Wednesday, February 20, 2008

Disable Symantec Antivirus

It is nearly impossible to stop Symantec Antivirus. Even after all Symantec services are stopped it still continues to scan. This is because it continues to run from a rooted directory located at program files\symantec antivirus\OEM. But it is possible to disable Symantec.
1. Stop symantec avtivirus service
2. Stop defwatch service
3. rename the \program files\common files\symantec shared\virusdefs directory

Symantec will continue scan but it won't be able to find its virus definitions. Symantec will correct its self at the next Liveupdate, so this is not a longterm hack. This will also cause Symantec to log systems errors and tamper errors.

No comments: