Threats Independently Tested Service
The answer is quite simple...
1. Install VM
2. Install XP/Vista on the VM
3. Clone the VM
4. Install different AV packages on the VMs
5. Sysdif the VMs
On a separate VM without AV (also SysDifed) go to various nefarious websites. Best way to get a virus nowadays is search for “cracks” and “keygens” – any top 20 Google results would infect you 100%. Also, do a search for *anything* on Emule, and save all the <100 KB exe files.
Download a bunch of “Keygens”, and save the EXE files. Run Sysdif again, and find all the lovely EXEs dropped by browser vulnerabilities. Save those. Restart the VM a couple of times to make sure dropped EXEs download more EXEs, save those too. By now, you would have at least 50 “current” viruses. (To get even more, setup compromised email account, and run everything that comes as attachments, and click on all the links)
Now that we have a whole bunch of Viruses, and spyware, key loggers, and so on, we can do the actual tests
6. One by one, run each of the EXEs on a VM with AV product on test.
7. After each EXE, sysdif the machine (even if AV claimed to have eradicated a threat)
8. Save the results in xls, plotting a nice graph, that will show... that not a single AV package will protect you from all the threats.
The problem with the AV industry is that they tend to cater to Joe Blogs who reads the sun online and Jane from accounts, who looks for carrier change as a lion tamer. That’s it. The Viruses that those individuals are likely to come across will be long discovered by the AV companies, and in most cases added to the signature database. They tend not to search for MP3’s nor do they try to download a no cd crack for a game they copied from a friend. But that is where “it’s all at”.
This AV industry status quo is shattered when you through a teenager in the mix. And bam! Your home computers are well and truly screwed! I mean, which teenager will refuse a file called “best joke ever.exe” from a random contact on MSN?
To this end, I call for El Reg to setup “Threats Independently Tested Service” I for one, would gladly contribute by submitting all the nasty malware I come across, and believe you me, that is plenty!