http://www.malware-test.com
AntiSpyware Detection Comparison Report (2006-01-03)
Revision History Revision No. 1.0
Revised By Samplas
Date of Change Jan 3, 2006
Copyright © 2006 Malware-Test Lab. All rights reserved.
Description Create this document.
1
http://www.malware-test.com
Contents Revision History ..............................................................................................1 Test Summary ................................................................................................3 Spyware Sample Collection ..............................................................................5 Detailed Test Report .......................................................................................6 Issues with Vendors ........................................................................................7 Contact Information ........................................................................................7 Appendix A: Test Platform and Testing Subjects ...............................................9 Appendix B: Testing Methodology ..................................................................20
Copyright © 2006 Malware-Test Lab. All rights reserved.
2
http://www.malware-test.com
Test Summary The following table shows detection rate for different antivirus or antispyware vendors. Antivirus or AntiSpyware Software’s Name BitDefender Internet Security v10 ESET NOD32 2.7 Kaspersky Internet Security 6.0 Grisoft AVG Anti-Spyware 7.5 (ewido anti-spyware 4.0) Alwil avast! 4.7 Home Edition (free) Norman Virus Control 5.82 Rising Antivirus 2006 F-Secure Internet Security 2007 Sunbelt CounterSpy 1.5 Panda Internet Security 2007 Spyware Terminator 1.5 (with WinClamAV 1.1) AVIRA AntiVir PersonalEdition Classic 7.0 (free) Trend Micro PC-cillin Internet Security 2007 EMSISoftware a-square free 2.1 (free) McAfee Internet Security 2007 Microsoft Windows Defender 1.1 (free) ZoneAlarm Security Suite 6.5 PC Tools Spyware Doctor 4.0 Trend Micro Anti-Spyware 3.5 SUPERAntiSpyware 3.4 AhnLab SpyZero 2007 Comodo AntiVirus 1.1 (free) Webroot Spy Sweeper 5.2 Symantec Norton Internet Security 2007 Lavasoft Ad-Aware SE Personal (free) CA Internet Security 2007 (antispyware part only) CyberDefender AntiSpyware 2006 Outpost Firewall Pro 4.0 Tenebril SpyCatcher Express 4.0 (free) TrojanHunter 4.6
Copyright © 2006 Malware-Test Lab. All rights reserved.
Detection Rate 94.85% 89.12% 88.86% 88.50% 84.47% 79.41% 69.11% 68.20% 67.51% 65.79% 65.57% 57.57% 49.18% 40.61% 38.35% 33.88% 32.12% 31.70% 28.30% 23.75% 23.45% 17.57% 16.51% 13.33% 12.42% 9.92% 3.08% 0.93% 0.52% 0.00%
3
http://www.malware-test.com For detailed information, please refer to the Detailed Test Report section.
Copyright © 2006 Malware-Test Lab. All rights reserved.
4
http://www.malware-test.com
Spyware Sample Collection In this report, the samples we use are collected daily from Honeypot.
Copyright © 2006 Malware-Test Lab. All rights reserved.
5
http://www.malware-test.com
Detailed Test Report AntiSpyware Detection Test Total spyware files are 16,126, including spywares, adwares, remote application tools, hacker tools and so on. The following table shows the date-type distribution of all spyware files: Data Type ASPACK EXE PETITE EXE UPX EXE WIN32 EXE WWPACK EXE Others
File Count 164 41 1925 13967 1 1770
If you want to verify our test result, please refer to the following:
For SHA1 value of all spyware files, please download it from our Forum (http://malware-test.com/smf/index.php?board=9.0). For all antivirus or antispyware scan logs, please download them from our Forum (http://malware-test.com/smf/index.php?board=9.0).
Copyright © 2006 Malware-Test Lab. All rights reserved.
6
http://www.malware-test.com
Issues with Vendors Please note the following issues: 1.
Some antispyware or antivirus softwares cannot scan specified folders. Trend Micro PC-cillin 2007 (AntiSpyware part only) SpyBot S&D 1.4 (we cannot test it) McAfee Internet Security 2007 FaceTime X-Cleaner build 38995 (it is available in the deluxe version) ZoneAlarm Security Suite 6.5
2.
