Explanation
Notes
The statistics that are listed here are the Day0 test. I.E. what are the results on the day that we acquire any binary and is tested. We also have included all the re-test results over the same calendar day. Each vendor should improve as they start detecting the older and more common malicious binaries.
Each of the vendor's update process is executed prior to each run to ensure that the latest virus signatures are loaded for our tests.
The tables on each page represent the results of the Anti-Virus tests against the malware that we collect each day. Each AV vendor has different capabilities and success in detecting malware that is collected. No single vendor detects 100%, nor can they ever. To expect complete protection will always be science-fiction.
That being said, you can see the different statistics of the different vendors in our charts. It can be confusing since each vendor uses a different name for each infection type and family. All tests are done with the same set of binaries for each vendor. We continue to test each of the binaries until each vendor is able to detect each piece of malware in our repository. Where ever possible we have attempted to contact the vendor for assistance with the command line options that we use. Otherwise we try different options to produce the highest detection rate available from the options.
Time Periods
In all cases the time periods listed for the charts are summarizations for that specific time period. So for the Re-Tests, the time period does not represent the interval for testing. ie, the weekly charts are for the last seven days of processing. The seven day Re-Test chart does not represent that the binaries were re-tested once in that period. It does represent a summarization of the processing and testing of the binaries in that time period.
AV Results for Comparisons
It is difficult to not compare one vendor to the next due to how we have the data structured on the pages. It would be impossible not to try and derive conclusions from those results. While that is the case, our goal is not to create a real comparison site for everyone to try and compete to see which AV vendor is better than the next. There are a multitude of those already, each of which have their own sets of malware to test and rules that they follow for complete their testing. That is not our purpose. We do not have a specific set of malware to test. We instead gather in new malware daily and test it against the different vendors.
The versions of AV engines that we have are as new as the vendor can provide us and updated at least hourly if not more frequently. But they are gateway or fileserver products for the most part. We do have plans for using full consumer AV applications as well, but that will take time and much more in donations to allow us to build the back end for that. We will get to it, just not today.
AV Vendor List
The following Vendor tables show which of the AV vendors we are currently using as well as the engine and signature level of each application. In most cases we are using the command-line-interface versions, gateway versions, or file server versions. These are not the normal home user versions and in some cases are special versions for anti-virus test systems. The data within the tables is being pulled from the live systems and updated twice a day. The actual engines and signatures are attempted to be updated prior to each malware run whether it is from the day0 test or for a retry. So the applications should be as updated as possible before testing occurs.
The current list of AV tools that we use are as follows:
Linux Vendor List
| Vendor | Engine | Signatures | Command Options |
| Authentium | 4.6.5 | 201305180140 | aiscan --nomem --nombr --noboot --all --pua |
| Avast | 3.2.1 | 130518-1 | avastcmd --testall --blockdevices --testfull --archivetype=A |
| AVG | 13.0.3114 | 3162/6335 | avgscan --heur --arc --macrow --pwdw --repok --pup |
| Avira | 8.2.12.44 | 7.11.79.62 | avscan --batch -noboot -nombr -s -rs --scan-in-archive --alltypes --allfiles --without-PCK -nomem --heur-level=3 --alert-action=none |
| BitDefender | 7.2 | 7.47412 | bdc -arc -noclean |
| Clam | 0.97.6 | 17238 | clamscan --no-summary --detect-pua -r |
| DrWeb | 6.0.0.02020 | 7.0.4.9250 | drweb -ar -cn -ha -ok -path=$1 |
| Eset | 3.0.21 | 7679 (20121110) | esets_scan --files --arch --subdir --mail --sfx --rtp --adware --heur --adv-heur |
| FProt | 4.5.1.85 | 201302010107 | fpscan --scanlevel=4 --heurlevel=4 --archive=99 --adware --report |
| FSecure | 2.50 build 11035 | Friday, 17 May 2013_06 | fsav --allfiles=yes --scanexecutables=yes --archive=yes --mime=yes --riskware=yes --virus-action1=report --riskware-action1=report --suspected-action1=report --auto=yes --list=yes |
| Ikarus | 1.04 | 19.05.2013 | t3scan |
| Kaspersky | 8.0.0.35 | Monday, 4 February 2013 | kes4lwks-control --scan-file |
| McAfee | 5400.1158 | 5000 created May 18 2013 | uvscan --recursive --noboot --allole --mime --program --unzip --secure --!guru --!server |
| Norman | 7.1.4 | 2013-17-05 21:39 | mtscan |
| Panda | 9.04.03 | 16/05/2013 | pavcl -auto -nob -cmp -nos -noscr -rpt:$out -aex -heu:1 |
| Sophos | 4.89.0 | 4.89 | savscan -all -archive |
| TrendMicro | 3.00-1009 | Saturday, 18 May 2013 | vscantmrh -S -NC -NM -NB |
| Vexira | 5.5.2.13 | 15.0.385.1 | vascan --all-files --heuristics=high --sfx --action=skip -G |
| VirusBlokAda | 3.12.22.0 | Saturday, 18 May 2013 | vba32.sh -m=3 -af+ -pm+ -rw+ -ha=2 -vm+ -ar+ -sfx+ -ml+ |
| VirusBuster | 5.5.2.13 | 15.0.444.0 | vbscan --all-files --heuristics=high --sfx --action=skip -G |
Windows Vendor List
| Vendor | Engine | Signatures | Command Options |
| AhnLab | Sunday, 19 May 2013.00 | Sunday, 19 May 2013.00 | v3tmedic.exe /scantype:all /cure:off /log |
| Authentium | 4.6.2 | 201305180140 | aiscan.exe --nomem --nombr --noboot --all --pua |
| Avast | command-line scanner | 130518-1 | ashcmd /_ /s /d /p /a /c /i /t=a /x=P /e=100 /r=report |
| AVG | 10.0.3162 | 271/5836 | avgscanx.exe /HEUR /ARC /MACROW /PWDW /REPOK /PUP |
| Avira | 8.2.12.44 | 7.11.79.62 | scancl --nombr /s /z /a --nomem --heurlevel=3 |
| BitDefender | 7.1 | 7.47406 | bdc.exe -arc -noclean |
| Clam | 0.97.3 | 17238 | clamscan --no-summary --detect-pua -r |
| Comodo | 5.1 | 16281 | cavscons /h2 /c |
| DrWeb | 7.00.100.09170/7.00.4.09250 | Saturday, 18 May 2013 21:21 | dwscancl /ar /ha /ok /sls- /sps- |
| Emsisoft | 7.0.0.12 | Saturday, 18 May 2013 | a2cmd.exe /h /r /a /service |
| Eset | 4.2.71.2 | 8348 (20130518) | ecls --files --arch --subdir --mail --sfx --rtp --adware --heur --adv-heur |
| Fortinet | 5.0.43 | 17.655 | vscanner.exe -V -gALL |
| FProt | 4.6.2.117 | 201302012125 | bin64\\MS\\fpscan64.exe -i \\antivir.def --scanlevel=4 --heurlevel=4 --archive=99 --adware --report |
| FSecure | 9.00.17090 | Thursday, 18 April 2013 | scan --archive --adv-heur |
| GData | AVA 22.9742,AVL 22.1714 | 18.05.2013,18.05.2013 | avkcmd.exe /scan(e3): |
| Ikarus | 1.04 | 18.05.2013 | t3scan |
| K7 | 12.7.0.12 | 9.167.8711 | k7cscn32.exe |
| K7GW | 12.7.0.12 | 9.167.8711 | |
| Kaspersky | 6.0.4.1424 | 18052013 0916 | avp.exe SCAN /i0 /fa |
| McAfee | 5400.1158 | 7079 created May 18 2013 | scan.exe /RECURSIVE /NOBOOT /ALLOLE /MIME /PROGRAM /UNZIP /SECURE |
| Microsoft | 1.9506 | Sat May 18 14:20:32 2013 | mpscanp.exe /report /rptall |
| Norman | 5.99.02 | Saturday, 18 May 2013 05:39 | nvcc /BS- /C /CL:0 /N /L:0 /O /SB:1 /U |
| PCTools | 7.0.5.0 | 20130519.022 | SDAVFileScan.exe -v |
| QuickHeal | 11.00 | 18 May, 2013 | qhscan /DNAScan /ARCHIVE /WARE /LIST /PACKED |
| Sophos | 3.27.0 | 4.73G | sav32cli.exe -ndi -ns -nb -all -rec -nremove -eec -sc -f -tnef -mime -oe -pua -suspicious -archive -nmbr -nmem |
| Sunbelt | 3.0 | 17858 | sbscan /f |
| Symantec | 20121.3.0.76 | 2013/5/18 Build: 3 | symscan.exe /defs |
| TrendMicro | 5.00-1024 | Saturday, 18 May 2013 | vscantm.exe /S /NM /NB /NC |
| Vexira | 5.5.2.13 | 15.0.385.1 | vascan --all-files --heuristics=high --sfx --action=skip -G |
| VirusBlokAda | 3.12.22.0 | Saturday, 18 May 2013 | vba32w /mr=0 /as=0 /bt- /m=3 /af+ /pm+ /rw+ /ha=2 /vm+ /ar+ /sfx+ /ml+ |
| VirusBuster | 5.5.2.13 | 15.0.444.0 | vbscan.exe --all-files --heuristics=high --sfx --action=skip -G |
Updates
These reports are updated once a day.
AV Processing Statistics
This chart is the total number of files processed by the AV test system.

Zero AV Detection Statistics
These statistics are the result of AV testing over a 48-hour period and how many files were still not detected by any single vendor. There is a severe change in the results after 2011-07 which is when we added in the Windows AV scanners to our test suite. While on most days the results are not zero, the values are so low as to not be seen in the current chart.

<< | Statistics | >>


