Comparison Test of Anti-Virus-Software 2001-09 (Groupware products) of the
University of Magdeburg and GEGA IT-Solutions GbR (http://www.av-test.org)
Copyright (c) 2001 Andreas Marx <amarx@gega-it.de>

Last update: 2001-10-24 (Data: 2001-10-14)


Notice (2001-10-14): The following programs raised problems and could not
be tested: Command AV and F-Secure AV, as well as Group SecuriQ with
engines of AntiVir, F-Secure and NAI/McAfee. We will repeat the test of
these products later.


GRPA-E2
Group Technologies
SecuriQ (All Engines)

Comments:
- Installation is very complex, therefore the process should be explained
  better in the documentation
- Stability-/Heavy load tests failed: If many e-mails arrives the Server
  simultaneously not all e-mails will be scanned resp. e-mails will not
  be delivered anymore and the Exchange Server hangs with a load of 100%
- Performance tests not possible, because the test conditions were not
  fulfilled (Reason: Load tests not passed)
- Penetration tests (mail bomb) not passed: Server has a very high load
  which does not decrease anymore

Missed ITW viruses (On-Access):
- (All viruses found)


GRPS-E2
Group Technologies
SecuriQ (Sophos Engine)

Comments:
- See "Group SecuriQ (All Engines)"

Missed ITW viruses (On-Access):
- (All viruses found)


GRPT-E2
Group Technologies
SecuriQ (Trend Engine)

Comments:
- See "Group SecuriQ (All Engines)"

Missed ITW viruses (On-Access):
- (All viruses found)


GRPY-E2
Group Technologies
SecuriQ (Symantec Engine)

Comments:
- See "Group SecuriQ (All Engines)"

Missed ITW viruses (On-Access):
- (All viruses found)


GRSH-E2
Network Associates
GroupShield for Exchange

Comments:
- German translation of the product is very bad
- In the standard configuration all virus founds will be reported by a
  pop-up window on the Exchange Server
- Penetration tests (mail bomb) not passed: A single-processor system
  had a work load of 100% and a multi-processor system a load of about
  60%; It's impossible to fetch e-mails; The adjustable "maximum scan
  time of an attachment" was set to 180 seconds, but it did not work
- Notice: Shortly after the start of the test the new engine 4.1.50 was
  released, which has the opportunity to scan inside ACE and BZ2 archive
  files, too, and many new EXE compressors are supported now

Missed ITW viruses (On-Access):
- (All viruses found)


INOA-E2
Computer Associates
eTrust InoculateIT

Comments:
- To finish the installation process, a reboot is needed, even if the
  installation program suggests not to reboot the PC now
- The program has two scan engines (InoculateIT and VET), however, only
  one can be used at the same time; The test was performed using the
  InoculateIT engine only
- Program only supports AVAPI 1.0, therefore SP1 is not required, but
  files can only be checked on-access and not on-demand
- Scanner does not always scan all files at any time: Even under low
  workload e-mails will be passed sporadically without scanning,
  therefore, no performance tests are possible
- Disinfected files will be delivered together with a text file (scan
  report) as ZIP file, but sometimes this file is damaged so that it
  is defective (e.g. JS/Kak.A); Script viruses will usually stored in
  this ZIP file undisinfected and fully able to replicate
- Content Filtering: In the program an option exists to block special
  file types or pass them, however, this function did not work in our
  test (the scanner always let all files pass)
- Program tries to sporadically access the floppy drive (A:) 

Missed ITW viruses (On-Access):
- Win32/Sircam.A (1x LNK)


PAND-E2
Panda Software
Panda AV for MSEX

Comments:
- Penetration tests (mail bomb) not passed: Server had 100% work load and
  it was impossible to access the Server even with the management program
- Configuration changes need a few minutes to activate
- VBS/Loveletter.BJ was only detected in UUEncode attachments, the program
  was not able to find this virus in MIME encoded mails
- On-Demand: The option "Delete" does not work properly: An infection was
  correctly found, however, the messages were not deleted in every case
- On-Demand: It is possible to select the Public Information Store for
  scanning, but it will not be completely checked

Missed ITW viruses (On-Access):
- Win32/ExploreZip.210432 (2x), Win32/Mtx.A (1x), Win32/Beast.41472.A (2x),
  Win32/Msinit.A (2x), VBS/Loveletter.AS (2x), VBS/Loveletter.BJ (2x),
  Win32/Ska.10000 (1x)


SCML-E2
Trend Micro
ScanMail for Exchange

Comments:
- Installation copy files to the directory "C:\Program Files" and not
  to the German standard program folder called "C:\Programme"
- Penetration tests (mail bomb) not passed: The Exchange Server had
  a work load of 100% (on a single server as well as on a multi-processor
  systems) and it was impossible to fetch e-mails
- Program window is not resizable, therefore the reports are a little
  bit complicated to read
- The report file contains an additional character 0x00 at the start of
  every new line (after a line feed)

Missed ITW viruses (On-Access):
- (All viruses found)


SYBA-E2
Sybari
Antigen (All Engines)

Comments:
- Tests were only performed in the mode "AVAPI 2.0", but there is also
  an ESEAPI mode available which can be activated during installation
  or using a command-line program with a special switch
- On-Demand scans are only available in the mode ESEAPI, therefore,
  we were unable to test this function (if AVAPI is selected, the
  function "Quick Scan" under "Operate" will be displayed, but it
  cannot be selected)
- In the standard configuration "Bias" the program chooses the number of
  scan engine(s) that will be used depending on the file type; All tests
  were performed using the option "Max Certainly" to always use all or one
  specific engine
- Configuration changes on the option "Action" need a few seconds to activate
- Program window is not resizable, therefore the reports are a little
  bit complicated to read
- Options if a virus was found: e-mails infected by worms can be deleted
  automatically using the Sybari engine (a list of virus names), but no
  further selection options exist
- Manual update possibilities: On the Sybari web server, EXE files exists
  that can be downloaded to update the engine and signatures, however, it's
  only a self-extracting ZIP file - all the update steps (copy etc.) have to
  be done manually, therefore we gave a "no"; a "yes" was reserved for the
  programs which do all necessary steps completely automatically
- Report file: It's possible to insert the name of the computer, for this,
  the variable "%Server%" have to be used

Missed ITW viruses (On-Access):
- (All viruses found)


SYBC-E2
Sybari
Antigen (CA+VET Engine)

Comments:
- See "Sybari Antigen (All Engines)"

Missed ITW viruses (On-Access):
- (All viruses found)


SYBN-E2
Sybari
Antigen (NAI Engine)

Comments:
- See "Sybari Antigen (All Engines)"

Missed ITW viruses (On-Access):
- VBS/Haptime.A (1x)


SYBO-E2
Sybari
Antigen (Norman Engine)

Comments:
- See "Sybari Antigen (All Engines)"

Missed ITW viruses (On-Access):
- VBS/San.B (1x), VBS/Coldape.A (2x), VBS/Happy.A (2x)


SYBS-E2
Sybari
Antigen (Sophos Engine)

Comments:
- See "Sybari Antigen (All Engines)"

Missed ITW viruses (On-Access):
- (All viruses found)


SYMC-E2
Symantec
Norton AV for MSEX

Comments:
- Installation: To start the installation, it is required to manually adjust
  a few user rights or the program shows only a too small error message that it
  does not have all necessary rights - but the list what has to be changed cannot
  be found in the online help, only the web page shows an English description,
  but this one is unusable for the German version of Windows and Exchange
- Test was performed in the mode "AVAPI 2.0", however, there is also a MAPI mode,
  that can be selected during installation or in the program
- An on-demand scan is only available in the MAPI mode, but, if activated, the
  program completely uses MAPI only instead of AVAPI

Missed ITW viruses (On-Access):
- (All viruses found)


### END OF FILE ###
