Advice Request Scan on File Open vs Scan on File Execution

Please provide comments and solutions that are helpful to the author of this topic.

RoboMan

Level 38
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
High Reputation
Forum Veteran
Jun 24, 2016
2,615
24,636
3,600
Hidden Village of Hispanic America
Many antivirus have these type of options on it's real time protection: scan files on open, execution, creation.

My main question lies here: what's the difference between scanning a file on open or on execution. It looks like the same to me.

Thanks in advance.
 
From what I understand,
On open: You open a folder containing some files and those files would be scanned. Similar to what Windows Defender and most top AVs do. On open is also known as on access. When you open a folder Windows Explorer accesses those file for reading and if any contains malware then it would be detected. Most AVs usually don't scan every files, they have some selected extensions they scan on access.

On creation: Files that are already on your system won't be scanned unless executed. If you open a folder containing few exes then those won't be scanned. Only newly created files will be scanned. For example when you extract a zip file containing other files, those extracted files are newly created so those will be scanned by the AV.

On execution: We all know about it.
 
When the user is logging to his/her account, Windows opens the desktop (files are scanned on the desktop but not files in desktop folders). The same happens when opening the Explorer (or another file explorer based on Windows Explorer). The Desktop and Windows Explorer are parts of "Windows Shell".
The files are not scanned when one uses other shells (CMD, PowerShell, Bash), except when files are executed.
 
but didn't experience this on Norton
I was surprised myself
Image 1.jpg

Image 2.jpg

 
Last edited: