Hello listers. Since HJ has made their recommendation regarding which AV product to
use I felt I'd better step in and put
in my two cents. One the functions of my job is to handle all of the virus security
for our company. I have spent four
years collecting viruses and studying them to see how they work and I have evaluated
several different AV packages for
not only their detection and disinfection capabilities, but also for their
speech-friendliness so that I can use them
effectively. Bare with me for a moment while I explain something about AV programs.
Although most of you already
know this I feel it would help if I spelled it out anyway. All antivirus packages
consist of a minimum of two components.
Some have more than these two, but almost all of them have at least these two. The
first can be thought of as an on-
demand virus scanner. This component does not stay in memory. It only works when you
tell it to workor if a scheduler
runs it automatically. this is the component that scans your hard drive for viruses.
If it finds one you can decide what to
do next. The second component is the background scanner. This is the part of the
program that resides in your
computer's memory scanning every program or document, (depending on what type of
document it is), when you try to
open it. iN this way the AV program can catch a virus before it spreads. Having said
all of this we can now go on to
speech-friendliness. Most AV packages, Mcafee, Norton, DR Solomon, ANtiviral Toolkit
Pro, Vet, Thunderbyte etc, are
speech-friendly where the on-demand scanner is concerned. You can initiate a scan and
you can read the dialogue box
that pops up if a virus is found and select what action you wish to take. Where the
real speech issue comes into play is
when the background scanner finds a virus. An example would be if you click on Eudora
to run it and the background
scanner finds a virus in Eudora.exe. The two most popular AV packages, Norton and
Mcafee, will lock your system
when the background scanner finds a virus. Now your speech is gone. A dos message
box appears on the screen
saying that a virus has been found, but you can not read it with your screen reader.
If there is no sighted assistence
available you are now thrown into a guessing game with your computer's well being at
stake. What blind people who
use these packages do is take a chance and hit r for repair and then the speech comes
back. This may sound okay,
but the problem comes into play especially with Norton. Norton's background scanner
not only scans for viruses, but
also virus-like activity. This means that in our previous example when you click on
eudora.exe and Norton locks your
computer you don't know if Norton has locked your computer because it has found a
virus or because eudora.exe has
been replaced with some trojan horse program that is trying to alter the bootsector of
your hard drive so simply hitting r
may not solve the problem because you are trying to solve the wrong problem. For this
reason I personally do not
recommend Mcafee or Norton as your primary AV program. This doesn't mean that they
are worthless. ON the contrary,
they are both viable programs for their on-demand scanners, but not for their
background scanners. DR Solomon is a
nother good product, but as someone pointed out it has been purchased by Network
associates who owns Mcafee and
the idea is to meld the two products together. The reasoning is that Dr Solomon is a
far superior product to Mcafee in its
detection and disinfection ability, but where it has traditionally failed is that it
is very hard to get updates. It does not
have any built-in functionality to update itself over the internet which Mcafee does.
Thus they are combining the power
of DR Solomon with the ease of use and updating of Mcafee.The program that I use as my
primary AV program is
antiviral Toolkit Pro. The reason why I use it is because its background scanner does
not lock the system. If the
background scanner finds a virus JFW keeps right on talking and I can decide how to
handle the situation. Also, it is
updated almost weekly and this updating can be done right over the net. It's
detection and disinfection rates are way up
at the top with some other programs and all of the features work with JFW with no
scripting. I also use Norton 5.0 as a
second on-demand scanner because it is a very good product and it is good practice to
have more than one AV
program, (similar to getting a second opinion when a doctor says you have a disease.)
Note that I specified that I use
Norton only for its on-demand scanner. This is because #1, you should never have two
background virus scanners
running at once and #2, its background scanner locks speech when it finds something.
Again these are only my
personal opinions, but I thought some clarification about how AV products work with
relation to speech was necessary.
When considering the purchase of an AV package be aware that just because you can use
its on-demand scanner
easily with speech that is not the whole story. There is still the matter of what the
background scanner will do to your
screen reader if it finds a virus. Try different programs to see how they perform
under these conditions. Okay, you're
probably asking, "How will I know if the background scanner will lock my speech unless
I have a real virus to test it
with?" Fortunately there is a way to do this. Many AV packages can detect a dummy
virus called the EICAR standard
virus. EICAR stands for the european Institute for Computer Antivirus Research and it
is not a virus at all. Rather it is a
dummy file that AV programs will detect as a virus so you can test your scanner. Here
is how to make it. Open up
notepad or another text editor and put in only the following line. Hint, you can cut
and paste it right from this email into
notepad.
X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*
Now save the file as plain text and rename it to eicar.com and you are all set. Now
you can test your on-demand and
background scanners for screen reader compatibility. I know I have been kind of
long-winded here, but I hope some of
you find this clarification useful and ehlpful.
--Bob
-
Visit the jfw ml web page: http://yoyo.cc.monash.edu.au/~nallan/jfw