[Avcheck] Eicar detection by different antivirus software

Michael Tokarev mjt@tls.msk.ru
Mon, 14 Jan 2002 17:39:32 +0300


Sergey Akhapkin wrote:
> 
[]
> Ok. I'm try to explain such behaviour of our product. Our customers
> wait from our antivirus a good detection of viruses. They don't know
> (and don't want to know) about correct MIME header and about MIME :) -
> they just a users of PC.
[]
> As you can see in previous version we dont detect (correctly from view
> mail standards) virus in second message, but our customers asks us for it.
> 
> 1) Should we detect viruses in such cases ?
> 
> The answer for this question is differs from view points:
> - from mail standard - NO,
> - from our customers view - YES.
> 
> 2) Is it bad that we try to detect all possible viruses transports ?
> 
> I think no - it's good, very good. For special cases then one man
> (professional) want to send virus to other professional he will to make
> password protected archive - all antivirus software wouldn`t to be
> able to detect such virus.

Oh, thank you very much for great explanation.  Well, I agree here -- as
I suspected earlier, this is a feature of drweb, for users who want and
need no expirience in comuter hacking... ;)  So yes, drweb behaviour here
is good, very good.  For professionals like we all are ;), it may be
unwanted behaviour, but we can deal with that, easily, can we? ;)

Thank you!

Regards,
 Michael.