Norton AntiVirus
File:NortonAntiVirus Icon.png | |
Developer(s) | Symantec Corporation |
---|---|
Stable release | 2011 or 18.1.0.37 (Windows Edition), 11.1.1 (Mac Edition)
/ 31 August 2010 |
Operating system | Microsoft Windows (Microsoft Windows 7, Windows Vista, and Windows XP), Mac OS X |
Type | Antivirus |
License | Proprietary |
Website | symantec.com/norton/antivirus |
Norton AntiVirus, developed and distributed by Symantec Corporation, provides malware prevention and removal during a subscription period. It uses signatures and heuristics to identify viruses. Other features include e-mail spam filtering and phishing protection.
Symantec distributes the product as a download, a box copy, and as OEM software. Norton AntiVirus and Norton Internet Security, a related product, held a 61% US retail market share for security suites as of the first half of 2007. Competitors, in terms of market share in this study, include antivirus products from CA, Trend Micro, and Kaspersky Lab.[1]
Norton AntiVirus runs on Microsoft Windows and Mac OS X. Version 17.5.0.127 is the latest Windows build.[2] Windows 7 support is in development for versions 2006 through 2008. Version 2009 has Windows 7 supported update already. Version 2010 natively supports Windows 7, without needing an update. Version 11.1.1 is the latest Mac build.
Windows edition
In August 1990 Symantec acquired Peter Norton Computing from Peter Norton.[3] Norton and his company developed various utilities, or applications for DOS, including an antivirus. Symantec continued the development of acquired technologies. The technologies are marketed under the name of "Norton", with the tagline "from Symantec". Norton's crossed-arm pose, a registered U.S. trademark, was traditionally featured on Norton product packaging.[4] However, his pose was later moved to the spine of the packaging, and eventually dropped altogether.[5]
Product activation was introduced in Norton AntiVirus 2004, addressing the estimated 3.6 million counterfeit Norton products sold. An alphanumeric code is generated to identify a computer's configuration, which ties in with the product key. Users are allowed to activate their product five times with the same product key.[6] Spyware and adware detection and removal was introduced to the 2005 version, with the tagline "Antispyware Edition".[7] The tagline was dropped in later releases. However, Norton AntiVirus 2009 Classic does not include spyware or adware detection. The Classic edition is marketed alongside Norton AntiVirus 2009, which does include spyware and adware detection.
Existing users of the 2006, 2007, 2008 and 2009 versions can upgrade to the latest 2010 version without buying a new subscription. Upgrading will preserve the number of days left on a user's subscription.[verification needed][8]
Version 2006 (13.0)
The redesigned main graphical user interface aggregates information in a central user interface.[9] CNET reports the Norton Protection Center, while useful, attempts to advertise additional products. To further facilitate detection of zero-day malware, Bloodhound disassembles a variety of programming languages, and scans code for malicious instructions using predefined algorithms.[10] Internet Explorer homepage hijacking protection was introduced in this release as well; however notably missing is search engine hijacking protection. CNET highlighted Norton AntiVirus 2006's noticeable impact on system performance.[9]
Operating system requirements call for Windows 2000 Service Pack 3 or Windows XP. 150 MB of free space and a 300 MHz processor is required under either operating system. 128 MB of RAM is required under Windows 2000, while 256 MB is required in Windows XP.[9]
Version 2007 (14.0)
Norton AntiVirus was released on September 12, 2006.[11] Symantec revised Norton AntiVirus with the goal of reducing high system resource utilization.[12] Windows Vista compatibility was introduced in this release as well. Despite having about 80% of the code rewritten, CNET reports mixed results in performance testing.[13] New features include a tabbed interface, eliminating the need to have separate windows open for the Norton Protection Center and for configuring the settings.[13] Symantec extended its Veritas VxMS rootkit detection technology, allowing Norton AntiVirus 2007 to inspect files within directories to files on the volume level, detecting abnormalities or inconsistencies.[13]
Windows 2000 compatibility was dropped from this release. Compatibility with 32-bit versions of Windows Vista was added to this release with a patch from Symantec. Hardware requirements under Vista call for 150 MB free space, a 800 MHz processor and 512 MB RAM. Requirements under Windows XP similarly call for 150 MB free space, a 300 MHz processor, and 256 MB of RAM.
