This article is from the Computer viruses FAQ, by David Harley D.Harley@icrf.icnet.uk, George Wenzel gwenzel@telusplanet.net and Bruce Burrell bpb@umich.edu with numerous contributions by others.
CARO - Computer Anti-Virus Research Organisation. Invitation-only
group of techie researchers, mostly representing AV vendors. CARO
approves 'standard' names for viruses. Some people tend to mistrust
the fact that CARO members often share virus samples: however, CARO
membership is a convenient yardstick by which other members can
judge whether an individual can be trusted with samples. In general,
users at large benefit: this way, AV vendors with CARO members can
include most known viruses in their definitions databases.
EICAR - European Institute for Computer AntiVirus Research. Membership
comprises academic, commercial, media, governmental organisations etc,
with experts in security, law etc., combining in the pursuit of the
control of the spread of malicious software and computer misuse.
Membership is more open, but members are expected to subscribe to a
code of conduct. And yes, this is the origin of the EICAR test file.
EICAR has a web page at http://www.eicar.org/
 
Continue to: