Comparison Test of Anti-Virus-Software 2002-02 (Unix products) of the
University of Magdeburg and GEGA IT-Solutions GbR (http://www.av-test.org)
Copyright (c) 2002 Andreas Marx <amarx@gega-it.de>

Last Update: 2002-05-13 (Data: 2002-04-22)


Note (2002-04-22): The test of the ITW virus detection was performed using
the WildList 11/2001 (including Win32/Bady.C, even if it is a backdoor).


AVIR-LN
H+BEDV Datentechnik
AntiVir/Linux

Comments:
- Program can be installed as RPM or TGZ archive
- German and English language versions can be chosen via the command-line
- Update: the name of the signature database (antivir.vdf) is stored in a
  ZIP archive in capital letters, but the scanner requires it to be in
  lowercase
- Guard: version tested is Beta version 0.9.7, separate pre-compiled
  modules are available for all original kernels in series 2.2.x and 2.4.x
  for single processor and SMP systems - in newer versions a proxy module
  available as source code is used, which patches the current kernel and
  handles all requests from and to the guard module
- Guard: since no module for the patched Kernel 2.4.10-4GB in Suse 7.3 was
  present, an original 2.4.17 kernel was used for testing
- Guard: in the beta version, only one log can be created for infected
  files, actions can be specified in the well organized configuration file
  avguard.conf, but they are ignored nevertheless
- A graphical front-end interface for X-Windows is available from a third
  party (TK/AntiVir,
  http://www.sebastian-geiges.de/tkantivir/download_en.htm)
- The help function of the command line version documents the parameters
  and return codes well, but there is no man page available

Missed ITW viruses:
- On-Demand and On-Access: all boot viruses, VBS/VBSWG.Y (2x)

Scan speed / performance On-Demand - best possible settings:
- Scan time of non-infected files (Suse Linux 7.3 with ext2 file system on
  a P-III 800, 256 MB RAM without X running) using parameters
  "- all files s z -r2 R-S": 492 seconds


CSAV-LN
Command Software
Command Anti-Virus

Comments:
- Installation via two RPM packages: one for the program, the second one
  for the virus definitions
- The program is practically identical to F-Prot/Linux, the help screen
  for the scanner also refers that the name of the program is not CSAV, but
  F-Prot
- Program does not prompt before taking action (uses the parameter "-auto"
  by default)
- Parameter "-removeall" does not work: it should strictly remove all
  macros from a document, but does not
- CSAV scans self-extracting archives (EXE) by default, but requires an
  additional parameter ("-archive") to scan inside normal archive files,
  too
- Parameter "-ext" (scan only files with a certain file extension) does
  not work, files are always scanned in "smart" mode
- Scanner does not work correctly with relative paths: e.g. calling
  "csav *" generates only an "Error Scanning <filename>" message on all
  scanned files - however "csav ." works as expected
- Using "-delete" parameter to delete infected files does not function (by
  intention) with macro viruses (Message: "Virus-infected documents are not
  deleted"); it does not work for certain script and file viruses (EML,
  HTA, HTM, and SHS) because of an error (Message: "Could not delete file")
- Warning about old program version: program does not warn, if it's too old
  (it also does not do that with the optional parameter "-old")
- Program seems to scan system areas of floppy disks for boot viruses, but
  never finds anything
- No guard or daemon is available
- Command-line parameters and return codes are documented, the man page did
  not function (program did not extract the copied GZ file)

Missed ITW viruses:
- On-Demand: all boot viruses

Scan speed / performance On-Demand - best possible settings:
- Scan time of non-infected files (Suse Linux 7.3 with ext2 file system on
  a P-III 800, 256 MB RAM without X running) using parameters
  "-ai -archive -dumb -packed -collect": 851 seconds


FPRO-LN
Frisk, perComp
F-Prot for Linux (Beta)

Comments:
- Installation via TGZ archive (installation not necessarily, only unpack),
  updates via ZIP files, entries in the path ($PATH) must be added manually
- Unlike CSAV, there are no problems with relative paths or the "-ext"
  parameter (scan only files with known extensions) works, the "-old"
  (display warning, if version is too old) also works as expected
- Unlike CSAV, F-Prot prompts before taking action on a file (does not use
  "-auto" by default)
- F-Prot scans self-extracting archives (EXE) by default, but requires an
  additional parameter ("-archive") to scan inside normal archive files,
  too
- Using "-delete" parameter to delete infected files does not function (by
  intention) with macro viruses (Message: "Virus-infected documents are not
  deleted"); it does not work for certain script and file viruses (EML,
  HTA, HTM, and SHS) because of an error (Message: "Could not delete file")
- Program seems to scan system areas of floppy disks for boot viruses, but
  never finds anything
- Report files have bad line feed: 0x0a/0x00 (not compatible to anything -
  neither with Unix nor with Windows), therefore we gave it a "-" here
- Access / rights control: if files cannot be read (no "r..") an incorrect
  error message ("Not scanned (in use by another application)") is given
- No guard or daemon is available
- No man page available, return codes are not documented

Missed ITW viruses:
- On Demand: all boot viruses

Scan speed / performance On-Demand - best possible settings:
- Scan time of non-infected files (Suse Linux 7.3 with ext2 file system on
  a P-III 800, 256 MB RAM without X running) using parameters
  "-ai -archive -dumb -packed -collect": 1089 Seconds


FSAV-LN
F-Secure
Anti-Virus

Comments:
- Installation: at first, a self-extracting ELF archive file has to be
  unzipped from a ZIP file and after this, a long license key has to be
  entered, installation starts and prompts for paths and the option to
  create crontab entries to run scheduled on-demand scans or regular
  updates (these scripts are also available in the installation directory)
- Only the F-Prot scan engine is used in contrast to the Windows versions
  which uses the Kaspersky engine and the proprietary Orion engine, too
- Has a different command-line syntax than CSAV or F-Prot although it is
  nearly the same program
- Program output cannot always be redirected to a file using ">", one must
  use "&>" as a bypass
- Prompts for (interactive) acknowledgement when using parameters like
  "--delete" (F-Secure deletes all types of files contrary to F-PROT
  without any problem)
- Often reports paths incorrectly, e.g. with scan "/root/" as a parameter
  the scanner lists "/root//<file>" in the report
- Report file contains char 0x01 in some places, in particular with
  messages like "<file> is a security risk or "backdoor" program", "<file>
  is a destructive program" or "<file> could be infected with an unknown
  virus"
- Did not scan certain file types by default: PIF, LNK, CHM, EML, PPT, HTA,
  VBS and SHS were not scanned, causing a bad ITW virus test result - when
  the "--dumb" parameter was used to scan all files, all ITW viruses were
  found (apart from boot viruses), this should be fixed in the next
  version, according to the developers
- Command-line parameters are documented, but not the return codes, man
  page is available

Missed ITW viruses:
- On-demand: all boot viruses and in the default settings 51 viruses in 102
  files: Win32/Sircam.A (1x PIF, 1x LNK), Win32/Blebla.A (1x CHM),
  Win32/Blebla.B (1x CHM), Win32/Nimda.A (1x EML), PP97M/Tristate.C (2x)
  and JS/Kak.A (1x HTA), as well as all VBS script viruses

Scan speed / performance On-Demand - best possible settings:
- Scan time of non-infected files (Suse Linux 7.3 with ext2 file system on
  a P-III 800, 256 MB RAM without X running) using parameters
  "--archive --dumb": 890 seconds


ETRI-LN
Computer Associates
eTrust InoculateIT

Comments:
- According to the manufacturer, the product only runs under Red Hat 6.2,
  7.0, Suse 6.3, Caldera Linux 2.3 and Turbo Linux 6.0, additionally
  the guard only works with specific 2.2.x kernels
- Test was conducted under the very old Suse 6.3 distribution (standard
  installation with kernel sources, because the kernel must be recompiled
  anyway with guard module)
- Installation as Workgroup or Advanced Edition possible (tar.z archive)
- Installation documentation is available as a Windows program (EXE) or as
  PDF file, explanations are incomplete and user must manually determine
  necessary environment variables amongst other settings (kernel
  compilation will be performed automatically by the program, reboot is
  necessary)
- Administration is via a Java interface (http://<host>/ino) with a similar
  GUI look to the InoculateIT 6.0 product for Windows, the interface only
  works with Internet Explorer, online help is available as HTML
- Java: "About-It" window appears up to three times, even though only
  started once
- Update is available through the Java interface or manually via TAR
  archives, and the local computer can also be used as an update source for
  others computers
- Program uses only the InoculateIT engine, not the VET engine
- There is an option to "Delete worms to heal infections", but such files
  were not deleted regardless
- Each local user of the Linux computer can log-on to the On-Demand scanner
  to see all directory listings with root privileges, as well as being able
  to change all settings and options of the scanner and guard as desired
- No report file is available, all information is stored in a database
  (DBF), export as text is not provided, therefore we gave it a "-"
- Test of rights/ access control is not possible, scanner runs with
  administrator rights (root), so all access is possible
- No command-line scanner is available, so no man page or return code
  documentation is needed

Missed ITW viruses:
- On-Demand and On-Access: Win32/Nimda.A (1x EML), X97M/Jini.A1 (2x)

Scan speed / performance On-Demand - best possible settings:
- Scan time of non-infected files (Suse Linux 6.3 with ext2 file system on
  a P-III 800, 256 MB RAM without X running), start of the scan using Java
  interface (scan all files including archives): 1135 seconds
  

KASP-LN
Kaspersky Lab, Datsec
KAV for Linux

Comments:
- Installation: unpack the file "kavwseilinux.tgz" and install the single
  modules (Documentation, Key, Scanner) using "./kavinstaller <TGZ archive
  name>"; Updates are available as separate ZIP files
- A script is included to create an Emergency boot disk (with Linux)
- Both a daemon (to keep the scan database in memory) and an On-Access
  guard are available
- Calling "kavscanner" without parameters will scan the current user's home
  directory, and some other directories (see defUnix.prf)
- On screen, long pathnames are cut off, but they are listed completely in
  the report file
- Program tells, it is able to scan for boot viruses, but it does not work
  (at least not on floppy disks)
- Scanner: detection of boot viruses can be turned off with the parameter
  "-P" for MBR and "-B" for boot sector, but if this option is used, the
  program only crashes with a "Segmentation Fault"
- Scanner does not delete PPT files if asked, but disinfects them
- With the "kavtuner" a text-based interface is available, but it lacks
  clarity, and isn't much use anyway due to wrong character sets
- A beta version of the guard is available, but is only suitable for the
  2.0.x kernels and was not tested by a wish of the producer (meanwhile
  modules are available for the 2.2.x and 2.4.x kernels)
- Scanner can be controlled by a configuration file or command-line
  parameters
- Function range of the scanner, other options if a virus was found:
  scanner can change files to a new owner/rights (chown, chmod), or rename
  them, but one can adjust this only in the configuration file, not via the
  command-line
- Update function is available through "kavupdater" script (address for
  updating must be manually edited in the configuration file, a list of
  possible sites is supplied)
- Report file contains a mixture of 0x0a line feeds (usual under Unix)
  but also some 0x0d/0x0a endings (usual under DOS and Windows), therefore
  we gave it a "-" here
- Man page is available but not automatically registered, return codes are
  documented

Missed ITW viruses:
- On-Demand: all boot viruses

Scan speed / performance On-Demand - best possible settings:
- Scan time of non-infected files (Suse Linux 7.3 with ext2 file system on
  a P-III 800, 256 MB RAM without X running) using parameters "-* -Y":
  1090 seconds, with a redundant scan by means of "-* -Y -V": 1493 seconds


MCAF-LN
Network Associates
UVScan

Comments:
- Program is available as tar.Z archive, once unpacked a script installs
  the scanner in the /usr/local/uvscan directory
- Updating is possible trouble-free either via ZIP or TAR archives
- Documentation is included as PDF file in the installation archive
- No daemon or guard is available
- Information about command-line parameters can only be found in the
  documentation, the scanner simply gives a list of available parameters
  without any indication of function
- Updates: an update script can be found in the documentation, but it is
  not included as a file, therefore we gave it a "-" here
- Scanner has no report file option (this must be created by manually
  redirecting), it has no introduction (version number etc., but it is
  optionally available using the "--version" switch) and no scan summary
  (this can be specified by including an optional parameter "--summary")
- By intention, macro virus infected documents are not deleted when using
  "--delete" parameter, though this is possible by use of the undocumented
  "-/!delete" 
- Scanning for boot viruses with the "--floppya" or "--floppyb" options
  correctly identifies boot viruses, but displays an error message "A
  target has not been specified for scanning!"
- Hint: if one wishes to exclude paths or files by means of "--exclude",
  one must specify a file in which the paths and/or extension exclusions
  are listed, rather than passing them directly on the command-line (it is
  rather confusing, what <file> means)
- Report files: using the undocumented option "--html" log files can be
  generated in HTML format (but due to the fact it's undocumented, we gave
  it a "-" here)
- If one does not pay attention to include the correct number of "-"
  characters, an undesired function may be specified - for instance,
  "--mime" scans all MIME archives (e-mail in EML format) but "-mime" moves
  all infected files in the quarantine folder "ime"
- Man page available, return codes are documented

Missed ITW viruses:
- (All viruses found)

Scan speed / performance On-Demand - best possible settings:
- Scan time of non-infected files (Suse Linux 7.3 with ext2 file system on
  a P-III 800, 256 MB RAM without X running) using parameters
  "--secure -r --mime --summary": 800 seconds


PAND-LN
Panda Software
Panda Anti-Virus

Comments:
- Installation via RPM archive
- Update: manual rename of the signature file (pav.sig) is necessary as it
  is archived in capital letters (pav*.zip), and the scanner requires it in
  lowercase
- No daemon or guard available
- Program uses colours for all output (by means of control codes) which
  cannot be switched off
- German and English versions are selectable via the command-line, however
  German umlauts are not correctly displayed
- The scanner automatically generates two report files:
  /var/log/panda/pavcl.log is a summarised version, and
  /var/log/panda/pavcl.rpt is a full detail version (this can be switched
  off by "-NOR")
- Each time the program starts one must accept a "License Agreement", but
  this can be switched off using "-AUT"
- Some (non-infected) files causes a "Segmentation Fault" crash in the
  scanner, but this only happens if many files are scanned
- Using standard settings one instance of a Win32/Nimda.A infected EML file
  is missed, however using "-CMP" (scan compressed files) it is found
- When infected files are found in an archive, only the file name of the
  infected file within the archive is reported, not the archive name or
  path; this also applies to embedded OLE objects
- When prompted for action on an infected file, "D" stands sometimes for
  "Disinfect" (if possible) and also sometimes for "Delete" 
- Access/ rights control: the scanner sometimes outputs "Permission denied"
  on the monitor, but immediately shows the help screen after that, so the
  message cannot be read anymore, therefore we gave it a "-" here
- No man page is available, return codes are not documented

Missed ITW viruses:
- On-Demand: Win32/Nimda.a (1x EML)

Scan speed / performance On-Demand - best possible settings:
- Scan time of non-infected files (Suse Linux 7.3 with ext2 file system on
  a P-III 800, 256 MB RAM without X running) using parameters
  "-HEU -CMP -NSO -AEX -AUT": 1233 seconds


RAVP-LN
GeCAD
Reliable Anti-Virus (RAV)

Comments:
- Installation via RPM package, path ($PATH) has to be extended manually
- Program requires a path to the scan engine (/usr/local/rav8/rave), it has
  to be specified at each scan with the parameter "-RP" or an environment
  variable "rave" has to be created
- Configuration file (and registration key in the registered version) is
  stored in the user's home directory
- A separately installable daemon is available, but no guard
- Use is through either command-line or a GUI version in X with options
  like the ones in the Windows version (including updates)
- Combining several different action parameters is not possible on the
  command-line (only one option can be specified, like always uses delete or
  disinfect, if this is not possible, nothing happens) but in the GUI
  version this is adjustable
- Man page is available, but must be registered manually, return codes are
  documented

Missed ITW viruses:
- On-Demand: Win32/Nimda.A (1x EML)

Scan speed / performance On-Demand - best possible settings:
- Scan time of non-infected files (Suse Linux 7.3 with ext2 file system on
  a P-III 800, 256 MB RAM without X running) using parameters "-H=on -A -M":
  927 seconds


SERV-LN
Trend Micro
ServerProtect for Linux

Comments:
- According to the manufacturer, only runs under Red Hat Linux 6.2 or 7.1
  with original kernel, therefore it was tested on Red Hat 7.1 with kernel
  2.4.x
- To install simply run the RPM package (see manual)
- The current scan engine for Unix 5.600 is clearly older than the Windows
  version 5.630 of 2001-10-25
- Administration is completely via HTTP web interface (Port: 14942)
  possible, login via password (standard: none)
- Web interface uses JavaScript extensively (e.g. for the progress display)
- On-Demand scanner and On-Access guard available
- Web interface controllable options: Scan Options -> Real Time Scan,
  Scheduled Scan, Manual Scan, Exclusion List, Quarantine Directory;
  Notification -> Recipients, Alert Settings; Update -> Manual Update,
  Scheduled Update, Proxy Settings; Logs -> Scan Logs, Virus Logs, System
  Logs, Log Settings; Administration -> Startup Settings, Password;
  Registration -> Product Registration, Customer Registration
- Notification options available using SMTP (Mail) and/ or SNMP for various
  events, e.g. a virus detection, Outbreak Alert (certain number of viruses
  exceeded in a definable period), or when the guard is turned on or off
- Configuration is stored in an XML file, which can be altered manually
- All protocols are stored in /var/log/TrendMicro/SProtectLinux, these can
  be read directly or via the web interface where filtering and sort
  functions are also available and an export to a CSV file is possible
- Function for manual deletion of the report files would be desirable (at
  the moment, reports can only be deleted automatically after a specified
  adjustable period)
- Warning about old program version only available via e-mail or SNMP, no
  message is displayed during log-in to the web interface
- Test of rights/ access control is not possible, scanner runs with
  administrator rights (root), so all access is possible
- No command-line scanner available, therefore return codes or man pages
  not needed

Missed ITW viruses:
- On-Demand: all boot viruses, W32/Nimda.A (1x EML)

Scan speed / performance On-Demand - best possible settings:
- Scan time of non-infected files (Red Hat Linux 7.1 with ext2 file system
  on a P-III 800, 256 MB RAM without X running), scan started using web
  interface (scan all files including archives): 341 seconds


SOPH-LN
Sophos 
Anti-Virus (Sweep)

Comments:
- Installation: program in TAR archive, contains install script, requires
  user and group "sweep" to be created prior to installation
- Updates are delivered monthly on CD-ROM, between this, ITW virus
  detection updates can be downloaded as ZIP archive (available as
  required)
- "Intercheck" daemon available, but no guard
- Functional range of the On-Demand scanner: quarantine function available,
  this changes the rights of the infected file to current user/group/"r--"
  or a selected choice of group/users/rights
- If user requests interactive mode (e.g. confirmations) this input of the
  action specified is not displayed
- Report file: details of user/group/rights can be shown by using
  "--show-file-details"
- File viruses cannot be disinfected, but only deleted
- Man page is available, return codes of the scanner are well documented

Missed ITW viruses:
- (All viruses found)

Scan speed / performance On-Demand - best possible settings:
- Scan time of non-infected files (Suse Linux 7.3 with ext2 file system on
  a P-III 800, 256 MB RAM without X running) using parameters
  "-f -nb -all -archive": 519 seconds


TMIC-LN
Trend Micro
Vscan (ISVW)

Comments:
- Only the command line scanner "vscan" was tested, which is a part of the
  much larger "InterScan VirusWall" package
- Program only runs on certain versions of Red Hat Linux, tested on Red Hat
  7.1
- Installation is via TAR archive, which includes documentation (PDF, TXT),
  as well as an installation RPM
- Update can be performed using a ZIP or TAR archive
- The current scan engine for Unix 5.600 is clearly older than the Windows
  version 5.630 of 2001-10-25
- Defaults in the scanner are apparently completely ignored if any
  parameters are specified, so all required parameters should be specified
  (especially "-a")
- By default the scanner will scan 20 levels of archives ("-y20"), but on
  the command-line this value can be adjusted to a maximum of 9 levels only
- The report is available as CSV file (output can also be redirected from
  the screen), however, the specified options cannot easily be found, e.g.
  renamed files only at the extension of the last entry, "D" for "Delete"
  etc., on screen this information won't be displayed at all
- Access/ rights control: error message if file cannot be read (no "r..")
  "*** Scan error -94, file <filename>" is not very meaningful
- Man page is not included, return codes are not documented

Missed ITW viruses:
- On-Demand: All boot viruses, Win32/Sircam.A (1x LNK)

Scan speed / performance On-Demand - best possible settings:
- Scan time of non-infected files (Red Hat Linux 7.1 with ext2 file system
  on a P-III 800, 256 MB RAM without X running) using parameters
  "-a -c1 -c2 -nl -r -s -u -za -y9 -sd": 322 seconds


### END OF FILE ###