Version 2008 (15.0)
Norton AntiVirus 2008 was released on August 28, 2007. Emphasizing malware prevention, new features include SONAR, which looks for suspicious application behavior. This release adds real-time exploit protection, preventing attackers from leveraging common browser and application vulnerabilities.[14][15]
When installed in 32-bit versions of Windows XP Service Pack 2, 300 MB of free space, a 300 MHz processor, and 256 MB of RAM is required. When installed in 32-bit and 64-bit versions of Windows Vista, 300 MB of free space, a 800 MHz processor, and 256 MB of RAM is needed.
Version 2009 (16.0)
Norton AntiVirus 2009 was released on September 8, 2008. Addressing performance issues, over 300 changes were made, with a "zero-impact" goal.[16][17] Benchmarking conducted by Passmark Software PTY LTD highlights its 47 second install time, 32 second scan time, and 5 MB memory utilization. It should be noted Symantec funded the benchmark test and provided some scripts used to benchmark each participating antivirus software.[18]
The security status and settings are now displayed in a single main interface. A CPU usage monitor displays the total CPU utilization and Norton's CPU usage in the main interface. Other features include Norton Insight, a whitelisting technology which cuts scanning times by mapping known safe files using information from an online database. [19] To address malware response times, updates are delivered updates 5 to 15 minutes. However, such updates are not tested by Symantec, and may cause false positives, or incorrectly identify files as malicious. The exploit scanner found in the 2007 and 2008 versions was dropped from this release.
When installed in 32-bit versions of Windows XP Service Pack 2, 150 MB of free space, a 300 MHz processor, and 256 MB of RAM is required. When installed in 32-bit or 64-bit versions of Windows Vista, 150 MB of free space, a 800 MHz processor, and 512 MB of RAM is required.
Gaming and Classic Editions
Two variations on Norton AntiVirus 2009 are also marketed by Symantec. The Gaming edition provides finer control over when Norton downloads updates and allows components of the suite to be disabled either manually or automatically when the computer enters full-screen mode.
The Classic edition cannot find or remove adware and spyware.
Version 2010 (17.0)
Version 17.0 was released on September 9, 2009.[20] Several features have been updated in this release, including SONAR, now dubbed SONAR 2. It now uses more information to determine if an application is truly malicious. Norton Insight can present users with information about the origins, activities, and performance of applications along with reputation data.[20] A new feature codenamed Autospy helps users understand what Norton did when malware was found. Previous releases removed threats on sight and quietly warned users, potentially confusing when users are deceived in downloading rogue security software. Much of this information is placed on the back of the main window; a toggle button switches between the sides.[21] Symantec has also added Windows 7 support. Aside from that, Symantec has also added the Norton Download Insight to prevent drive by drive downloads.
Version 2011 (18.0)
Norton AntiVirus 2011 Beta was released on April 21, 2010. Changes include a new user interface and improved scanning of internet sites for malware. With the 2011 version, Symantec also released an application that "scans" the user's Facebook feed for any malware links. This application does not require a valid subscription.[22] The final version of Norton AntiVirus 2011 was released on August 31, 2010.
Macintosh edition
Norton AntiVirus 11 for Mac introduced support for Mac OS X v10.5 Leopard platform, with the capability to detect both Macintosh and Windows malware. Other features include a vulnerability scanner, which blocks attackers from leveraging software exploits.[23] Norton AntiVirus 11 also includes the ability to scan within compressed or archived files, such as Time Capsule volumes. Operating requirements call for Mac OS X Tiger.[24] A PowerPC or an Intel Core processor, 128 MB of RAM, and 100 MB of free hard disk space are also required. Norton AntiVirus Dual Protection for Mac is intended for Macintosh users with Windows running on their systems, using Boot Camp or virtualization software such as VMWare Fusion. It provides a license for both Norton AntiVirus 11 with Norton AntiVirus 2009.[25][26]
Criticisms
FBI cooperation
The FBI confirmed the active development of Magic Lantern, a keylogger intended to obtain passwords to encrypted e-mail and other documents during criminal investigations. Magic Lantern was first reported in the media by Bob Sullivan of MSNBC on 20 November 2001 and by Ted Bridis of the Associated Press.[27][28] The FBI intends to deploy Magic Lantern in the form of an e-mail attachment. When the attachment is opened, it installs a trojan horse on the suspect's computer, which is activated when the suspect uses PGP encryption, often used to increase the security of sent e-mail messages. When activated, the trojan will log the PGP password, which allows the FBI to decrypt user communications.[29][30] Symantec and other major antivirus vendors have whitelisted the Magic Lantern trojan, rendering their antivirus products, including Norton AntiVirus, incapable of detecting it. Concerns around this whitelisting include uncertainties about Magic Lantern's full surveillance potential and whether hackers could subvert it and redeploy it for purposes outside of law enforcement.[31][32]
