The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    testing effectiveness of your virus resident scanner!!

    Discussion in 'Security and Anti-Virus Software' started by i5evoSwift3814, Mar 22, 2008.

  1. i5evoSwift3814

    i5evoSwift3814 Notebook Consultant

    Reputations:
    7
    Messages:
    134
    Likes Received:
    1
    Trophy Points:
    31
    Are there any sites where you can test how effective your virus scanner is by dowloading fake virus programs?
     
  2. Lithus

    Lithus NBR Janitor

    Reputations:
    5,504
    Messages:
    9,788
    Likes Received:
    0
    Trophy Points:
    205
    I'm not sure you understand how a virus scanner works. A virus is either in the scanner's definitions or it's not, so the only way to test it is with a virus that's not in the definitions, in which case, the scanner would obviously fail. The only way I can think of actually testing them would be to load up on virii and see how comprehensive the definitions are, or measure the amount of time between the introduction of a new virus and it's appearance on updated definitions.
     
  3. bmwrob

    bmwrob Notebook Virtuoso

    Reputations:
    4,591
    Messages:
    2,128
    Likes Received:
    0
    Trophy Points:
    55
    Not sure if this will really answer your question, but there are online scanners such as this which, I suppose, you could use to double check your own AV's thoroughness.
     
  4. Lithus

    Lithus NBR Janitor

    Reputations:
    5,504
    Messages:
    9,788
    Likes Received:
    0
    Trophy Points:
    205
    I understand the heuristics part of the AV program, but you still can't make a benchmarking system in the traditional sense. All the companies have to do is include those virii into a definitions update, and that would guarantee a 100% pass.
     
  5. swarmer

    swarmer beep beep

    Reputations:
    2,071
    Messages:
    5,234
    Likes Received:
    0
    Trophy Points:
    205
    See www.av-comparatives.org ... they have data on the different AV packages and how many viruses are caught by the resident scanner and by on-demand scans.

    As far as doing your own tests... you could download a virus file and just not run it and see if the AV program flags it. That's all I can really think of.
     
  6. _radditz_

    _radditz_ Fallen to the Sith...

    Reputations:
    120
    Messages:
    1,584
    Likes Received:
    0
    Trophy Points:
    55
    what about running the virus in a virtual machine? I dont know that much about virtualisation though!
     
  7. Matt is Pro

    Matt is Pro I'm a PC, so?

    Reputations:
    347
    Messages:
    2,169
    Likes Received:
    0
    Trophy Points:
    55
    Don't forget the Heuristics that many also employ. This is used to track behavior rather then just a signature. In theory, a new virus may not have a signature yet, but the Heuristics may still detect the abnormal behavior and act upon that.

    Many AVs use both systems.