Blog Zscaler

Recevez les dernières mises à jour du blog de Zscaler dans votre boîte de réception

Security Research

Best And Worst Antivirus Against Fake AV Malware

image
JULIEN SOBRIER
septembre 30, 2010 - 2 Min de lecture
The detection rate for fake antivirus malware amongst antivirus vendors is usually below 25%. I was curious to see which AV engines were the best and worst, when it comes to blocking malicious fake AV executables. In order to figure it out, I obtained 16 different samples which I uploaded to VirusTotal in order to get the detection information on 43 AV engines.

Before I get into the results, it is interesting to note that fake AV perpetrators often reuse the same names for different executables. For example, the malicious executable scanner.exe, was found with different file sizes, which resulted in different AV detection results, depending on where the executables came from. The opposite is also true. The same exact file (same size, same MD5) was found on different domains under different names. I made sure my 16 samples were indeed different files to not skew the comparison.

Image
VirusTotal - Detection information for one sample
No absolute protection

The average detection rate was found to be 30%. The detection rate for each sample varied from 12% to 49%.

The best AV engine detected 13 of the 16 samples (81% detection rate). Only 13 out of the 43 AV software detected at least 50% of the samples.



Image
Click on the image to see the detection rate for all AV software
Best AV solutions

The best AV solution to detect fake AV malware is Sophos, with an 81% detection rate, followed by Sunbelt (75%).

Image
5 best AV solutions against fake AV malware

The 13 AV engines which detected at least 50% of the malicious executables are (in alphabetical order):
  1. AhnLab-V3
  2. AntiVir
  3. BitDefender
  4. F-Secure
  5. GData
  6. Kaspersky
  7. NOD32
  8. PCTools
  9. Sophos
  10. Sunbelt
  11. Symantec
  12. TrendMicro
  13. TrendMicro-HouseCall
Worst AV software

The following 7 AV engines did not detect any of the samples:
  1. ClamAV
  2. eSafe
  3. Fortinet
  4. Jiangmin
  5. TheHacker
  6. ViRobot
  7. VirusBuster
AVG, a popular free antivirus, detected 19% of the samples, the same as McAfee.

Conclusion

The AV vendors need to step up and improve their detection. Samples are easily found. I've explained how to get to the fake AV pages from a Google query of the Hot Trends in previous posts.

-- Julien
form submtited
Merci d'avoir lu l'article

Cet article a-t-il été utile ?

Clause de non-responsabilité : Cet article de blog a été créé par Zscaler à des fins d’information uniquement et est fourni « en l’état » sans aucune garantie d’exactitude, d’exhaustivité ou de fiabilité. Zscaler n’assume aucune responsabilité pour toute erreur ou omission ou pour toute action prise sur la base des informations fournies. Tous les sites Web ou ressources de tiers liés à cet artcile de blog sont fournis pour des raisons de commodité uniquement, et Zscaler n’est pas responsable de leur contenu ni de leurs pratiques. Tout le contenu peut être modifié sans préavis. En accédant à ce blog, vous acceptez ces conditions et reconnaissez qu’il est de votre responsabilité de vérifier et d’utiliser les informations en fonction de vos besoins.

Recevez les dernières mises à jour du blog de Zscaler dans votre boîte de réception

En envoyant le formulaire, vous acceptez notre politique de confidentialité.