10/27/2008

how good are free antiviruses against new malware binaries ?

Missed = Malware binary miss count
Missed Logs = Full list of all missed malware binaries
Detects = Antivirus system overall detection rate based on exposure to 3740 malware  binaries from this honeypot (those in red that are good enough are free)

These detection rates represent the TRUE POSITIVE detection rates of these various antivirus tools on the limited corpus of malware binaries captures by our honeynet. The results do not take into consideration the false positive rate of a given tool, and thus a tool that declares everything to be infected would appear to have the highest true positive percentage rate. All antivirus results provided via www.virustotal.com

This list changes very frequently

RankDetectsMissedMissed LogProductVendorCCProduct URL
1st96%117AntiVir_Missed_MD5s.htmlAntiVirAvira www.free-av.com
2nd94%190Ikarus_Missed_MD5s.htmlIkarusIkarus Security Software www.ikarus-software.at (german)
3rd93%238BitDefender_Missed_MD5s.htmlBitDefenderBitDefender Inc www.bitdefender.com
4th93%262AVG_Missed_MD5s.htmlAVGGrisoft Inc www.grisoft.com
5th91%320F-Secure_Missed_MD5s.htmlF-SecureF-Secure Corporation www.f-secure.com
6th90%360Avast_Missed_MD5s.htmlAvastALWIL Software www.avast.com
7th90%373Norman_Missed_MD5s.htmlNormanNorman Inc www.norman.com
8th89%378Sophos_Missed_MD5s.htmlSophosSophos Labs www.sophos.com
9th87%482ClamAV_Missed_MD5s.htmlClamAVSourceFire www.clamv.net
10th86%502Microsoft_Missed_MD5s.htmlMicrosoftMicrosoft Corporation www.microsoft.com
11th86%513Kaspersky_Missed_MD5s.htmlKasperskyKaspersky Lab www.kaspersky.com
12th85%558CAT-QuickHeal_Missed_MD5s.htmlCAT-QuickHealQuick Heal Technologies quickheal.co.in
13th84%564DrWeb_Missed_MD5s.htmlDrWebDr. Web www.drweb.com
14th84%587VirusBuster_Missed_MD5s.htmlVirusBusterVirusBuster Ltd www.virusbuster.hu
15th83%624Fortinet_Missed_MD5s.htmlFortinetFortinet Inc www.fortinet.com
16th82%644Symantec_Missed_MD5s.htmlSymantecSymantec Corporation www.symantec.com
17th82%668Rising_Missed_MD5s.htmlRisingBeijing Rising International Software www.rising-global.com
18th81%691F-Prot_Missed_MD5s.htmlF-ProtFrisk Software International www.f-prot.com
19th80%713eTrust-Vet_Missed_MD5s.htmleTrust-VetComputer Associates www.ca.com
20th80%720Webwasher-Gateway_Missed_MD5s.htmlWebwasher-GatewaySecure Computing www.securecomputing.com
21st77%838McAfee_Missed_MD5s.htmlMcAfeeMcAfee Inc www.mcafee.com
22nd77%856Authentium_Missed_MD5s.htmlAuthentiumAuthentium www.authentium.com
23rd76%890AhnLab-V3_Missed_MD5s.htmlAhnLab-V3AhnLab www.ahnlab.com
24th75%899TheHacker_Missed_MD5s.htmlTheHackerHacksoft www.hacksoft.com.pe
25th75%906Panda_Missed_MD5s.htmlPandaPanda Security www.pandasecurity.com
26th75%913VBA32_Missed_MD5s.htmlVBA32VirusBlokAda Ltd www.anti-virus.by/en
27th65%1300TrendMicro_Missed_MD5s.htmlTrendMicroTrend Micro www.trendmicro.com
28th59%1523NOD32v2_Missed_MD5s.htmlNOD32v2ESET LLC www.eset.com
29th37%2356Ewido_Missed_MD5s.htmlEwidoEwido Networks www.ewido.net (now avg)
30th25%2782Prevx1_Missed_MD5s.htmlPrevx1Prevx Corporation www.prevx.com
31st5%3521Sunbelt_Missed_MD5s.htmlSunbeltSunbelt Software www.sunbelt-software.co
32nd0%3741FileAdvisor_Missed_MD5s.htmlFileAdvisorBit9.com fileadvisor.bit9.com

12:42 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

Post a comment