PC Review


Reply
Thread Tools Rate Thread

Another observation on the "Symantec" conflict.

 
 
=?Utf-8?B?bWVj?=
Guest
Posts: n/a
 
      17th May 2006
I have made some attempts:
If in Windows Defender, under Tools/Options/Real-time Protection Options, it

is unchecked the "Application Execution" module (only), nothing appears
anymore in the Log of "Symantec resource protector".

It would seem clear, therefore, that the conflict is caused only by the
"Application Execution" module of the Real time protection.
I hope that this a little bit helps the developers for resolving the ISSUE!
 
Reply With Quote
 
 
 
 
=?Utf-8?B?am9yaXM=?=
Guest
Posts: n/a
 
      18th May 2006
in a quick test this seems to be working for me also , only downside this way
you are lowering the defense of defenders real-time protection....

one thing is for sure the new engine 1440.0 is not helping to resolve the
problem so i think it is a difficult problem....


"mec" wrote:

> I have made some attempts:
> If in Windows Defender, under Tools/Options/Real-time Protection Options, it
>
> is unchecked the "Application Execution" module (only), nothing appears
> anymore in the Log of "Symantec resource protector".
>
> It would seem clear, therefore, that the conflict is caused only by the
> "Application Execution" module of the Real time protection.
> I hope that this a little bit helps the developers for resolving the ISSUE!

 
Reply With Quote
 
=?Utf-8?B?bWVj?=
Guest
Posts: n/a
 
      18th May 2006
A solution could be to be able to choose some exclusions (in this case for
the Symantec applications), defined by the user, for the "Application
Execution" module.

"joris" wrote:

> in a quick test this seems to be working for me also , only downside this way
> you are lowering the defense of defenders real-time protection....
>
> one thing is for sure the new engine 1440.0 is not helping to resolve the
> problem so i think it is a difficult problem....
>
>
> "mec" wrote:
>
> > I have made some attempts:
> > If in Windows Defender, under Tools/Options/Real-time Protection Options, it
> >
> > is unchecked the "Application Execution" module (only), nothing appears
> > anymore in the Log of "Symantec resource protector".
> >
> > It would seem clear, therefore, that the conflict is caused only by the
> > "Application Execution" module of the Real time protection.
> > I hope that this a little bit helps the developers for resolving the ISSUE!

 
Reply With Quote
 
=?Utf-8?B?Qml0bWFu?=
Guest
Posts: n/a
 
      21st May 2006
Let's do a quick review of this "conflict":

Symantec Resource Protection logs multiple entries indicating that Defender
is accessing some of the Symantec files.

The Defender Real-time module that performs this access appears to be the
Application Execution agent, which per WD Help; "Monitors when programs start
and any operations they perform while running."

Since the Defender AE agent would likely perform at least an md5 check to
determine if the Symantec executables are malware, this is also likely to
trigger the Symantec Resource Protection to indicate an "Unauthorized
access", which is really nothing more than a read of the file. Obviously this
is an over-reaction, but this is what the Symantec Resource Protection is
designed to do, since it didn't 'authorize' Defender's access.

At this point it appears that the result is nothing more than log entries of
these file access attempts that Symantec Resource Protection blocks and
indicates as "Unauthorized access", which sounds far more threatening than it
really is.

Since it's the Symantec Resource Protection that's deciding that Defender is
'attacking' and Defender itself seems to experience no ill effects, even due
to the block caused by Symantec Resource Protection, there doesn't appear to
be a real problem, and if there is, it's the logging of the entries by
Symantec Resource Protection.

Conclusion: Contact Symantec Support and ask them to stop detecting the
Defender file reads as an Unauthorized access, or disable the Defender
Application Execution agent (which protects from far more important things
than SRP), or disable the Symantec Resource Protection, or better yet, simply
ignore this useless false positive detection by Symantec Resource Protection.

Moral: AntiMalware that watches itself is like watching yourself twiddle
your thumbs, while your house is burning down around you.

Bitman

"mec" wrote:

> A solution could be to be able to choose some exclusions (in this case for
> the Symantec applications), defined by the user, for the "Application
> Execution" module.
>
> "joris" wrote:
>
> > in a quick test this seems to be working for me also , only downside this way
> > you are lowering the defense of defenders real-time protection....
> >
> > one thing is for sure the new engine 1440.0 is not helping to resolve the
> > problem so i think it is a difficult problem....
> >
> >
> > "mec" wrote:
> >
> > > I have made some attempts:
> > > If in Windows Defender, under Tools/Options/Real-time Protection Options, it
> > >
> > > is unchecked the "Application Execution" module (only), nothing appears
> > > anymore in the Log of "Symantec resource protector".
> > >
> > > It would seem clear, therefore, that the conflict is caused only by the
> > > "Application Execution" module of the Real time protection.
> > > I hope that this a little bit helps the developers for resolving the ISSUE!

 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
C# Outlook addin build problem: "No way to resolve conflict between "office, Version=11.0.0.0, Culture=neutral, PublicKeyToken=71e9bce111e9429c" Hans Merkl Microsoft Outlook Interoperability 0 1st Feb 2006 02:47 AM
Driver conflict "Logitech QuickCam Fusion" vs. "TV Studio 2000". What Should I do? Neno Windows XP Help 0 24th Oct 2005 05:09 AM
"Conflict Message" dialog without any items to "keep" Keir Microsoft Outlook 0 10th Aug 2005 06:45 PM
Registry -- removing all "norton" and "symantec" Dick M. Windows XP General 6 11th Oct 2004 05:24 AM
Interesting observation - WinXP Professional "Upgrade" Richard Urban Windows XP General 5 2nd Oct 2004 04:50 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 10:23 AM.