Some antispyware or antivirus softwares have no scan log files, so we cannot get accurate scan results, sometimes it will affect test result (perhaps it is incorrect). McAfee Internet Security 2007 Tenebril SpyCatcher Express 4.0 CA Internet Security 2007 CyberDefender AntiSpyware 2006 Outpost Firewall Pro 4.0 (record detection name only) ZoneAlarm Security Suite 6.5 Microsoft Windows Defender 1.1 Symantec Norton Internet Security 2007
3.
Symantec Norton Internet Security 2007 needs to spend long time to take action and has no configuration of action, we do not know why (they can reproduce the problem very easily)?
4.
Avira AntiVir PersonalEdition Classic 7.0 cannot disable alert sound for virus found.
5.
FBM ZeroSpyware needs flash player 7, after we follow their instructions to install it, but we still cannot use it.
6.
Kingsoft Internet Security 2007 has simple-chinese version of registration, so we cannot test it.
Note that if you read above, please help inform the vendors. Thanks.
Contact Information If you have any questions or suggestions about this report or test methodology, please feel free to contact us.
Copyright © 2006 Malware-Test Lab. All rights reserved.
7
http://www.malware-test.com E-Mail:
[email protected]
Copyright © 2006 Malware-Test Lab. All rights reserved.
8
http://www.malware-test.com
Appendix A: Test Platform and Testing Subjects Malware-Test Lab uses the following specification in producing any data presented in this document.
OS: Windows XP Profession, English Version with Service Pack 2. IE Version: 6.0 with Service Pack1. Test Machine: Intel® Core™2 CPU with 2GB RAM.
List of Antivirus vendors to be tested and their setting at the time being tested:
All antivirus or antispyware softwares are tested by using full scanning capabilities and the default settings are not used.
AhnLab SpyZero 2007
Alwil avast! 4.7 Home Edition (free)
Copyright © 2006 Malware-Test Lab. All rights reserved.
9
http://www.malware-test.com
AVIRA AntiVir PersonallEdition Classic 7.0 (free)
BitDefender Internet Security v10
Copyright © 2006 Malware-Test Lab. All rights reserved.
10
http://www.malware-test.com
CA Internet Security 2007 (antispyware part only)
Comodo AntiVirus 1.1 (free)
CyberDefender AntiSpyware 2006
EMSISoftware a-square free 2.1 (free)
Copyright © 2006 Malware-Test Lab. All rights reserved.
11
http://www.malware-test.com
ESET NOD32 2.7
F-Secure Internet Security 2007
Copyright © 2006 Malware-Test Lab. All rights reserved.
12
http://www.malware-test.com
Grisoft AVG Anti-Spyware 7.5 (ewido anti-spyware 4.0)
Kaspersky Internet Security 6.0
Copyright © 2006 Malware-Test Lab. All rights reserved.
13
http://www.malware-test.com
Lavasoft Ad-Aware SE Personal (free)
McAfee Internet Security 2007
Copyright © 2006 Malware-Test Lab. All rights reserved.
14
http://www.malware-test.com
Microsoft Windows Defender 1.1 (free)
Norman Virus Control 5.82
Outpost Firewall Pro 4.0
Copyright © 2006 Malware-Test Lab. All rights reserved.
15
http://www.malware-test.com
Panda Internet Security 2007
PC Tools Spyware Doctor 4.0
Rising Antivirus 2006
Copyright © 2006 Malware-Test Lab. All rights reserved.
16
http://www.malware-test.com
Spyware Terminator 1.5 (with WinClamAV 1.1)
Sunbelt CounterSpy 1.5
SUPERAntiSpyware 3.4
Copyright © 2006 Malware-Test Lab. All rights reserved.
17
http://www.malware-test.com
Symantec Norton Internet Security 2007: No information
Tenebril SpyCatcher Express 4.0 (free)
Trend Micro Anti-Spyware 3.5
Trend Micro PC-cillin Internet Security 2007
TrojanHunter 4.6
Copyright © 2006 Malware-Test Lab. All rights reserved.
18
http://www.malware-test.com
Webroot Spy Sweeper 5.2
ZoneAlarm Security Suite 6.5
Copyright © 2006 Malware-Test Lab. All rights reserved.
19
http://www.malware-test.com
Appendix B: Testing Methodology Please refer to http://www.malware-test.com for detailed test methodology.
Copyright © 2006 Malware-Test Lab. All rights reserved.
20