Virus Bulletin
Copyright © 2016 Virus Bulletin
It was an all-new platform for this month's VB100 comparative, with our first look at Microsoft's latest server‑grade operating system variant, Windows Server 2016. Although the platform was officially released only shortly before the test got under way, previews had been available for some time, and being largely similar to the widely deployed desktop equivalent Windows 10, we hoped that security developers would have had plenty of time to ensure their products supported the new environment to the full. However, any new setup will inevitably bring some surprises, so we were more than usually keen to see just how well products would perform this month.
Installation, as usual using standard install media acquired through the MSDN programme, proved fairly simple, and the preparation of our test systems, including the addition of our standard selection of common tools, went smoothly too. Trials of our test automation systems, such as our performance measurement tools, brought up nothing untoward either, with all necessary tweaks already having been made for Windows 10 testing. However, one major change in the platform was clear from the start: for the first time on a Windows Server platform, the built-in Windows Defender anti-malware solution was enabled by default. With many of our regular participants having warned us to watch out for this, alerting us to the fact that many of them had not been provided with suitable means of disabling the protection automatically, and that there had been numerous reports of disabled setups reverting unexpectedly to an enabled state, we opted to shut Defender down for ourselves and monitor its status closely throughout testing.
As is our standard approach for speed and performance measures, baselines were taken with the system in its default state, which in this case meant with Defender enabled. The aim of this approach is to enable users to judge how much of an impact each solution has on the speed of a standard system compared to a basic, unmodified installation. This time, however, we quickly noticed something of a problem – almost every product appeared to be running much faster than the baseline times, with significantly lower resource usage too.
The resulting flood of negative numbers made our usual speed graphs rather difficult to read, and after some analysis and consideration we eventually decided to break from our standard practice and rebuild the baseline measures using unprotected, bare systems rather than the default setup for the chosen platform. This gave us a much more easily consumed set of speed data for this report. To give some indication of how Windows Defender fits into the picture, we've included for reference in the main performance and on-access lag time charts the performance numbers that were originally intended to be baselines, although as Defender was not officially submitted for testing, no full set of detection data is available.
The test deadline was set for 2 November, a little later than usual due to the VB conference having taken up a lot of our time in October. Our sample sets were frozen on 2 November and we used the latest WildList available at the time, v4.033. As always, our clean sets were updated and tidied in preparation for the test, with the latest version comprising around 850,000 files and 180GB of data.
With all preparations complete, we settled down to find out how the products would fare on the new platform.
Main version: 9.0.22.7 build 919
Update versions: 2016.11.02.01, 2016.06.25.00, 2016.11.23.05, 2016.11.29.04
Last 6 tests: 1 passed, 0 failed, 5 no entry
Last 12 tests: 3 passed, 0 failed, 9 no entry
ItW on demand: 100.00%
ItW on access: 100.00%
False positives: 0
Stability: Stable
AhnLab's products tend to pop up in our tests at fairly random intervals, but generally put in decent performances. The latest server edition looks slick and glossy with a clean and clear layout, and proved to run pretty smoothly on Windows Server 2016 with only a single incident of the product GUI crashing out. Our performance measures showed pretty low use of resources and a fairly sizeable slowdown of our set of standard tasks, although they still ran through a good bit faster than with Windows Defender operational. File read times were also a little slow on first encounter of items, but again mostly better than with Defender enabled, and they sped up considerably on repeat runs. Scanning speeds looked decent too, particularly over the local system partition.
Detection was strong in the response sets, dropping off fairly considerably in the offline reactive sets. The core certification sets were handled nicely though, and AhnLab kicks off this month's test with a VB100 award.
Main version: 12.3.2515 build 12.3.3154.0
Update versions: 161102-0, build 12.3.3154.23/161116-0, 161122-0, 161128-0
Last 6 tests: 6 passed, 0 failed, 0 no entry
Last 12 tests: 12 passed, 0 failed, 0 no entry
ItW on demand: 100.00%
ItW on access: 100.00%
False positives: 0
Stability: Stable
Avast is a much more regular participant in our tests, with a 100% pass rate in recent years. The vendor's business edition has a slick and attractive appearance that is similar to that of its home‑user offerings, with simplicity on the surface and a wealth of configuration options available. The product demonstrated good stability for the most part – the only issue noted occurred at the end of the offline RAP test, when the entire machine froze and required a reboot. This was not reproducible however, and occurred at a time of high stress, so didn't dent the stability rating too heavily.
Speeds were not the fastest on demand, but on-access lag times were light, especially in the warm runs. RAM usage was low, CPU use a little high, and our set of tasks ran through a touch slowly. Detection was strong in the response sets, tailing off somewhat in the offline part of the sets. The certification sets presented no difficulties though, and Avast maintains its clean run of passes.
