Back to glossary

Antispyware

4 min read

Antispyware is software built specifically to detect, prevent and remove spyware: programs that install without consent and quietly collect information, monitor behaviour or send data to somebody else.

July 30, 2026
Compartir:

Antispyware means programs and tools built specifically to detect, prevent and remove spyware from a system.

Spyware is malicious software that installs on a device without the knowledge or consent of the person using it, and then does things they did not ask for: collecting personal information, monitoring what they do, or sending data to a third party.

It protects privacy as much as it protects the machine, and it sits alongside antivirus and antimalware rather than replacing either.

How it works

Behavioural detection. Heuristic and behavioural techniques identify activity that looks like spyware: monitoring system activity and network interaction for the patterns this kind of software produces.

Definition updates. Like antivirus products, antispyware relies on a regularly updated database describing the characteristics and behaviour of known spyware, which is what lets it recognise recent threats.

System scanning. Full scans look for files, registry entries and configuration changes that indicate an infection, either on a schedule or on demand.

Real time protection. Many products watch continuously and block installation or execution rather than waiting for the next scan, which is the difference between finding spyware and preventing it.

A worked example

Somebody notices their computer behaving oddly: it is slow, the browser configuration has changed without them changing it, and intrusive pop-up advertising has appeared.

Suspecting spyware, they run a full scan.

The scan identifies several files and registry entries belonging to a piece of spyware, and finds that it has been collecting browsing history and sending it to external servers.

The tool removes it and recommends the obvious follow-up: keep the product updated, and be more careful about what gets installed.

Where the category stands today

Antispyware as a separate product is largely historical. What used to be sold on its own is now a function inside endpoint protection, and on most corporate estates it is one detection engine among several rather than a program somebody installs.

The problem it addressed has not disappeared, it has changed shape and got more serious. The modern equivalent is the infostealer: malware whose entire purpose is to harvest saved passwords, session cookies and browser tokens, and to send them to a market where they are sold. A stolen session cookie is worse than a stolen password, because it can bypass multi-factor authentication entirely.

The other descendant is the keylogger, which records what is typed, and which is still the simplest route from a compromised endpoint to a working credential.

The practical consequence for an organisation is that scanning for spyware is no longer the interesting control. Assuming credentials leave the endpoint, and building around that, is: short lived sessions, phishing resistant authentication, and monitoring for credentials that appear where they should not.

Where to read more

Malwarebytes, What is spyware: an explanation of what spyware is, how it works and what removes it.

Microsoft Defender documentation: how the built-in antivirus and antispyware protection in Windows is kept updated and what it covers.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.