Sunday, October 22, 2006

Comprehensive Protection from Malware

In a way, a Windows PC can be a lot like a glass of tap water — everything may look normal on the surface, but a closer examination can reveal all sorts of hidden stuff inside. Often that stuff may be benign, but some of it can also be quite harmful. In water the contaminants may be microbes or chemicals, but on a PC it's malicious software that you need to worry about.

The Cleaner Professional Screenshot

These days there are countless unpleasant programs floating around the Internet looking for systems to infect, and it often seems as if there are almost as many programs that you can employ to help rid your computer of these infections.

The Cleaner Professional from MooSoft is one such program that tries to protect your system against a variety of threats, from spyware to keyloggers to trojans and worms. Like many similar utilities, The Cleaner Professional aims to not only ferret out existing infections but to prevent new ones as well by monitoring the changes that are made to your system. We found that The Cleaner Professional could be helpful in locating, removing, and thwarting infections, but it also suffers from a poor interface design that in many cases requires too much effort from the user.

The Cleaner Professional actually consists of three separate programs. There's the main application that scans your system for problems, and then there are two additional modules called TCActive and TCMonitor, which monitor processes in memory and the Windows Registry (respectively) in the hopes of blocking unauthorized changes and arresting damage before it occurs.

Each piece of the The Cleaner Professional is a stand-alone application that is accessed independently (both TCActive and TCMonitor have their own Windows Tray icons), and while we certainly appreciate The Cleaner Professional's thoroughness, a more integrated interface would be easier to work with than having to go to three different places to use or view the various aspects of the overall program.

System Scanning

We installed The Cleaner Professional on two Windows test systems we knew to be infected and performed a complete scan. The scans identified multiple infections on each system and offered the option to quarantine or delete them, each of which it was able to do successfully. The time necessary to scan the entire system (including hidden files and inside compressed archives) didn't seem inordinately long, though the estimated time remaining counter is too inaccurate to be helpful. (In addition to complete system scans, you can also scan any individual file via a right-click context menu option.)

Unlike some spyware cleaning tools, The Cleaner Professional doesn't flag tracking cookies, which can be troubling but usually doesn't pose a serious risk to a system.

If you want to learn more about a malicious program you just uncovered, you can consult a Trojan database accessible from within The Cleaner Professional. Alas, although the database contains what looks to be hundreds of entries, most of them offer very little information other than the specific category (i.e. adware, dialer, backdoor, etc.) the malware falls under.

Each entry also has a link to MooSoft's online database, which often contains a bit more information, but it's usually nothing more than a cursory description of what the malware does. Ultimately the database isn't as informative as it could be, and there are better resources on the Web for researching the nature of a suspicious program.

A more useful capability is The Cleaner Professional's Stealth Mode, which can randomly change the name of the program's executable files (and removes the program names from Window titles) so that they won't be recognized by malware programs that try to identify and deactivate any defensive programs you have running on your system.

System Monitoring

The first step for a malevolent piece of software to get its hooks into your system is to modify the Registry (behind your back of course). To guard against this, TCMonitor runs in the background and keeps an eye on things, flagging you whenever a Registry change is attempted.

When a change is detected, TCMonitor pops up a warning accompanied by a rather jarring siren sound that plays over and over again until you dispense with the warning. (Only one alternative sound effect is offered, though you can substitute the .wav file of your choice or dispense with the audio altogether.) TCMonitor can also notify you via e-mail, which is nice.

With TCMonitor running in the background, we set out looking for some spyware. Before long we found some, and luckily, so did TCMonitor. We also ran some of the tests available at www.spycar.org, which, among other things, attempt to modify your Registry, change your browser settings, and execute programs the way a malicious program might. In this case, TC Monitor flagged every attempt at a Registry change, but it didn't prevent many of the browser changes or program executions.

But there's another catch: While adept at detecting Registry changes, TC Monitor makes responding to them more difficult that it should be. It's initial warning tells you which Registry key is being changed, but to examine the actual change you must click a button to open another window. Moreover, since TC Monitor displays two columns that list the key's entire contents before and after the change, the potentially damaging modification isn't always immediately obvious.

If you decide that the change is unauthorized your recourse is to click a button to launch the Windows Registry Editor, which you must then use to manually delete the modification yourself. We would much prefer a single dialog that warns of the modification, displays all the relevant information, and then offers the option to accept or reject the change.

The Cleaner Professional lets you schedule your scans and even the downloading of program updates, but here too the interface leaves something to be desired. You can create a new scheduled scan or update from within The Cleaner Professional, but the program then drops you into Windows Task Scheduler to configure the day/time along with any other options.

Conclusion

The Cleaner Professional works with most versions of Windows (98, Me, 2000, XP, Vista). (There's no Mac or Linux version, but who attacks those operating systems anyway, right?) You can download a fully-functional version of The Cleaner Professional to use for a 30-days. Registering the software after the trial period will set you back a $49.99 (plus an additional $4.99 and $10.95 if you want extended download rights or a CD, respectively). The welcome dialog box offers a link to purchase the software at a 10% discount, but no such discount was applied when we followed it.

It's hard to recommend a program that requires users to jump through so many interface hoops as well as interact with standard Windows tools like Registry Editor and Task Manager. When you add that with the software's uneven performance and relatively high price tag, the final verdict is clear: There are simply more effective, user-friendly, and lower-cost options in the never-ending quest to keep malware at bay.

No comments: