Zscalerのブログ

Zscalerの最新ブログ情報を受信

Security Research

Best And Worst Antivirus Against Fake AV Malware

image
JULIEN SOBRIER
September 30, 2010 - 2 分で読了
The detection rate for fake antivirus malware amongst antivirus vendors is usually below 25%. I was curious to see which AV engines were the best and worst, when it comes to blocking malicious fake AV executables. In order to figure it out, I obtained 16 different samples which I uploaded to VirusTotal in order to get the detection information on 43 AV engines.

Before I get into the results, it is interesting to note that fake AV perpetrators often reuse the same names for different executables. For example, the malicious executable scanner.exe, was found with different file sizes, which resulted in different AV detection results, depending on where the executables came from. The opposite is also true. The same exact file (same size, same MD5) was found on different domains under different names. I made sure my 16 samples were indeed different files to not skew the comparison.

Image
VirusTotal - Detection information for one sample
No absolute protection

The average detection rate was found to be 30%. The detection rate for each sample varied from 12% to 49%.

The best AV engine detected 13 of the 16 samples (81% detection rate). Only 13 out of the 43 AV software detected at least 50% of the samples.



Image
Click on the image to see the detection rate for all AV software
Best AV solutions

The best AV solution to detect fake AV malware is Sophos, with an 81% detection rate, followed by Sunbelt (75%).

Image
5 best AV solutions against fake AV malware

The 13 AV engines which detected at least 50% of the malicious executables are (in alphabetical order):
  1. AhnLab-V3
  2. AntiVir
  3. BitDefender
  4. F-Secure
  5. GData
  6. Kaspersky
  7. NOD32
  8. PCTools
  9. Sophos
  10. Sunbelt
  11. Symantec
  12. TrendMicro
  13. TrendMicro-HouseCall
Worst AV software

The following 7 AV engines did not detect any of the samples:
  1. ClamAV
  2. eSafe
  3. Fortinet
  4. Jiangmin
  5. TheHacker
  6. ViRobot
  7. VirusBuster
AVG, a popular free antivirus, detected 19% of the samples, the same as McAfee.

Conclusion

The AV vendors need to step up and improve their detection. Samples are easily found. I've explained how to get to the fake AV pages from a Google query of the Hot Trends in previous posts.

-- Julien
form submtited
お読みいただきありがとうございました

このブログは役に立ちましたか?

免責事項:このブログは、Zscalerが情報提供のみを目的として作成したものであり、「現状のまま」提供されています。記載された内容の正確性、完全性、信頼性については一切保証されません。Zscalerは、ブログ内の情報の誤りや欠如、またはその情報に基づいて行われるいかなる行為に関して一切の責任を負いません。また、ブログ内でリンクされているサードパーティーのWebサイトおよびリソースは、利便性のみを目的として提供されており、その内容や運用についても一切の責任を負いません。すべての内容は予告なく変更される場合があります。このブログにアクセスすることで、これらの条件に同意し、情報の確認および使用は自己責任で行うことを理解したものとみなされます。

Zscalerの最新ブログ情報を受信

このフォームを送信することで、Zscalerのプライバシー ポリシーに同意したものとみなされます。