Applications detected by CA Anti-Spyware are evaluated against the characteristics listed below. These criteria describe behaviors that are typical of Spyware and which may cause a loss of productivity, privacy and security. When evaluating logical expressions, all uses of “or” are non-exclusive unless otherwise noted. Detailed information describing behaviors and attributes referenced within this Scorecard can be found in the “Behaviors - the Building Blocks of Spyware Analysis” document at http://www.ca.com/us/securityadvisor/content.aspx?cid=95576 and the "Attributes - Modifying Behaviors" document at http://www.ca.com/us/securityadvisor/content.aspx?cid=95579. Note: Solely for the purposes of this Scorecard, acceptance or acknowledgement of a product’s end-user license agreement (EULA) or Privacy Policy does not constitute user permission, user knowledge or user consent. For guidelines on what does constitute user permission see the document “Spyware, Adware and User Permission: Meeting CA Anti-Spyware’s Requirements” at http://www.ca.com/us/securityadvisor/content.aspx?cid=67985.
- Installs even when the user selects "no" or equivalent negative response when prompted or questioned about installing the application.
A program fails this item when, without obtaining user permission, it takes the following action:
- Installs itself or any other item without clear notice to user and obtaining user permission at time of installation.
A program fails this item when, without obtaining user permission, it takes any of the following actions:
- Installs itself without providing clear and explicit opt-out option from vendor’s site or associated application.
A program fails this item when, without obtaining user permission, it takes the following action: Or takes the following action with or without obtaining user permission:
- Changes browser settings without clear notice to the user and obtaining user permission at the time of change.
A program fails this item when, without obtaining user permission, it takes one of the following actions:
- Changes system configuration in any manner without clear notice to the user and obtaining user permission at the time of change.
A program fails this item when, without obtaining user permission, it takes one of the following actions: - Proxies, redirects or relays the user’s network traffic or modifies the networking stack to send traffic through a third-party server (D1)
- Creates or modifies "hosts" file to divert domain reference (D2)
- Changes default networking settings (Broadband, telephony, wireless, etc.)(D3)
- Hides files, processes, program windows or other information from the user or from other programs (F1)
- Allows remote parties to read local files/registry entries/other data (F8)
- Allows remote parties to modify or delete local files/registry entries/other data (F9)
- Allows remote parties to identify vulnerabilities on the host (F10)
- Allows remote parties to execute arbitrary code on the local system (F11)
- Allows remote parties to take limited actions on a local system (F12)
- Disables or removes security software, such as AntiVirus or Firewall software (F13)
- Lowers security settings, such as in the browser, application, or operating system (F14)
- Allows for remote control of the application, beyond self-update (F15)
- Replaces or otherwise alters web page content beyond search results or advertisements (F16)
- Replaces or otherwise alters web page content related to search results or advertisements (H4)
- Changes system or application settings not enumerated elsewhere in such a way as to reduce user control (I1)
- Changes browser error page (I2)
- Changes browser home page (I3)
- Changes browser search page (I4)
- Changes browser settings unrelated to security (I5)
- Changes browser settings related to security(I6)
- Modifies user settings such as favorites, icons, shortcuts, etc. (I7)
- Disables or interferes with functionality of system (M4)
- Creates or modifies "hosts" file to divert domain reference without clear notice to the user and obtaining user permission at time of change.
A program fails this item when, without obtaining user permission, it takes the following action:
- Defends itself against removal of, or changes to, its components.
Takes any of the following actions: - Dials phone numbers or holds connections open without clear notice to the user and obtaining user permission.
A program fails this item when, without obtaining user permission, it takes the following action:
- Displays popup/popunder ads when product is not actively in use, or which do not appear to be connected with the product.
A program fails this item when it takes the following action: Or with attribute XXIII (Behavior occurs when the program is not in active use) takes any of the following actions:
- Displays popup/popunder ads that cannot be closed by clicking a clearly visible close button.
With Attribute XIX (Actively defends the results of an action, such as continually re-writing changed settings) or Attribute XX (Passively defends the results of an action, such as not offering a visible way to close a popup window), takes any of the following actions: - Updates itself or any other item without clear notice to the user and obtaining user permission at time of update.
A program fails this item when, without obtaining user permission, it takes any of the following actions:
- Transmits User Data without clear notice to the user and obtaining user permission.
A program fails this item when, without obtaining user permission, it takes any of the following actions:
- Covertly modifies another program’s information or website content as displayed – for example, changing search results, substituting ads for other ads, etc.
A program fails this item when, without obtaining user notice, takes any of the following actions:
- Covertly tracks input or personally identifiable information without clear user permission.
A program fails this item when, without clear user permission, it takes any of the following actions:
- Violates or bypasses the user rights schema inherent to the computer's operating system without clear notice to each user and obtaining permission of each of the system users who are being impacted.
A program fails this item when, without obtaining user permission on the part of the system owner/administrator and each user account impacted, takes any of the following actions:
- Cannot be uninstalled by Windows Add/Remove Programs and no uninstaller is provided with application.
A program fails this item when, without Attribute XVI (Program is a single executable file without installer and does not create registry keys at all, or create files outside of its immediate folder), it takes the following action:
- Uninstaller is actually a covert re-installer.
A program fails this item when it takes both of the following actions:
- Uninstaller leaves potentially damaging running objects, executables, or other components after reboot.
A program fails this item when it takes the following action:
- Interferes with the regular operation of another program without obtaining user permission.
A program fails this item when, without obtaining user permission, it takes any of the following actions: - Uninstalls other applications, for example, competitor’s programs (A9)
- Hides files, processes, program windows or other information from the user or from other programs (F1)
- Lowers security settings, such as in the browser, application, or operating system (F14)
- Replaces or otherwise alters web page content beyond search results or advertisements (F16)
- Replaces or otherwise alters web page content related to search results or advertisements (H4)
- Changes system or application settings not enumerated elsewhere in such a way as to reduce user control (I1)
- Changes browser error page (I2)
- Changes browser home page (I3)
- Changes browser search page (I4)
- Changes browser settings unrelated to security (I5)
- Modifies user settings such as favorites, icons, shortcuts, etc. (I6)
- Modifies or injects code in the memory space of other running applications (J1)
- Modifies unrelated executable files on disk (J2)
- Attaches to other programs, such as the browser, using a non-standard method (M3)
- Displays behavior which harms or attacks another system or creates software that will harm or attack another system.
A program fails this item when, without obtaining user permission from the owner/operator of the system being targeted by the behavior, takes any of the following actions:
- Uses misleading, confusing, deceptive, or coercive text or graphics text, graphics, advertising or other false claims to induce, compel, or cause users to install or run the software or take actions (such as click on an advertisement)
- A program fails this item when it takes the following action:
Scorecard Ownership and Responsibility
CA Anti-Spyware is solely responsible for the creation, interpretation, and application of this scorecard and its use in the determination of what products and/or programs are classified as Spyware.