network startup risk with Live Update

R

Randy Brook

This applies to users of Norton Antivirus with automatic Live Update.
(I don't know about other antivirus programs.) The risk is highest
with PCs/laptops connected via wireless LANs whent they go unused for
a week or more.

If you enable automatic Live Update, by default it runs NetDetect.exe
to check for new virus signatures every 4 hours. Symantec tech support
has given me conflicting info on when the 4 hours starts and if LU
runs once at startup or simply waits until the scheduled run. However,
it probably doesn't matter. Either way, NAV doesn't ever get updated a
startup.

Let's say we give Symantec the benefit of the doubt and assume it
tries to run LU on booting. Also according to Symantec, NetDetect.exe
will only run if it sees a network connection. But it takes at least
30 seconds after logon for a wireless connection to be established and
an IP address assigned by the router. So assuming NetDetect.exe LU
runs, it will not see any network present and therefor will not start
any update. There is no error message for this. Nor can you see any
evidence of an attempt to run NetDetect.exe in the Event Viewer or in
Task Scheduler.

NetDetect.exe will try again at the next scheduled time, up to 4
hours later, but by then it may be too late. You will probably have
downloaded new email and your antivirus checking will not have been
updated.

I've tried putting NetDetect into the Startup group for All users but
this doesn't seem to allow enough time for the network to connect.
Putting it into Task Scheduler to run once at system start or logon
similarly appears to be too soon.

I don't know any fix, other than to remember to run LiveUpdate
manually every time I startup a machine I haven't used in a few days.
Symantec has not seemed willing to recognize this as a risk or a
problem.
 
G

Gerald Vogt

Randy said:
This applies to users of Norton Antivirus with automatic Live Update.
(I don't know about other antivirus programs.) The risk is highest
with PCs/laptops connected via wireless LANs whent they go unused for
a week or more.
...
I don't know any fix, other than to remember to run LiveUpdate
manually every time I startup a machine I haven't used in a few days.
Symantec has not seemed willing to recognize this as a risk or a
problem.

This is the problem of any update service. If the computer is down, is
won't get updated. For example, it applies to Automatic Windows Updates,
too. It always takes a while until everything is updated. If you have a
slow internet connection and your virus, windows update and personal
firewall decide to download updates at the same time while you have
opened your e-mail program which downloads all e-mails and everything is
a couple of 100+ MBs, you can do the math: it will take a couple of
minute...

You can run netdetect every minute and it won't help you either, because
even the antivirus companies need some time to update the downloads.

Anyway, I don't see much what you could change. If it's a personal PC
you have to remember to run updates first if you have been offline for a
while. Not only AntiVirus but also Windows Update, PFW etc. That should
be the first thing to do.

In a corporate environment, the normal "personal" editions of antivirus
etc. won't do the job. You need the more expensive corporate editions
which allow for instance push updates, i.e. if a client gets back
connected to the network a server in the network will automatically push
all required updates to that server.
--
Gerald
Die neue deutsche Money-FAQ http://money.gvogt.de/

Software-Fingerprint:
01 fa 8c 7a f3 24 d7 f1 54 7b be 16 2a cc b0 61 27 15 91 71
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top