19 August 2006

Why I Avoid Norton AV

What's the most important thing about an antivirus scanner?

That it detects 97% rather than "only" 95% of malware in a test?
Nope, not even close.

That you can keep it updated?
Closer, but that isn't it either.

No; the most important thing is that it works.

Norton Antivirus, on the other hand, is deliberately designed to not work - if it "thinks" it's being used in breach of its license conditions.

A while back, I added a new step in the process of disinfecting systems; right at the end of the Bart CDR boot phase, after doing the scans and checking integration points, I rename away all Temp and "Temporary Internet Files" locations so that any missed malware running from there will be unreachable when I boot Windows for the first time.

Over the last few weeks, I noticed several PCs would start Windows with an "Activate Norton Antivirus" nag, usually as "Your trial period has expired". Norton AV would not only not run, but would also not provide access to its quarantine or logs of previous scans.

Generally, I just shrug, uninstall it as the useless PoS it has proven to be, and replace it with a decent free scanner that works. I'm not going to phone clients to query license status, ask for product keys, etc. and as I neither sell nor recommend Norton, I wouldn't bother to troubleshoot it further unless paid clock time to do so.

However, I did do a Google( Norton Activation ) and that was verrry interesting...

http://www.extremetech.com/article2/0,1697,1395940,00.asp

http://www.extremetech.com/article2/0,1697,1396474,00.asp

http://www.eweek.com/article2/0,1895,1779931,00.asp

...as well as plenty of forum shrieks:

http://techrepublic.com.com/5208-6239-0.html?forumID=52&threadID=175000

http://www.computing.net/security/wwwboard/forum/15607.html

http://www.mcse.ms/archive182-2005-11-1890449.html

http://forums.pcworld.co.nz/archive/index.php/t-53985.html

As usual, it's doesn't fully meet the vandor's needs even as it screws the users:

http://www.theregister.co.uk/2003/09/22/norton_antivirus_product_activation_cracked/

Symantec offers the following hoops to jump through...

http://service1.symantec.com/SUPPORT/nav.nsf/docid/2003093015493306?Open&src=w

http://service1.symantec.com/SUPPORT/custserv.nsf/docid/2004122212374346?Open&src=w&docid=2003093015493306&nsf=nav.nsf&view=docid

http://service1.symantec.com/SUPPORT/custserv.nsf/docid/2005092709273146?Open&src=w&docid=2003093015493306&nsf=nav.nsf&view=docid

http://service1.symantec.com/SUPPORT/custserv.nsf/docid/2005092311012446?Open&src=&docid=20040324164239925&nsf=SUPPORT%5Cemeacustserv.nsf&view=eedocid&dtype=&prod=&ver=&osv=&osv_lvl=

...but why should you accept this mission? Why pay scumbags who embed commercial malware within a product ostensibly designed to help you counter malware? Tackling malware is tough enough without having to worry about whether each hidden file or hook is part of Norton's self-serving un-documented user-hostile code, or some other malware.

No comments: