home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!ukma!cs.widener.edu!dsinc!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: bill.lambdin%acc1bbs@ssr.com (Bill Lambdin)
- Newsgroups: comp.virus
- Subject: LAT details
- Message-ID: <0005.9301281842.AA17847@barnabas.cert.org>
- Date: 17 Jan 93 21:32:00 GMT
- Sender: virus-l@lehigh.edu
- Lines: 61
- Approved: news@netnews.cc.lehigh.edu
-
- Some have asked me about certain aspects of LAT, and I have decided to
- send one public message insead of multiple messages via Email.
-
- 1. I started LAT because of the hype in advertizing. I bought two less
- than adequate anti-virus programs, and I thought other users might like to
- see some fair and unbiased reports on anti-viral software before they buy.
- I have no vested interest in any of these companies, and I am not paid to
- compile this report.
-
- 2. LAT is an acronym it means "Lambdin's Accuracy Tests"
-
- 3. The chart is scanner certification pure an simple. I have the scanners
- passively scan for viruses on the hard drive.
-
- 4. VCheck from Victor Charlie only detects the 60 or 70 most common
- viruses, and the authors of Victor Charlie "Alan Dawson, and John DeHaven"
- request that VCheck not be included in scanner certifications such as the
- chart in LAT.
-
- 5. The testing of scanners and the recommendations of generic virus
- detection software is two different tests.
-
- First I extract a subset of my viruses to diskette. This subset contains
- specimens from all types of viruses.
-
- Direct infectors, viruses that run as TSR, companion infectors, stealth
- viruses, polymorphic, boot sector infectors, etc.
-
- Then I install this generic virus detection software to another diskette,
- then go into my CMOS and deactivate my hard drive temporarily,
-
- I run the generic detection software, then run a virus, run a few small
- files so these files will be infected, then run this generic virus
- detection software If it detects the virus. I go through the same steps
- with another virus. It usually takes a few hours to fully evaluate one of
- these products. After the software has prooven that it can really detect
- new or unkmown viruses without relying on signature scanning, I put it in
- the list of generic virus detection software that I recommend.
-
- Since there are several different ways to detect viruses with generic
- methods, It isn't easy to use a % scale like I use for the scanner
- certifications.
-
- 1. Integrity checking as used in Integrity Master, Untouchable, and Victor
- Charlie.
-
- 2. TSRs like PC-Rx and PC-cillin that looks for virus like activities.
-
- Hooked interrupts
- Access to the boot sector
- access to the partition table
- programs loading as TSR
- tampering with executable files
- and more.
-
- 3. trying to get infected on purpose like Victor Charlie
-
- Bill
-
- - ---
- * WinQwk 2.0 a#383 * Hacked version of Telegard TG29EALP.*
-