Anti-virus software driving you mad? 5 fight-back tips

I like to think that most of us who use computers are reasonably bright and responsible. So I get really irritated by the mindset of some technology vendors who insist that treating us like children is not only okay, but also the responsible thing for them to do.

Update Java and You May Get Annoying McAfee Scanner Too

I spoke to various engineers from anti-virus companies last week about a bizarre incident that caused a fair amount of pain to Windows users who meant to install a Java update and got stuck with an annoying security update that they neither wanted nor needed.

I'll get to the details in a bit, but I was struck by this remark: "I want it (the AV program) to be so simple my mother won't have a problem with it," said one engineer. Aside from the implicit sexism and ageism (who says older women can't be as competent as younger men?) the answer reeked of the patronizing users needed to be protected from themselves attitude I find so irritating.

Last week's incident began when some Windows users opted to install a routine update to Java, a programming language Oracle inherited when it purchased Sun Microsystems. For some reason, Oracle decided to bundle McAfee Security Scan Plus along with the Java update. The software is installed by default unless you notice and uncheck a little box to opt out.

The security program checks the PC to see if it has antivirus and firewall software installed and if they're both up-to-date. Various popup windows open from time to time and you're prompted to accept licensing terms, all of which use up system resources, slowing the PC down. The only way to get away from the darn thing is to uninstall it using the Windows control panel.

It turns out that Adobe did the same thing, bundling the scan program with some updates to its Reader application. Queried by our colleagues at Computerworld, a McAfee spokesman said: "McAfee believes it's better to be protected than unprotected, therefore we are offering this as a default." Translation: We don't trust you to do it yourself.

This incident has more lessons in it than a high school algebra textbook, not the least of which is the aforementioned patronizing attitude of tech vendors. Fortunately, it also suggests as few actions that you can take to avoid this sort of nonsense.

1. Pay attention before, during and after you download

My one-time colleague Andrew Brandt, a former tech journalist now working for Webroot, a security vendor, warns that the practice of stealth bundling is becoming all too common. A number of companies make a living by striking deals with vendors and tricking user into downloading all sorts of junk.

For example, you may see a big button on a Web site that looks like it will play a video when you click it. When you do, it brings up a cheesy flash animation that says you need a particular codec to run it. If you say okay, you'll go through a number of confusing steps and wind up with a copy of Real Player as well as a codec (an application that lets you play video) on your PC. Real Player has its good points, but it also winds up creating a lot of system-slowing traffic by frequently grabbing information from the Web and pushing it to you.

Generally you can defend yourself by paying attention before you download anything. In particular, says Brandt, look at the fine print and various boxes that are usually checked by default, meaning you've agreed to something you may not like at all.

2. Get a better look at your PC's processes

Brandt suggests downloading a free program from Microsoft called Process Explorer, which is, as he puts it, "is like Task Manager" but stronger. I tried it and it works well, showing you what processes are running, a little bit about what they do, and how much memory and CPU power they are taking up. The program gives you the option to kill the process and related stuff it has spawned, a really handy feature that will help you spot junk you didn't know was there. Be warned though: You want to be careful about anything from Microsoft, because killing Windows-related processes can cause serious problems.

3. Learn how to control your anti-virus programs

Because the anti-virus makers are sure you need them hovering like Tiger Moms, all sorts of stuff is turned on by default in these programs. Fortunately, many of the programs have controls that let you adjust what they're doing - if you can find them.

Webroot, for example, has a "gamer mode" that turns off a lot of the checking it normally does. If you think Webroot is getting in the way, just pretend you're a gamer. You will, of course, lose some of the protection you're paying for, but thats the kind of tradeoff adults should think about.

Symantec's nearly ubiquitous Norton program doesn't have a corresponding feature (or if it does, I haven't seen it) and it can be a little hard to find some of the controls. But they are there. For example, the program does a background security check of your system at regular intervals, and because it looks at so much of your hard drive, it takes a while and slows things down. So go to "settings" and click on "computer scans" and you'll a label that says "scan scheduled." That's not as explicit as it might be, but click on it and you'll get to a menu that lets you schedule the scan for a time, like 3 a.m., when you're probably not using your computer.

With plenty of other settings you can also tweak, it's worth poking around any AV program. Look at the help files or go online to see what other users of the program have to say.

4. Check out lightweight alternatives

Joshua Corman, a research director at the 451 Group, gets even more irritated with security programs than I do. He says that some popular anti- virus programs create more problems than they solve, which is to say that the system slowdown they cause may be worse than the slowdown a virus or other malware might provoke. And he likens the fee that people pay to companies like Symantec for ongoing updates and protection to a tax, or as he puts it "the $50 security tax."

Still, he's careful to say that he's not suggesting you kill your anti-virus programs. He notes that there are a number of lightweight programs out there that are cheap, or even free (Microsoft Security Essentials, for example) that give decent protection. He adds, though, that the larger programs may provide more complete protection, so you need to decide if you're willing to make the tradeoff.

5. Don't use more than one security program

If one security program gives decent protection, wouldn't it be even better to run two or even three? Not at all. In fact running multiple security programs not only isn't necessary, but also can lead to annoying system problems.

New PCs often come with an AV program thrown into the mix. Or you may download one via one of those bundles we talked about and forget that it's running. Multiple programs can trip over each other, or at the very least, suck up even more system resources. Check your hard disk for them by looking in the Windows Control panel and delete the ones you don't want.

San Francisco journalist Bill Snyder writes frequently about business and technology. He welcomes your comments and suggestions. Reach him at

Follow Bill Snyder on Twitter @BSnyderSF. Follow everything from on Twitter @CIOonline.

Read more about security in CIO's Security Drilldown.

Join the CSO newsletter!

Error: Please check your email address.

Tags desktopsmcafeesecurityhardware systemsdesktop pcssoftwareTechnology TopicsOracleantivirusTechnology Topics | Security

More about Adobe SystemsAndrew Corporation (Australia)BillMcAfee AustraliaMcAfee SecurityMicrosoftNortonOracleSun MicrosystemsSymantecWebroot

Show Comments

Featured Whitepapers

Editor's Recommendations

Solution Centres

Stories by Bill Snyder

Latest Videos

  • 150x50

    CSO Webinar: The Human Factor - Your people are your biggest security weakness

    ​Speakers: David Lacey, Researcher and former CISO Royal Mail David Turner - Global Risk Management Expert Mark Guntrip - Group Manager, Email Protection, Proofpoint

    Play Video

  • 150x50

    CSO Webinar: Current ransomware defences are failing – but machine learning can drive a more proactive solution

    Speakers • Ty Miller, Director, Threat Intelligence • Mark Gregory, Leader, Network Engineering Research Group, RMIT • Jeff Lanza, Retired FBI Agent (USA) • Andy Solterbeck, VP Asia Pacific, Cylance • David Braue, CSO MC/Moderator What to expect: ​Hear from industry experts on the local and global ransomware threat landscape. Explore a new approach to dealing with ransomware using machine-learning techniques and by thinking about the problem in a fundamentally different way. Apply techniques for gathering insight into ransomware behaviour and find out what elements must go into a truly effective ransomware defence. Get a first-hand look at how ransomware actually works in practice, and how machine-learning techniques can pick up on its activities long before your employees do.

    Play Video

  • 150x50

    CSO Webinar: Get real about metadata to avoid a false sense of security

    Speakers: • Anthony Caruana – CSO MC and moderator • Ian Farquhar, Worldwide Virtual Security Team Lead, Gigamon • John Lindsay, Former CTO, iiNet • Skeeve Stevens, Futurist, Future Sumo • David Vaile - Vice chair of APF, Co-Convenor of the Cyberspace Law And Policy Community, UNSW Law Faculty This webinar covers: - A 101 on metadata - what it is and how to use it - Insight into a typical attack, what happens and what we would find when looking into the metadata - How to collect metadata, use this to detect attacks and get greater insight into how you can use this to protect your organisation - Learn how much raw data and metadata to retain and how long for - Get a reality check on how you're using your metadata and if this is enough to secure your organisation

    Play Video

  • 150x50

    CSO Webinar: How banking trojans work and how you can stop them

    CSO Webinar: How banking trojans work and how you can stop them Featuring: • John Baird, Director of Global Technology Production, Deutsche Bank • Samantha Macleod, GM Cyber Security, ME Bank • Sherrod DeGrippo, Director of Emerging Threats, Proofpoint (USA)

    Play Video

  • 150x50

    IDG Live Webinar:The right collaboration strategy will help your business take flight

    Speakers - Mike Harris, Engineering Services Manager, Jetstar - Christopher Johnson, IT Director APAC, 20th Century Fox - Brent Maxwell, Director of Information Systems, THE ICONIC - IDG MC/Moderator Anthony Caruana

    Play Video

More videos

Blog Posts