelt Software's CounterSpy Enterprise, and Tenebril's SpyCatcher Enterprise. I was eager for the opportunity to review these products, which have been—in many cases—a long time coming. Administrators and users everywhere will likely welcome them with open arms. If you're wondering whether the antivirus heavyweights are joining the anti-spyware fight, the answer is yes, but at press time neither Symantec nor McAfee could participate in the review. See the sidebar "Not Ready for Prime Time" for a discussion of the enterprise antispyware offerings that we were unable to include in this review. And for information about Microsoft's recent foray into the antispyware space, see the sidebar "Microsoft's GIANT Acquisition."

How I Tested
To test these enterprise antispyware products, I created a group of four client systems and one server to act as the console and centralized management point for each product. The clients all ran Windows XP Service Pack 1 (SP1), with the exception of one system that had SP2 installed. The console system ran Windows Server 2003. Before testing any products, I installed and tracked varying collections of spyware on the client systems. After polluting the clients, I took a disk image of each system, which I used to restore the clients to their fully infected state for each product test.

See associated table

eTrust PestPatrol AntiSpyware Corporate Edition
CA acquired PestPatrol in late 2004 and has added the product to its eTrust line of solutions. The components of PestPatrol are the Management Console, the Workstation Agent, the command-line scanner, and the Active Protection module. You can install the Management Console on any Pentium-based system running Windows 2003, Windows XP Professional, or Windows 2000.

I installed the console and the included PDF-format Network Administrator's Guide on the management server in less than 1 minute, then launched the software from the Start menu. Upon launch, the software notified me that new updates were available and gave me the option of downloading them immediately. After the update, the console screen opened, as Figure 1 shows. I did a quick scan of the test clients with the Log only option selected, and PestPatrol displayed all detected pests. Next, I selected the Quarantine option for detected pests and rescanned. I switched to the View logs/Clean pests tab to delete the quarantined items. While viewing either logs or quarantined items, I could double-click an entry to view more threat-specific information, contained in the product's online Pest Encyclopedia.

The software couldn't quarantine some of the detected pests, and the log told me to scan with the Delete option selected to remove those items. When I scanned once more with the Delete option selected, the software removed the remaining pests. The log files for both Quarantine and Delete operations recommended a reboot of the client workstation to finish the removal process.

I also tested PestPatrol's scheduling, exclusion, notification, and update features. I configured the client systems to run a full scan of memory, cookies, registry, and disk drives once a week and scheduled a less intensive scan to run every day. The process of scheduling client scans is straightforward, and the scans proceeded without problems on my test systems. Because the software might unintentionally identify some legitimate software as a threat, PestPatrol lets you create a list of items you want to exclude from a scan to avoid unintentional software quarantine or removal. I added Virtual Network Computing (VNC) to the list of exclusions in my test environment, and PestPatrol no longer identified it as a pest. Email alerting worked as I expected, although I would have appreciated more configurable message options. The PestPatrol console checks for updates each time you open it, and you can also manually check for updates from within the console. When the software downloads updates to the console, you must push them out to the clients. The option of scheduling both central-console and client updates would provide for better protection and less administrative interaction.

PestPatrol is an easy-to-use product that does a good job of detecting and removing spyware. CA could improve the console interface by adding simple selection and sorting enhancements. A console-managed command-line version of PestPatrol supports down-level clients such as Windows 98, but I didn't test this functionality.

eTrust PestPatrol AntiSpyware Corporate Edition
Contact: Computer Associates * 888-423-1000
Web: http://www.ca.com
Price: $23 per user for 100 users; volume discounts apply
Summary
Pros: The size of the company benefits R&D; client deployment is simple; threat detection and removal are above average
Cons: Reporting mechanisms aren't thorough or flexible
Rating: 3.5 out of 5
Recommendation: A close runner-up in our tests. The product's user-friendly console functioned well. PestPatrol is a good option if you need to support Windows 9x clients.


DynaComm i:scan
FutureSoft was in the midst of a DynaComm i:scan product revision at the time of my testing. The enterprise product I tested addressed the criteria I specified, but it didn't incorporate registry-based and memory-based threat scanning. The personal version of DynaComm i:scan, however, contained these features. Assured by FutureSoft that registry-scanning and memory-scanning features would soon be part of the enterprise product, I agreed to a hybrid test, using the personal client to evaluate the spyware detection and removal capabilities.

When I installed the enterprise version of DynaComm i:scan, the software prompted me to specify the users who would have permission to use the product. You can populate the list of users from the domain or an individual system. The software then prompted me for an account under which the DynaComm i:scan service would run. After providing an account for the DynaComm i:scan service, the installation finished and I rebooted the server.

DynaComm i:scan's antispyware features are a subset of its overall content-security focus. The product is designed to scan storage throughout your enterprise, categorize the files it finds and—optionally—take action when it finds certain types of files. Actions range from logging to moving or deleting a file. File signatures identify problem files. The product includes a database of file signatures for spyware, as well as a collection of predefined scans (which Figure 2 shows) that look for files matching one or more file signatures. DynaComm i:scan gives you a great deal of control over file signatures, letting you create your own list of spyware or other types of offending files.

