Subscribe to the Free Print Edition!
Celebrating 25 Years

Four antivirus programs depth-charge viruses before they can infect

By Greg Crowe, Special to GCN

These virus detectors each have speed, simplicity, intuition and tools

Antivirus programs used to be judged by how many viruses they could detect. That’s no longer the case. Nowadays any vendor that is receiving suspect files from users on a daily basis can keep its virus definitions up to date.

Product differences lie in the efficiency of the scanning engines and the ease of the interfaces. Some products take a guide-users-by-the-hand approach. Others give users greater control but also a bigger risk of getting lost.

I tested four antivirus programs on a 2-GHz Pentium 4 system with 512M of RAM, Microsoft Windows XP and a T1 Internet connection. I put each product through the same four procedures: installation, download of updates, scanning, then removal.

As each product was installed and uninstalled in turn, the total number of files in a full drive scan would vary slightly. So, to compare scanning speed and efficiency accurately, I created a 1,795-file test folder with virtually every kind of file extension.

Hide and seek

It wouldn’t be an antivirus test without viruses. To fill the bill, I downloaded test viruses from neutral organizations on the Internet and hid three in different places in my test folder: right up front, several folders deep and inside a zipped file.

I’m happy to report that all four products found all three viruses, and all claimed to scan the 1,795 files in the folder. There were minor philosophical differences between programs as to whether the single file inside the zipped file should be counted in addition to the zipped file itself.

Some products required registration at installation or at update, and total installation time reflected how long I spent filling out the electronic forms. A lengthy update might only mean a particular program came out in advance of a significant engine upgrade. So I gave that statistic less weight.