Graham Cluley, a technology consultant from Sophos, said "We have no way of knowing if it was written by the FBI, and even if we did, we wouldn’t know whether it was being used by the FBI or if it had been commandeered by a third party".[33] Another reaction came from Marc Maiffret, chief technology officer and cofounder of eEye Digital Security who states: "Our customers are paying us for a service, to protect them from all forms of malicious code. It is not up to us to do law enforcement's job for them so we do not, and will not, make any exceptions for law enforcement malware or other tools."[34]
Proponents of Magic Lantern argue the technology would allow law enforcement to efficiently and quickly decrypt time-sensitive messages protected by encryption schemes. Implementing Magic Lantern does not require physical access to a suspect's computer, unlike Carnivore, a predecessor to Magic Lantern, since physical access to a computer would require a court order.[35] FBI spokesman Paul Bresson, in response to a question about whether Magic Lantern also needed a court order to deploy, would only say "Like all technology projects or tools deployed by the FBI it would be used pursuant to the appropriate legal process."[36][37]
Updates kill legitimate software
The January 28, 2010 Symantec Anti-virus update marked Spotify as a Trojan horse disabling the software across millions of PCs. [1] [2]
Product support
Retail customers report slow and indifferent service on bugs. Examples include a faulty error message stating current subscriptions had expired.[38] Users received an error stating "Your virus protection cannot be updated." This error occurred after an update to the software and refused to allow daily updates.[38] Though the bug was reported in 2004, it was not corrected for the 2005 or 2006 versions.
Another incident occurred in May 2007, when Norton Antivirus flagged components of the Pegasus e-mail client as malicious, rendering the program corrupted.[39] Symantec customer service addressed the problem by running through a checklist of troubleshooting steps which were not always successful.
Faulty update
On July 25, 2006, Symantec released a faulty update for Norton AntiVirus 2006 users. Users reported an onscreen message stating "Norton AntiVirus 2006 does not support the repair feature. Please uninstall and reinstall.".[40] Symantec claimed the faulty update was downloaded to customers between 1:00 PM and 7:00 PM on July 25, 2006. Symantec developed a workaround tool and has listed troubleshooting steps, available here. The company released a statement, stating they expected to deliver a repair patch to affected users by Monday, July 31, 2006." [41]
Uninstallation
Norton AntiVirus has been criticized for refusing to uninstall completely, leaving unnecessary files behind.[42][43] Another issue is versions prior to 2009 installed LiveUpdate, which updates Norton-branded software, separately. The user must uninstall both Norton AntiVirus and the LiveUpdate component manually. The LiveUpdate component is purposely left behind to update other Norton-branded products, if present.[44] In response, Symantec developed the Norton Removal Tool to remove leftover registry keys and values along with files and folders.[45] However, neither route of uninstallation will remove subscription data, preserved to prevent users from installing multiple trial copies.
Incompatibilities with ZoneAlarm
Norton AntiVirus 2007 will not install alongside ZoneAlarm. This incompatibility has caused annoyance for Norton customers who purchased Norton AntiVirus 2007 with no prior warning or notice of the incompatibility.[46] Symantec recommends removing ZoneAlarm, then reinstalling it with its Internet Worm Protection feature disabled, which controls what applications can access the Internet and which protocols they can use to do so.
PIFTS.exe
On March 9, 2009, some users of Norton AntiVirus 2006 and 2007 experienced a firewall warning stating a Norton-associated file, "PIFTS.exe", was trying to connect to the Internet.[47] Although this file was revealed to be a harmless diagnostic patch, the program gained attention in the media when Symantec removed posts from their forum concerning PIFTS. With no information available about the purpose of the program there was speculation that the program was malware or a backdoor.[48]
The SANS Internet Storm Center claimed to have spoken to a Symantec employee who has confirmed that "the program is theirs, part of the update process and not intended to do harm."[49] Graham Cluley, a consultant from antivirus vendor Sophos found PIFTS connected to a Symantec server, forwarding product and computer information.[50]
On March 10, Symantec made an official response to the PIFTS program, claiming posts in the support forum were deleted due to forum spam rules; however the deletion of PIFTS-related posts began before the spam attacks.[51] Symantec stated PIFTS itself was a diagnostic patch.[48] Cole stated the purpose of the update was to help determine how many customers would need to be migrated to Windows 7-compatible versions of Norton AntiVirus. PIFTS apparently was released without a digital signature to verify its identity, causing firewalls to prompt for permission when it attempted to connect to the Internet.[52]
Consumer complaints
Symantec has been criticized for many ethical violations, mainly in its India support branch, whereby support technicians would tell customers inquiring about certain issues that their systems were infected and therefore needed a technician to remove it remotely for an extra fee of 99 euros, and refuse to refund when, as in almost all cases, their systems were not infected.[53]
See also
References
- ^ "Channel Best-Sellers: Winning Security Players". CRN Staff. United Business Media LLC. November 23, 2007. Retrieved 2009-03-09.