The first time I ran the Find Malware scan from the console, the product installed client service software on the targeted clients. The client service software, which runs on Windows NT and later, performs scanning locally on the client and provides configurable real-time monitoring and protection. (You can use the product to scan Win9x systems, but on Win9x systems, the console performs the scan over the network, consuming both network and console-server bandwidth.) The scan results showed numerous files that fit DynaComm i:scan's predefined malware signatures. I opened the file-scan log viewer, and by right-clicking identified files in the list I could choose to open, copy, move, or delete the items.

Although the enterprise version of DynaComm i:scan detected a number of disk-based spyware infections, I had to run the personal edition to gauge how DynaComm i:scan stacked up against the competition in terms of disk, memory, and registry threat detection and removal. DynaComm i:scan wields a lot of power, but along with the functionality comes a bit more complexity than you probably want to deal with if you're after a dedicated antispyware solution. In the end, DynaComm fared the worst in handling disk-based threats and second worst in handling registry threats, but I'm deriving these figures from the standalone tool.

DynaComm i:scan
Contact: FutureSoft * 800-989-8908
Web: http://www.futuresoft.com
Price: $27 per user for 100 users; volume discounts apply
Summary
Pros: The file-management application is flexible and powerful; the product boasts polished enterprise features
Cons: DynaComm i:scan doesn't do the job as a turnkey solution for spyware
Rating: 3 out of 5
Recommendation: DynaComm i:scan offers extended functionality for managing files but requires up-front knowledge.


   Previous  [1]  2  3  Next 


Reader Comments
Interesting the the current #1 Enterprise Anti-Spy product (Webroot Spysweeper Enterprise) was left out of this review. How could you leave this product out?

Anonymous User March 30, 2005 (Article Rating: )


Why would a review leave out the Top selling Top performing and oldest enterprise Anti Spyware solution (Spy Sweeper) It is easy to be rated #1 when you are not compared against the cream of the crop

Anonymous User March 30, 2005 (Article Rating: )


I am curious why Webroot's Spy Sweeper Enterprise was NOT included in the review? Several other IT trade magazines DID include Spy Sweeper Enterprise in their reviews.

Anonymous User March 30, 2005 (Article Rating: )


How about InterMute's SpySubtract Enterprise. Easily the best as far as my testing goes. I believe when you do a bkaeoff you should test all of the products. It is easy to see why the Sunbelt product won this test as the other 4 tested are very weak.Does Sunbelt invest in your you company? The reason I am asking is becuase with these 5 products tested it seems like you fixed the fight so SunBelt could win.

Anonymous User March 30, 2005 (Article Rating: )


This seems like a very minimal "evaluation" considering you aren't including leading products, and you don't have any metrics...looks like you don't know a whole lot about the market.

Anonymous User March 30, 2005 (Article Rating: )


LOL...this review is funny...i love all the extra comments that basically are calling you on it.....looks like another biased article written by someone that doesn't get it.

Anonymous User March 30, 2005 (Article Rating: )


Another point that should be included concerning Counterspy Enterprise is that the product does not support terminal services. The author makes no mention of it although it stands out like a sore thumb on their download page. Doesn't sound like an enterprise edition to me.

Anonymous User March 30, 2005 (Article Rating: )


A waste of my time to read. There is nothing in this article telling me what the PC was infected with, nor what was missed by each product. The lack of Webroot Spysweeper Enterprise is a glaring omission. The sections on each product are inconsistant. This "article" needs to be revised or pulled immediately.

Anonymous User March 30, 2005 (Article Rating: )


Of the five products tested only one is a major vendor in the field. While the product evaluations were interesting, I think the comparisons are flawed. One product was in beta testing while another product was based on an enterprise version that didn't exist yet (DynaComm i:scan). Comparing mature products to unreleased products seems like an imbalanced test.
Still, the testing procedures were sound and the information interesting.
-Mauricem

Anonymous User March 30, 2005 (Article Rating: )


Am I the only one who thinks "Anonymous User" works for Webroot? This wasn't meant to be a comprehensive duke-it-out review, sounds to me like a quickly comparison against what was at hand... Making your purchase decision based on this single "review" would be silly!

DrestinBlack March 30, 2005 (Article Rating: )


 See More Comments  1   2   3 

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
WinInfo Short Takes: Week of November 24, 2008

An often irreverent look at some of the week's other news, including a Vista Capable dismissal request, Zune price reductions, Morrow musings, Novell and Microsoft sitting in a tree ... two years later, Yahoo!, IE 6 on Windows Mobile, and so much more ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

PsExec

This freeware utility lets you execute processes on a remote system and redirect output to the local system. ...


Security Whitepapers The Impact of Messaging and Web Threats

Why SaaS is the Right Solution for Log Management

Protecting (You and) Your Data with Exchange Server 2007

Related Events SQL Server 2008 – Can You Wait? | Philadelphia

SQL Server 2008 – Can You Wait? | Atlanta

SQL Server 2008 – Can You Wait? | Chicago

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing