dacs.doc electric

 

Norton AntiVirus 5.0

All Grown Up

By Jeffrey A. Setaro

 

Norton AntiVirus 5.0 BoxNORTON ANTIVIRUS HAS finally come of age. Over the years I have looked at several versions of NAV and have never been particularly impressed. So when the time came to peel the shrinkwrap off version 5.0, I did so with a host of preconceived notions. I expected to find a product with a pretty user interface that provided barely adequate virus detection. What I found instead was a product that maintains its good looks and ease of use while vastly improving virus detection. Surprise!

Norton AntiVirus detected and properly identified 99.9% of the 2,550 viruses in my test collection. It missed only one sample of TMC_Level-69. My test collection was composed of ten specimens of each of the 255 viruses contained on the August 1998 WildList.

Getting Started

Installation was a breeze. The NAV setup wizard guides you though the process of installing and configuring the program. Personally, I chose to override the default settings and not enable AutoProtect, scheduled scans, or scan at startup (under normal circumstances I would recommend that you keep the default s settings). After rebooting my PC to complete the installation, NAV launched LiveUpdate to download the latest virus definitions and program updates and then prompted me to create a set of rescue disks.

Norton AntiVirus 5.0 Screen Shot.So what is it like to use NAV? In a word-simplicity. All of NAV’s functions can be accessed from the easy-to-use interface. From the NAV main window you can access the program’s configuration
menu, choose what drives or folders to scan, manage quarantined files, or view NAV’s list of virus descriptions.

Choosing the Options button brings up a tabbed dialog where you can change settings for the program’s various functions. It is from this dialog that you choose what action Norton AntiVirus
should take when it encounters a virus. Personally I’d recommend configuring NAV’s background scanner, called AutoProtect, to deny access to any infected files.

Although it is capable of disinfecting most viruses on the fly, the main on-demand scanner provides addition information about the virus involved and allows the user to make a more informed decision about what to do with an infected file.

Once you have configured the program to work the way you want, scanning files is a breeze. Just select drives you want, scan, and click the Scan Now button. Once NAV has completed scanning
the selected drives, it will either present you with a summary screen showing the number of files scanned and the elapsed time, or if it finds a virus, its Repair Wizard will guide you through the process of repairing or quarantining infected files. If you’ve chosen to have the program automatically disinfect infected files, NAV will prepare a report showing the problems detected and the action taken. If NAV was unable to clean the infected file, you can then choose to quarantine or delete it and replace it with a clean copy from a backup.

Norton AnitVirus Quarantine Screen Shot.Probably the most interesting features of Norton AntiVirus 5.0 are its new Quarantine and Scan & Deliver functions. Essentially it works like this: If NAV locates a file that it believes is infected with a new virus or that it cannot currently disinfect, you can have it encrypt the
file and store it in a special quarantine directory somewhere on you hard drive. Then using the
Quarantine utilities’ Scan & Deliver Wizard, you can send the files over the Internet to Symantec’s Anti-Virus Research Center (SARC) for analysis. If SARC finds the file you have submitted is, in fact, infected, they will e-mail you a special set of definitions for NAV so you can repair the infected files.

Not Perfect, But Close

While I didn’t encounter any major problems with NAV, I did find a few minor ones.

First NAV does not support recursive scanning of archives. Recursive scanning means the contents of an archive (a .ZIP file, for example) are extracted and scanned into memory. For whatever reason, NAV’s designers have decided to extract archived files to a temporary directory on the hard drive and scan them there. While this isn’t strictly a problem, I would personally prefer not to have potentially infected files written to my hard drive.

Second NAV does not remind you to update your rescue disk set after updating its virus definitions.

Third, and most perplexing, was the problem I encountered with the Scan & Deliver feature. When I tried to use it to submit a sample of the Widowmaker.5747 virus to SARC, it would crash. At first I thought that particular specimen was corrupted in some way. But after trying with additional samples of Widowmaker and receiving the same result, I was left wondering what was happening. Scan & Deliver worked fine with every other file I’d thrown at it, infected or otherwise.

Bottom Line

Overall, Norton AntiVirus 5.0 provides good protection against the viruses most likely to cause people problems in the real world. Any home or small-office user who is looking for a low cost, easy-to-use anti-virus program would do well to give NAV 5.0 a look. Price: $49.95 Single User

Quick Facts

Norton AntiVirus 5.0
Symantec Corporation
10201 Torre Avenue
Cupertino, CA 95014
800-441-7234
http://www.symantec.com


JEFF SETARO wears multiple DACS caps. He is Webmaster for www.dacs.org, general program director, active board member, and resident viral disinfectant agent. Contact Jeff at jasetaro@sprynet.com.

BackHomeNext