Results 1 to 3 of 3

Thread: If 1 AV is good, 2 is better...right?

  1. #1
    Ex-MSFT Paul Adams's Avatar
    Join Date
    Jul 2003
    Location
    %systemroot%
    Posts
    1,926
    Thanks
    29
    Thanked
    77 times in 59 posts
    • Paul Adams's system
      • Motherboard:
      • Asus Maximus VIII
      • CPU:
      • Intel Core i7-6700K
      • Memory:
      • 16GB
      • Storage:
      • 2x250GB SSD / 500GB SSD / 2TB HDD
      • Graphics card(s):
      • nVidia GeForce GTX1080
      • Operating System:
      • Windows 10 x64 Pro
      • Monitor(s):
      • Philips 40" 4K
      • Internet:
      • 500Mbps fiber

    Post If 1 AV is good, 2 is better...right?

    Wrong.

    I've heard it argued both ways that having 2 anti-virus products running on the same machine can be better for security and worse for system stability.

    Until yesterday I assumed the worst that would happen would be to double the amount of on-access scanning done by the AV engines, and occasionally error message popping up when AV 1 puts a file into its quarantine and then AV 2 gets upset when it wanted to work with the now non-existent file.

    What happened yesterday? A visit to my wife's cousin's apartment in Stockholm, following a frantic phone call involving the words "virus", "update" and "can't use Windows".


    As it turns out there was no virus, and never had been, the story is this...

    Windows XP SP2 running "Norman" Anti-Virus and Personal Firewall (bundled with laptop purchase), connecting to the Internet by dial-up - has been operating fine for some 3 years based on the dates of various OEM folders I found.

    Friday night, while connected to the Internet, the AV product comes to update itself and throws out a spurious error about "files1.txt more than 10000 lines!".
    Fearing the worst (AV go boom now), the owner of the laptop downloaded a Norton Anti-Virus trial and installed it.

    On rebooting, Windows logged into the desktop as normal, but the Start button, task bar and system tray were unresponsive.
    Clicking any of the myriad of icons on the desktop briefly brought up an hourglass on the mouse cursor, but no program launched.

    CTRL-ALT-DEL did nothing, only the mouse cursor moved and keyboard was responding.
    (This in itself is an odd combination, as the secure attention sequence is owned by winlogon.exe and not related to explorer.exe, and should never been hooked - only unresponsive if the machine has suffered a hard lockup.)

    Booted into safe mode and everything was (within expectation) fine.
    Due diligence was taken to ensure no rootkits or other nasties were present.

    Services tab showed Norman AV services and Norton/Symantec services.
    Add/Remove Programs listed Norman AV & Personal Firewall, but trying to uninstall just reported some missing file.
    There was no Add/Remove entry for Norton to be seen.

    Set the Norman AV services to disabled (couldn't see anything obviously Norton-related) and rebooted - system now functioned.

    Not having any refernece to Norton on the system, and having disabled Norman, I installed Avast! and rebooted.
    On rebooting, Avast! warned that as it found another conflicting product - Symantec AV - it would not load all its resident protection agents.

    Found the uninstall string for Norton in the registry and tried to run it - got told the MSI package had to be launched via setup.exe.
    Hunted around and found the setup files in a temporary folder in the user profile - had to actually install Norton again as it thought it wasn't there, then rebooted an uninstalled it again via the newly-installed Add/Remove Programs entry.

    Manually eradicated all traces of Norman I could find in the registry and the disk, leaving Avast! as the system protection (connected to the Internet and updated it to make sure everything was hunky-dory).


    My assumption is this:
    Norman was running, failed to update for whatever reason, but was still running with 1-week old signatures.
    User tried to install Norton, thinking Norman was a goner - installation "kind of" worked, but there were no shortcuts or entries in Add/Remove Programs - system was now restarted (possibly had to be hard reset) and now 2 sets of AV services were battling for supremacy.

    Theory: CTRL-ALT-DEL did not bring up Task Manager as these 2 AV services were deadlocked and blocking every single new process/thread from being created while they tried to sort it out - possibly as they were both trying to set themselves as the very first entry in the IRP (I/O Request Packet) stack.

    Once either one of the services was crippled, the other could insert itself into the I/O mechanism and allow things to function again.


    The same could easily occur with multiple personal firewalls, so think twice before trying to make your system ultra-secure by making it impossible to actually do anything.
    ~ I have CDO. It's like OCD except the letters are in alphabetical order, as they should be. ~
    PC: Win10 x64 | Asus Maximus VIII | Core i7-6700K | 16GB DDR3 | 2x250GB SSD | 500GB SSD | 2TB SATA-300 | GeForce GTX1080
    Camera: Canon 60D | Sigma 10-20/4.0-5.6 | Canon 100/2.8 | Tamron 18-270/3.5-6.3

  2. #2
    Senior Amoeba iranu's Avatar
    Join Date
    Oct 2003
    Location
    On the dinner table. Blechh!
    Posts
    3,535
    Thanks
    111
    Thanked
    156 times in 106 posts
    • iranu's system
      • Motherboard:
      • Asus Maximus Gene VI
      • CPU:
      • 4670K @4.3Ghz
      • Memory:
      • 8Gb Samsung Green
      • Storage:
      • 1x 256Gb Samsung 830 SSD 2x640gb HGST raid 0
      • Graphics card(s):
      • MSI R9 390
      • PSU:
      • Corsair HX620W Modular
      • Case:
      • Cooler Master Silencio 352
      • Operating System:
      • Win 7 ultimate 64 bit
      • Monitor(s):
      • 23" DELL Ultrasharp U2312HM
      • Internet:
      • 16mb broadband
    I have heard that running two firewalls or anti-virus suites is a bad idea. I did it once to test a new program and had no problems but it's not advised.

    In my experience NAV is a really nasty aggressive piece of software. Even if you remove it from your pc in the normal add/remove programs alot of it stays behind eating system resorces. Just this week I had a friend try to sort a mates machine out where NAV was causing the problem. It also came pre-installed on a Dell machine for my old man's work, which took 5 minutes to boot on a brand new machine! It was slow as hell with 1gb of memory in. I removed NAV and installed something better, now it works like a dream. I now consider Norton AV to be malware and recommend that people stay well clear.
    "Reality is what it is, not what you want it to be." Frank Zappa. ----------- "The invisible and the non-existent look very much alike." Huang Po.----------- "A drowsy line of wasted time bathes my open mind", - Ride.

  3. #3
    Not Very Senior Member RavenNight's Avatar
    Join Date
    Aug 2005
    Location
    Somewhere with food
    Posts
    1,188
    Thanks
    5
    Thanked
    11 times in 10 posts
    Yep I too was fixing a PC with Norton this week, it reall cripples them. Not only that but it missed stuff! I ran NOD32 on it and and picked up several nasties that Norton could do nothing about. Worst of all somethiing seems to have infected the Norton system files so that Auto-pritect doesn't run, it can't be uninstalled and shoves up auto-protect isn't on messages every two minutes. It was also blocking the majority of the net, and because none of the settings worked nothing could be done about it.
    AMD 3700+ San Diego @ 2.8GHz | Zalman CNPS 9500LED + Arctic Cooling MX-1 | Asus A8N-SLi Deluxe + Zalman Northbridge | 1024MB DDR RAM (2 x 512MB Corsair XMS Pro TwinX) | Leadtek nVidia 6600GT 128MB | Creative SoundBlaster X-Fi Xtreme Music | 2x80GB Hitachi Deskstar SATA-II (RAID 0) | Gigabyte 3D Aurora Case | Hiper Type-R 580W Modular | Enermax Ultimate Fan Controller| Microsoft Nautral 4000 | Logitech G5 + fUnc 1030| Ideazon Fang | SpeedLink Medusa 5.1 Surround Headset | Samsung SM913N 19" TFT | Compro DVB-T200

    "Dell? You get better tech support with a cheese sandwich"

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Sony Ericsson P910i - how good is it as a PDA?
    By Taz in forum Smartphones and Tablets
    Replies: 9
    Last Post: 01-12-2005, 06:38 PM
  2. Heaven: Not so good??
    By BEANFro Elite in forum General Discussion
    Replies: 62
    Last Post: 11-07-2005, 04:40 PM
  3. Good PVP Players to work with..
    By TiG in forum PC
    Replies: 2
    Last Post: 27-04-2005, 12:59 PM
  4. good wireless hardware
    By DizMatt in forum Networking and Broadband
    Replies: 5
    Last Post: 24-02-2004, 10:40 PM
  5. Good Value IL-2 Hardware :)
    By Zak33 in forum PC
    Replies: 19
    Last Post: 09-01-2004, 06:11 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •