Re: How to turn off the "File System Real-time Protection" in Symantec Antivirus Corporate Edition?

From: cquirke (MVP Win9x) (cquirkenews_at_nospam.mvps.org)
Date: 04/28/04


Date: Wed, 28 Apr 2004 13:39:16 +0200

On Wed, 28 Apr 2004 13:30:36 +0400, "Dmitriy Kopnichev"

>I don't work with administrator rights all the time,

<shrug>

>I install all critical updates,

Good ;-)

>I antivirus check all incoming files.

Nice, FWIW.

>How could a virus run on my computer?

Let me count the ways:
  - because it's too new for the av to detect
  - because there's a missed frontier point thru which stuff comes
  - exploitation of an uptached hole (negative time-to-exploit)
  - on-demand av limitations of malware scanning

The last is a biggie, in the current age of pwd-encrypted .zip that
can't be scanned until they start to unpack themselves.

Put it this way; if this were to happen (or circumstances arose where
this was suspected) and you were the only PC on the system with
real-time av disabled, you'd be on the back foot. All the more so if
you'd used tech steps to subvert the risk policy intended by the org.

I'd have to have a really compelling reason to go there, and I don't
think the paltry speed gains from avoiding resident av would be wirth
it. Either the resident av really sucks, or your PC is old and slow,
and if the latter, then leave as-is to motivate for a faster PC :-)

Tip: When org ppl phone you, you can say things like "hang on... just
waiting for it to load..." etc. whenever you have to look something
up. After a while, they'll get the picture <g>

>The administrator doesn't like me and doesn't know how to turn off the
>mandatory "File System Real-time Protection" for my computer. The
>administrator who turned on doesn't work here anymore.

Hm. Lots of stories there, I'd bet.

<hippo-chomp of accumulated quotage>

>-------------------- ----- ---- --- -- - - - -
  Running Windows-based av to kill active malware is like striking
  a match to see if what you are standing in is water or petrol.
>-------------------- ----- ---- --- -- - - - -



Relevant Pages