1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

NAV Redirector update of 05/12

Discussion in 'Security and Privacy' started by charlesvar, 2004/05/12.

Thread Status:
Not open for further replies.
  1. 2004/05/12
    charlesvar

    charlesvar Inactive Alumni Thread Starter

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    After NAV Redirector update (for NAV2002), had a problem, couldn't re-boot or shut down - use of Reset button resolved it.

    The following Symantec executes added to system:

    Program Files\CommonFiles\Symantec shared:
    Sevinst.exe
    IDSLU.exe
    IDSCol.exe

    Program Files\Symantec\LiveUpdate:
    SNDMon.exe

    Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Exitem1169_symantec$20redirector_4.5.2_english\LUProdRg.exe

    Don't know which of the above caused the condition - if anyone has a problem with this update beyond what I had, here is where to look.

    Regards - Charles

    EDIT: This one: SNDMon.exe wants to startup at bootup as Symantec NetDriver Monitor
     
    Last edited: 2004/05/12
  2. 2004/05/13
    Christer

    Christer Geek Member Staff

    Joined:
    2002/12/17
    Messages:
    6,585
    Likes Received:
    74
    Hi Charles!

    I use the 2003 version and have not noticed anything at or around this date but out of interest:

    Does the condition persist?

    If not, how did You fix it?

    If it was a one time occurrence, then I had a similar experience a week or so ago when the computer froze on shut down. That happened after re-enabling protection for Messenger Downloads.

    Christer
     

  3. to hide this advert.

  4. 2004/05/13
    charlesvar

    charlesvar Inactive Alumni Thread Starter

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    Hi Christer,

    It did resolve itself once I hit the reset and the system rebooted.

    Got a message right after the NAV update was finishing that the system has to be re-booted for the changes to take effect and to hit OK. So I think the "reboot" command to the system by the Symantec process failed.

    I also disabled that new startup - Symantec NetDriver Monitor -for the time being. Will try to track down what it is and what it does.

    Do you have any of these new additions I listed?

    Regards - Charles

    EDIT: This update gave someone running NIS2002 a far bigger headache: http://www.wilderssecurity.com/showthread.php?t=31945
     
    Last edited: 2004/05/13
  5. 2004/05/13
    Christer

    Christer Geek Member Staff

    Joined:
    2002/12/17
    Messages:
    6,585
    Likes Received:
    74
    I had a look and this is what I've got (folder names translated from swedish):

    C:\Program\Common Files\Symantec Shared\sevinst.exe
    which is "Symantec Symevent Installer" and
    C:\Windows\Prefetch\sevinst.exe-26954B68.pf

    C:\Program\Common Files\Symantec Shared\IDSDefs\idslu.exe
    which is "IDS Updater "

    C:\Program\Common Files\Symantec Shared\IDSDefs\idscolu.exe
    which is "IDS core updater" (note: idscolu not idscol)

    No sndmon.exe on my system

    No luprodrg.exe on my system but
    C:\Windows\Prefetch\luprodrg.exe-20B5E4F1.pf

    I don't seem to have "Symantec NetDriver Monitor" or anything similar running.

    Christer
     
  6. 2004/05/14
    charlesvar

    charlesvar Inactive Alumni Thread Starter

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    The only refernce to SNDMon.exe (Symantec NetDriver Monitor) is here: http://computercops.biz/forum82.html which BTW is the nearest thing to a Symantec forum I've run into.

    This appears from the one of the posts to be tied to Symantec's current security problem and is giving users of NIS2002 hell.

    I have it disabled and appears to have no effect on any NAV function. It may have to do with LiveUpdate (which I have disabled) or this is Symantec's attempt at equiping :) NAV2002 with its very own version of CCClient - I think that's what its called.

    Regards - Charles
     
  7. 2004/05/18
    charlesvar

    charlesvar Inactive Alumni Thread Starter

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    Tracked down some more info on Symantec NetDriver Monitor:

    quote
    The Symantec Redirector (Symredir) is a set of shared network drivers that allow Norton AntiVirus, Norton Personal Firewall, and Norton Internet Security to filter incoming and outgoing data for malicious or undesired content.

    The Redirector intercepts data coming into, or leaving your computer, and redirects it to a temporary location on your hard drive where it processes the data, and then sends the data to its intended destination. Without the Redirector, your email program sends your email messages directly to your email server. With the Redirector running, data that your browser sends to a Web server is diverted through the Norton Internet Security (NIS) or Norton Personal Firewall (NPF) filters to scan for and protect privacy or confidential data. Once filtered, that data is sent to the Web server. Data coming in from a Web server is diverted through the NIS/NPF filters, and undesired active content or unwanted advertising content is filtered out. The data is then passed to your Web browser for processing.

    In all these situations, the Redirector is invisible to both the email programs and Web browsers you use.
    End quote

    Ok, so if one is not running any Symantec firewall/security suite, this startup is superfluous. I'm wondering how much of the rest of the Redirector update is besides the point if only running the AV.

    Regards - Charles
     
  8. 2004/06/01
    balo

    balo Inactive

    Joined:
    2004/06/01
    Messages:
    73
    Likes Received:
    0
    balo,
    #7
  9. 2004/06/01
    charlesvar

    charlesvar Inactive Alumni Thread Starter

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    Hello balo and welcome here,

    Thanks for confirming that its useless if NOT RUNNING NIS/NPF :)

    Regards -Charles
     
  10. 2004/06/02
    Christer

    Christer Geek Member Staff

    Joined:
    2002/12/17
    Messages:
    6,585
    Likes Received:
    74
    In an earlier post to this thread, I stated that I had no SNDMon.EXE. A few days ago I restored an Image and ran LiveUpdate. I now have it in C:\Program\Symantec\LiveUpdate and it runs from msconfig - autostart. Maybe I missed it the first time I looked on May 13 but I don't think so since the file I have is dated May 21. It has probably been there since May 21 but I never looked for it.

    Christer
     
  11. 2004/06/02
    charlesvar

    charlesvar Inactive Alumni Thread Starter

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    Hi Christer,

    This all started because of this hole in Symantec firewalls http://www.internetnews.com/dev-news/print.php/3353841

    Mark higihlighted this issue earlier on this Board and I didn't especially pay attention to it because I don't use Symantec firewalls. Only after SNDMon.exe started on my system that I started looking into it.

    For users, the fix caused problems. This thread here on this Board for example http://www.windowsbbs.com/showthread.php?t=31204 and here: http://www.dslreports.com/forum/remark,10248995~mode=flat and the thread on ComputerCops Symantec forum for which I gave a reference to above. Warning, the last two are both l o o n g threads :)

    Regards - Charles
     
    Last edited: 2004/06/02
  12. 2004/06/02
    balo

    balo Inactive

    Joined:
    2004/06/01
    Messages:
    73
    Likes Received:
    0
  13. 2004/06/02
    charlesvar

    charlesvar Inactive Alumni Thread Starter

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    Hi balo,

    Great to have another new person on the Board.

    Yes, please do let us know.

    For the sake of clarity, are you running a Symantec suite/firewall or just an AV?

    Regards - Charles
     
  14. 2004/06/02
    balo

    balo Inactive

    Joined:
    2004/06/01
    Messages:
    73
    Likes Received:
    0
    I am running SWS Pro 2003 and the Symantec Firewall
     
  15. 2004/06/02
    Johanna

    Johanna Inactive Alumni

    Joined:
    2003/03/08
    Messages:
    2,402
    Likes Received:
    2
    FWIW,
    My kids' comp (XP Pro with NIS 2002) took that update automatically and was not affected, AFAIK.

    Dumb luck? :confused:
    Johanna
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.