Big brands slip up in antivirus tests

Kingsoft AntiVirus named worst performer

Many big-brand security products fail to spot commonly-circulating malware, testing outfit has Virus Bulletin found in its latest tests.

A total of 17 out of 32 of antivirus products failed the company's stringent VB100 test, which expects software to detect 100 percent of the commonly-circulating 'WildList' thrown at it without signalling any false positives.

Programs failing included those from Sophos, Kaspersky, Fortinet, Trend Micro, CA Home, and PC Tools, though within this group detection failures varied widely. CA's Home program scored a disturbingly high 40 misses, while the others scored from 8 misses down to only one miss for Kaspersky. PC Tools' Spyware Doctor detected the WildList suite but failed because it falsely identified two files as malware.

The worst performer on test was the relative unknown, Kingsoft AntiVirus, which missed large numbers of malware types, including 120 examples from the WildList, and over 80 percent of the worms and bots it was tested against.

"It was a shock and a concern to see such a poor performance from so many products in this latest round of testing," said John Hawes of Virus Bulletin.

"It is particularly disappointing to see so many major products missing significant real-world threats. In these days of hourly updates computer users really ought to be able to rely on their chosen security vendors for full protection against known threats."

The tests were run on Windows 2000 using a variety of worms, viruses, bots, and polymorphic malware though the company said it rated the issues as being independent of platform. A program failing to spot a particular piece of malware on one platform would be unlikely to spot it running on another, such as XP, because the detection system would be the same.

"Once the products are up and running, the detection engines should in much operate the same way on all systems - we use the default settings applied by the products," said another company source.

"The main problem here was with some particularly tricky polymorphic viruses listed as 'In the Wild' by the WildList organization, with many products detecting some but not all files infected by the malware. There were also several clean files wrongly labelled as malware. Both these problems will have been repeated on XP, Vista, and probably other platforms too."

Not everyone agrees that the WildList, used by the VB100 tests, is a representative sample of real-world malware. The list excludes certain types of malware such as Trojans, backdoor rootkits. Moves are afoot to come up with a consistent set of tests for such malware based on behavioral characteristics rather than specific signatures.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

John E. Dunn

Techworld.com
Show Comments

Cool Tech

Breitling Superocean Heritage Chronographe 44

Learn more >

SanDisk MicroSDXC™ for Nintendo® Switch™

Learn more >

Toys for Boys

Family Friendly

Panasonic 4K UHD Blu-Ray Player and Full HD Recorder with Netflix - UBT1GL-K

Learn more >

Stocking Stuffer

Razer DeathAdder Expert Ergonomic Gaming Mouse

Learn more >

Christmas Gift Guide

Click for more ›

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Walid Mikhael

Brother QL-820NWB Professional Label Printer

It’s easy to set up, it’s compact and quiet when printing and to top if off, the print quality is excellent. This is hands down the best printer I’ve used for printing labels.

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?