- ^ "NAV/NIS 2009.5 Patch Update [ Edited ]". Tim Lopez. Symantec Corporation. March 19, 2009. Retrieved 2009-03-13.
- ^ "COMPANY NEWS; Symantec to Acquire Peter Norton". Lawrence M. Fisher. The New York Times Company. May 15, 1990. Retrieved 2009-03-30.
- ^ "Legal Notice - Symantec Canada". Symantec Corporation. Retrieved 2009-03-30.
- ^ "SYMANTEC BRAND IDENTITY" (PDF). frog design inc. Retrieved 2009-03-30.
- ^ "Symantec adds product activation". David Becker. CBS Interactive Inc. August 26, 2003. Retrieved 2009-03-31.
- ^ "Norton Internet Security 2005 Antispyware Edition". Robert Vamosi. CBS Interactive Inc. April 18, 2005. Retrieved 2009-03-30.
- ^ "The Norton Update Center". Symantec Corporation. Retrieved 2009-03-18.
- ^ a b c sralls (October 3, 2005). "Norton AntiVirus 2006 Internet security and firewall reviews - CNET Reviews". Reviews.cnet.com. Retrieved 2009-02-23.
- ^ "Bloodhound". Symantec. Retrieved 2009-02-23.
- ^ "Symantec's Norton AntiVirus 2007, Norton Internet Security 2007 Provide State-Of-The-Art Security and Performance to Protect Against Today's Newest Threats". 09-12-2006. Retrieved 05-29-2010.
{{cite web}}
: Check date values in:|accessdate=
and|date=
(help) - ^ Reviewed by: Robert Vamosi. "Norton AntiVirus 2007 Internet security and firewall reviews - CNET Reviews". Reviews.cnet.com. Retrieved 2009-02-23.
- ^ a b c Reviewed by: Robert Vamosi. "Norton AntiVirus 2007 Internet security and firewall reviews - CNET Reviews". Reviews.cnet.com. Retrieved 2009-02-23.
- ^ "New Zealand PC World Magazine > Symantec unveils Browser Defender in its 2008 consumer security software". Pcworld.co.nz. 2007-08-30. Retrieved 2010-11-09.
- ^ "Symantec unveils Browser Defender in its 2008 consumer security software". Gregg Keizer. Fairfax New Zealand Limited. August 30, 2007. Retrieved 2009-03-07.
- ^ "Symantec Launches Norton Antivirus 'Gaming Edition'". PC Magazine. Retrieved 2009-02-24.
- ^ "Symantec Launches Fastest Security Products in the World". Marketwire, Incorporated. September 9, 2008. Retrieved 2009-03-04.
- ^ http://www.passmark.com/ftp/antivirus_09-performance-testing-ed3.pdf
- ^ Tal (January 5, 2009). "Norton Internet Security 2009". geekstogo.com. Retrieved 2009-01-07.
- ^ a b Neil J. Rubenking (July 2, 2009). "Symantec Releases Norton 2010 Betas". PC Magazine. Retrieved 15 July 2009.
- ^ Preston Gralla (July 7, 2009). "Norton Internet Security 2010 beta: Different approach, new features, some glitches". Thomson Reuters. Retrieved 8 July 2009.
- ^ "Norton Safe Web". Facebook: Symantec. Retrieved 2010-05-05.
- ^ "Norton AntiVirus 11 for Leopard Announced". PC World Communications, Inc. December 10, 2007. Retrieved 2009-02-28.
- ^ "Norton Antivirus 11.0 for Mac". about.com. Retrieved 2009-02-24.
- ^ "Norton AntiVirus 11 for Mac". Symantec. Retrieved 2009-02-24.
