PDA

View Full Version : Active infections treatment test


IlyaOS
July 30th, 2007, 04:00 PM
Hi everybody!

I found another intersting antivirus test that had been made by Anti-Malware Test Lab. They analyzed the ability of popular antivirus programs to treat active infections -- that is, when a malicious program has been executed and installed on a computer and may be using various methods to prevent detection and removal by antivirus solutions.

Award Products

1st place
Norton AntiVirus 2007 (80%)

2nd place
Kaspersky Anti-Virus 6.0 (70%)

3rd place
Avast! Professional Edition 4.7 (50%)
Eset NOD32 Antivirus 2.7 (50%)
Sophos Anti-Virus 6.0 (50%)
BitDefender Antivirus 10 (50%)
AVZ 4.21 (50%)

Poor results
AVG Anti-Virus PE 7.5 (40%)
McAfee VirusScan 2007 (40%)
Panda Antivirus 2007 (40%)
Avira AntiVir СE 7.0 (30%)
Dr.Web Anti-Virus 4.33 (30%)
F-Secure Anti-Virus 2007 (30%)
Trend Micro PC-Cillin 2007 (30%)
VBA32 Antivirus 3.11 (30%)

http://www.anti-malware-test.com/?q=taxonomy/term/14

Testing methodology
For the purposes of testing antivirus programs for the treatment of active infections, the expert group from Anti-Malware.ru selected 10 malicious programs based on the following criteria:

1. Detection of the parent file by all of the antivirus solutions tested.
2. Ability to mask the malicious program’s presence in the system.
3. Ability to interfere with the installation and operation of the antivirus solutions.
4. Ability to recover after deletion some program components.
5. All malicious programs had to be sufficiently widespread and well known.
....

http://www.anti-malware-test.com/?q=node/10
http://www.anti-malware-test.com/?q=node/9

What do you think about this?

trjam
July 30th, 2007, 04:03 PM
I think their is some validity to it, but realize I will get chewed up for saying it.

JerryM
July 30th, 2007, 04:31 PM
I wonder why F-Secure would score so low compared to Kaspersky.
Jerry

lodore
July 30th, 2007, 04:51 PM
{QUOTE-> I wonder why F-Secure would score so low compared to Kaspersky.
Jerry <-QUOTE}
Hi jerry,
maybe its because kaspersky 6 and onwards has advanced disenfection technology?
lodore

Don Pelotas
July 30th, 2007, 04:57 PM
{QUOTE-> Hi jerry,
maybe its because kaspersky 6 and onwards has advanced disenfection technology?
lodore <-QUOTE}
No, i just think it is not a great test..................it's hard to believe the difference would be this big. :)

JerryM
July 30th, 2007, 05:09 PM
I don't know a great deal about these things, but when something looks so far out of line I have to wonder about the worth of the test.

Best,
Jerry

MalwareDie
July 30th, 2007, 05:20 PM
If it's malware-test it can't be reliable

KDNeese
July 31st, 2007, 12:37 AM
Norman beating both Kaspersky AND NOD32??? Give me a break...

MalwareDie
July 31st, 2007, 01:07 AM
{QUOTE-> Norman beating both Kaspersky AND NOD32??? Give me a break... <-QUOTE}

its Norton, not Norman.

IlyaOS
July 31st, 2007, 06:56 AM
{QUOTE-> Hi jerry,
maybe its because kaspersky 6 and onwards has advanced disenfection technology?
lodore <-QUOTE}

The difference between this two product is huge, Kaspersky Anti-Virus 6.0 has special ability to treat some kinds of difficult malware. F-Secure hasn't, because it based on KAV engine only without such technologies.

IlyaOS
July 31st, 2007, 07:03 AM
{QUOTE-> If it's malware-test it can't be reliable <-QUOTE}

It's Anti-Malware Test Lab ;)

MalwareDie
July 31st, 2007, 06:29 PM
{QUOTE-> It's Anti-Malware Test Lab ;) <-QUOTE}

oops Im going blind. I still wonder if they are reliable though. 10 infections is not a lot.

Coolio10
July 31st, 2007, 09:44 PM
It's funny how every time norton/mcafee or any other long hated av products does good than the test has to be fake :D. Face it people, Norton is coming back to own kaspersky. Even in av comparatives its retrospective test is going high.

Be afraid, be very afraid :shifty: .

Ever since 2007 version norton is getting better like before it was bought by symantec. I am not that old but i heard things about it was good before symantec bought it :D.

I am also sure F-secure only shares kaspersky's engine but not its cleaning ability.

I am with you trjam! I am ready to be flamed ;)

JerryM
July 31st, 2007, 09:48 PM
{QUOTE-> It's funny how every time norton/mcafee or any other long hated av products does good than the test has to be fake :D. Face it people, Norton is coming back to own kaspersky. Even in av comparatives its retrospective test is going high.

Be afraid, be very afraid :shifty: .

Ever since 2007 version norton is getting better like before it was bought by symantec. I am not that old but i heard things about it was good before symantec bought it :D.

I am also sure F-secure only shares kaspersky's engine but not its cleaning ability.

I am with you trjam! I am ready to be flamed ;) <-QUOTE}

Hi Coolio10,

Aside from this test, what evidence do you have that FSIS is so inferior to Kaspersky?
This is not an argumentative question, but a search for information.

Thanks,
Jerry

Coolio10
July 31st, 2007, 10:10 PM
{QUOTE-> Hi Coolio10,

Aside from this test, what evidence do you have that FSIS is so inferior to Kaspersky?
This is not an argumentative question, but a search for information.

Thanks,
Jerry <-QUOTE}

You test me :o .

http://support.kaspersky.com/faq/?qid=193239259

Never seen that feature in F-secure though i have never used it :D.

A simple automatic safe mode feature in kaspersky can cause it do much better than F-Secure as many know :D.

Safe mode stops almost all viruses from loading.

JerryM
July 31st, 2007, 10:13 PM
{QUOTE-> You test me :o .

http://support.kaspersky.com/faq/?qid=193239259

Never seen that feature in F-secure though i have never used it :D. <-QUOTE}

Thanks.
Jerry

IlyaOS
August 1st, 2007, 10:44 AM
Come on ... treatment ability is not the same as detection rate.
Norton can miss a lot of malware that kaspersky don't, otherwise Norton will successfully desinfect they.

Guys from Anti-Malware Test Lab got the ten most complicated malware using different method to hide itself from anti-virus. It takes much more time then just scan 10 files on HDD.

Durad
August 1st, 2007, 10:59 AM
I remember few years ago (during virus time) Norton was one of the best for cleaning viruses.

However even during NAV2005-2006 it was rated "the best" by many "independent" testers and we know that at that time Norton was not that good.

I agree with wollowing:

{QUOTE-> Originally Posted by MalwareDie
If it's malware-test it can't be reliable <-QUOTE}