Virus Hunters
It has been 12 years since the first real Internet virus scare. On Nov. 2, 1988, Cornell University graduate student Robert Morris unleashed a 'worm' program that used e-mail protocols to propagate itself across the Internet.
BY KEVIN JOHAH
![]() |
Diagnose the problem
| The Lowdown | ||
by scanning for the signatures or code patterns of known viruses, or by scanning for suspicious behavior. | ||
On the defense
It's all in the content
Kevin Jonah is a network manager and free-lance technology writer in Maryland.
| Company | Product | Type of product | Detection method | Platforms | Update service | Checks e-mail attachments before launch | Detects script files in e-mail | Warning before launching scripts | Deployment tools | Price |
| GFI Fax & Voice USA Cary, N.C. 888-243-4329 www.gfi.com | MailEssentials for Exchange/SMTP | E-mail security, content gateway that removes all types of e-mail threats before they are delivered to users | Content screening | NT, Win 2000 | Automatic | Yes | Yes | Quarantines script files and inline scripts | Deployed at mail server | $275 up for 10 users; government discounts available |
| InDefense Inc. Santa Cruz, Calif. 877-472-3372 www.indefense.com | Achilles' Shield | Behavior-based intrustion detection | Analyzes any unknown code, alerts users of intrusive tendencies, can certify good known code | NT, Win9x, Win 2000 | Not required; upgrades available | Yes | Yes | Yes | Network administration program with log-in scripting | $29 per user, $1,500 for 100 users; $2,500 for 1,000 users |
| Network Associates, Inc. Santa Clara, Calif. 888-847-8766 www.nai.com | McAfee Active Virus Defense | Scans for viruses at Internet gateway, groupware server, file server, desktop PC and PDA | Scans for known viruses by signature and by heuristic analysis of the code | NT 4.0, Win9x, Win 2000, WinCE, Palm OS, NetWare, Unix, Linux, Microsoft Exchange, MS-DOS Lotus Domino | Automatic, with options for scheduling and for selecting download locations | Yes; also checks them before they reach recipient | Yes, at the Internet gateway e-mail server | No | Through McAfee ePolicy Orchestrator, or through software deployment tools such as Microsoft SMS | $70 up per seat for 2-year license; PC and PDA $105 up per seat for perpetual license; both prices 50-100 users; discounts for larger volumes |
| Roxio Inc. Milpitas, Calif. 408-259-7694 www.roxio.com | GoBack Enterprise Edition 2.23 | A system-undo software package; does not screen for viruses, but can return a system to pre-virus state | No | NT, Win9x, Win 2000, Win Me | Updates on Web site | No | N/A | No | Network installation | $63 for 1 user; $265 for 5; $487 for 10; $2,095 for 50 $3,832 for 100 $14,995 for 1,000 |
| Sophos Inc. Wakefield, Mass. 781-213-3456 www.sophos.com | Sophos Anti-Virus (OS-based) | SWEEP provides on-demand and scheduled virus checking of files on file servers or workstations; InterCheck provides local on-access virus-checking on workstations and server-based on-access virus-checking for networked workstations; Sophos Anti-Virus Interface allows third-party software developers to integrate their firewalls, gateways and similar applications | Scans for known viruses by signature, using file scanning and pattern recognition | For servers: NT, Win 2000, NetWare, OS/2,Unix, OpenVMS; For clients: Win9x, NT,Win 2000, OS/2, Mac OS, MS-DOS Windows 3.1 | Yes | Yes | No | Will not let a known malicious script run | Via central installation on network and provided admin tool | $1,495 for 50 users |
| Sybari Software Inc. East Northport, N.Y. 631-630-8500 www.sybari.com | Antigen for Exchange; Antigen for Lotus Notes | Mail server virus protection provides mail attachment filtering and content checking | Content screening | NT and Win 2000 with Exchange Server 5.0 and up; NT, AIX and Solaris with Lotus Notes | Automatic or on-demand | Yes | Yes | Yes, will quarantine scripts | None (through mail server) | $4,995 for 250 users with a two-year license |
| Symantec Corp. Cupertino, Calif. 408-253-9600 www.symantec.com | Norton AntiVirus Corporate Edition 7.5 | Desktop and server virus detection and prevention; allows administrators to centrally deploy to clients; provides centralized event logging | Scans for known viruses by signature, using file scanning and pattern recognition | MS-DOS, Win 3.x, Win9x, NT, Win 2000, NetWare | Scheduled and on-demand | On Notes, Outlook, cc:Mail | Yes | No | Through management console or HTTP intranet deployment | Based on site licensing requirements |
| Trend Micro Inc. Cupertino, Calif. 800-228-5651 www.antivirus.com | Interscan Virus Wall | Internet gateway; stops viruses and other malicious code in SMTP, HTTP and FTP traffic before it gets to servers and users; optional eManager adds spam blocking, content filtering, and e-mail scheduling | Scans for malicious activity using signature pattern matching or behavioral analysis | NT, Solaris, Linux, HP-UX | Scheduled or on-demand updates via the Internet or regular mail | Yes | Yes | No | Managed through browser or Windows-based management console | $725 up for 25 users |
| Scan Mail for Exchange; ScanMail for LotusNotes | ScanMail for Exchange detects and cleans viruses from inbound and outbound e-mail on the Exchange server in real time and provides manual and scheduled scans of the information store database; ScanMail for LotusNotes detects and removes viruses hidden in Notes mail, shared databases and during Notes replication | Scans for malicious activity using signature pattern matching or behavior analysis | NT 4.0 and Win 2000 for Exchange; NT, Solaris, OS/390, AIX and OS/2 for Notes | Scheduled or on-demand via the Internet or regular mail | Yes | Yes | No | Managed through browser or Windows-based management console | $600 up for 25 users |





