Saturday, November 22, 2008

How To Update Virus Definition

Virus definition file (also called signature file) is basically a database that contains the virus code (the signature) of those known viruses. To detect a virus, the antivirus program looks for these code strings in executable programs.

In addition, the virus definition file also contains repair information about all the discovered viruses so that the antivirus program knows how to remove the virus from the directories and registry in the inflected computer.

There are many new viruses and security risks being introduced into the computer community every day. In order for the antivirus program knows to how detect and clean the most recent viruses, the virus definition file must be updated regularly to have the latest information.

For Symantec AntiVirus Corporate Edition (for Norton as well), there are two ways of update the virus definitions:-
1. Live Update
2. Intelligent Updater

Live Update
It is the preferred method for the virus definition update as it is easy to use.

If your computer is configured as an unmanaged client, then it can be configured to get the update automatically from Symantec virus definition’s server.

If your computer is configured as a managed client (Live Update option may be grayed out), the “virus definition” update is most likely getting from a central, internal server in your company.

In any time, if you need to get ad-hoc update from the server, you can just simply click the “Live Update” button to trigger the download (as shown below).

Intelligent Updater
The Intelligent Updater file is an executable file (EXE file) to use as an alternative to LiveUpdate for updating virus definitions.

It is less convenient as compared with LiveUpdate, because it is a manual process. It also needs a larger download (say, bigger than 35 MB) that may be inconvenient if you have a slow internet connection (e.g. dial-up).

If your Symantec AntiVirus on your computer is configured as a managed client, it will not able to get the virus definitions from the company’s server when your computer is not connecting to the office network (for example, working on your notebook from home).

In that case, the only choice is to download the Intelligent Updater directly from the internet server and get the update.

The URL to the Symantec Security Response Web site to download the Intelligent Updater is as follows:-

http://www.symantec.com/business/security_response/definitions/download/index.jsp