- ^ "Norton AntiVirus Dual Protection for Mac". Symantec. Retrieved 2009-02-24.
- ^ Sullivan, Bob (2001-11-20). "FBI software cracks encryption wall". MSNBC. Retrieved 2007-11-20. [dead link ]
- ^ Ted Bridis. "FBI Develops Eavesdropping Tools," Washington Post, November 22, 2001.
- ^ "FBI Has a Magic Lantern". Usgovinfo.about.com. Retrieved 2009-02-23.
- ^ "The FBI's Magic Lantern". Worldnetdaily.com. 2001-11-28. Retrieved 2009-02-23.
- ^ "Invasive Software: Who's Inside Your Computer?" (PDF). George Lawton. July 2002. Retrieved 2009-03-12.
- ^ http://www.kaspersky.com (2001-12-11). "The FBI's "Magic Lantern" Shines Bright". Kaspersky.com. Retrieved 2009-02-23.
{{cite web}}
: External link in
(help)|author=
- ^ Jackson, William (2001-12-06). "Antivirus vendors are wary of FBI's Magic Lantern – Government Computer News". Gcn.com. Retrieved 2009-02-23.
- ^ McCullagh, Declan (2007-07-17). "Will security firms detect police spyware? – CNET News". CBS Interactive, Inc. Retrieved 2009-02-23.
- ^ "IMPLICATIONS OF SELECT NEW TECHNOLOGIES FOR INDIVIDUAL RIGHTS AND PUBLIC SAFETY". Amitai Etzioni. Harvard Journal of Law & Technology. 2002. Retrieved 2009-03-12. [dead link ]
- ^ "FBI Confirms 'Magic Lantern' Project Exists" (PDF). Elinor Mills Abreu. At Home Corporation. December 31, 2001. Retrieved 2009-03-12.
- ^ "THE CASE FOR MAGIC LANTERN: SEPTEMBER 11 HIGHLIGHTS THE NEED FOR INCREASED SURVEILLANCE" (PDF). Christopher Woo & Miranda So. Harvard Journal of Law & Technology. 2002. Retrieved 2009-03-12.
- ^ a b "Error: "Your virus protection cannot be updated" when running the Intelligent Updater". Symantec Corporation. July 27, 2007. Retrieved 2009-05-27.
- ^ "Pegasus Email Client Being Flagged as a Trojan Program". DanB. TNPC Newsletter. May 18, 2007. Retrieved 2009-05-27.
- ^ "Faulty Update Stymies Norton Users". The Washington Post Company. 2009. Retrieved 2009-02-26.
- ^ Vamosi, Robert (2006-07-31). "Symantec ships faulty Norton AntiVirus 2006 update - Alpha Blog - alpha.cnet.com". Reviews.cnet.com. Retrieved 2010-11-09.
- ^ "Symantec uninstaller may not finish the job". Scott Dunn. WindowsSecrets.com. February 7, 2008. Retrieved 2009-03-05.
- ^ "How can I fully remove Norton Antivirus from my system?". Dave Taylor. Retrieved 2009-02-23.
- ^ "PCWorld". PCWorld. Retrieved 2009-02-23.
- ^ "Download and run the Norton Removal Tool". Symantec Corporation. Retrieved 2009-02-23.
- ^ Schofield, Jack (2006-11-02). "Norton AV versus Zone Alarm -- can't you have both?". The Guardian. London. Retrieved 2010-05-20.
- ^ Beaumont, Claudine (2009-03-10). "Internet conspiracy theories abound over Symantec Pifts.exe file". The Daily Telegraph. London. Retrieved March 10, 2009.
- ^ a b Krebs, Brian (2009). "Users Complain of Mysterious 'PIFTS' Warning". The Washington Post. Retrieved 2010-05-20.
- ^ Frantzen, Swa (2009). "Conspiracy fodder: pifts.exe".
- ^ Cluley, Graham (2009). "The mystery of Symantec and PIFTS.EXE".
{{cite web}}
: Unknown parameter|unused_data=
ignored (help) - ^ Cole, Dave (2009). "Norton product patch "PIFTS.exe" and Norton Users Forum".
- ^ "Cybercrooks Take Advantage of Symantec PIFTS.EXE Fuss". Lucian Constantin. Softpedia. March 11, 2009. Retrieved 2009-05-25.
- ^ "Consumer complaints about Norton". Consumeraffairs.com. Retrieved 2010-11-09.