Main version: 15.0.23.58
Update versions: 8.12.131.62, 8.12.134.48, 8.12.136.252, 8.12.138.86
Last 6 tests: 3 passed, 1 failed, 2 no entry
Last 12 tests: 7 passed, 1 failed, 4 no entry
ItW on demand: 100.00%
ItW on access: 99.68%
False positives: 0
Stability: Solid
Avira's products show up in most of our tests and generally put in strong performances. The server version has the usual simple, angular appearance with a strong set of controls under the covers, and this month held up well under the pressure of testing with no stability problems noted. Scanning speeds were decent, while file read times look fast thanks to there being limited scanning on-read by default. Performance measures show slightly elevated resource usage and a noticeable but not too heavy impact on our set of activities.
Detection was decent too, and there were no issues in the clean sets. There was a clean run over the WildList sets on demand, but on access we noted a couple of items that were not being alerted on; further checking revealed a detection was being prevented by the cloud lookup system, a problem Avira picked up on rapidly and fixed without intervention from us. Nevertheless, it was enough to deny Avira a VB100 award this month, despite another good showing.
Main version: 6.2.10.832
Update versions: 7.67876, 7.68036, 7.68137, 7.68262
Last 6 tests: 6 passed, 0 failed, 0 no entry
Last 12 tests: 12 passed, 0 failed, 0 no entry
ItW on demand: 100.00%
ItW on access: 100.00%
False positives: 0
Stability: Stable
One of the very few vendors maintaining a perfect score card over the last two years, Bitdefender's business product has a minimalist appearance, with large fonts and clear messaging making up for minimal controls (most of which are provided in a separate management system). Stability was for the most part very good indeed, although during one large scan job we did note the PC freezing up and needing a restart, an incident which was not repeated and only occurred during unusually heavy usage.
Scanning speeds were pretty decent to start with and blasted through in no time on repeat runs, while file read lags were low and resource consumption also nominal, with a low impact on our set of activities. Detection was very strong indeed, dropping off a little into the proactive sets, and with a flawless run through the certification sets another VB100 award is well earned by Bitdefender.
Main version: 5.1.38
Update versions: 5.4.25/201611021006, 201611171229, 201611230923, 201611282121
Last 6 tests: 5 passed, 0 failed, 1 no entry
Last 12 tests: 6 passed, 4 failed, 2 no entry
ItW on demand: 100.00%
ItW on access: 100.00%
False positives: 0
Stability: Stable
CYREN's venerable Command product has picked up a good string of passes of late, its earlier, long-running issues with false positives seemingly now in the past, although the product remains the unchallenged title holder in the 'most retro interface' category. Stability was reasonable in everyday use, although scanning unusually large sets of malware seemed like a fairly sure-fire way to crash the GUI. Scanning speeds were sluggish, file read lags pretty hefty, and our set of activities took a long time to complete, with low resource usage figures more a reflection of the long period over which the numbers were averaged out rather than any particular efficiency.
Detection was very strong in the reactive sets, distinctly lower in the proactive tests where the product had no access to cloud lookups, and the WildList was nicely covered. The clean sets were once again handled without issues, and another VB100 award goes to CYREN.
Main version: 15.0.0106
Update versions: 9.244.21362, 15.1.0103/9.245.21537, 9.245.21583, 9.245.21644
Last 6 tests: 1 passed, 0 failed, 5 no entry
Last 12 tests: 6 passed, 0 failed, 6 no entry
ItW on demand: 100.00%
ItW on access: 100.00%
False positives: 0
Stability: Solid
Defenx seems to be back in our regular lineup after a brief absence, having replaced its previous technology provider with K7. The product interface is clean and clear with good controls and plenty of information available, and seemed to brush off any attempt to stress it, earning top marks for stability. Scanning speeds were decent with some good optimization in the warm runs, while file read times weren't slowed down too much and our set of tasks completed in good time too, with minimal resource usage.
Detection was a little lower than most this month, but within acceptable bounds, and with another clean run over the certification sets a VB100 award is easily won by Defenx.
Main version: 14.0.1400.1948 DB
Update versions: N/A
Last 6 tests: 6 passed, 0 failed, 0 no entry
Last 12 tests: 12 passed, 0 failed, 0 no entry
ItW on demand: 100.00%
ItW on access: 100.00%
False positives: 0
Stability: Stable
Another member of the 12/12 club with a perfect pass record in recent years, eScan's server edition has a very bright and colourful tiled main screen, with other areas including the ample set of configuration options looking a little less slick, but generally working well. We noted a single GUI crash, during normal usage, as well as a single problem with logging not behaving as expected, but nothing too serious. Scanning speeds were impressive, file access lags pretty light for the most part, and our set of activities wasn't hit too hard, with reasonable resource consumption.
Detection, assisted by the Bitdefender engine, was strong with a slight drop into the proactive sets, and a good showing in the core sets earns eScan another VB100 award.
Main version: 6.4.2014.0
Update versions: 14376, 14453, 14485, 14517
Last 6 tests: 6 passed, 0 failed, 0 no entry
Last 12 tests: 12 passed, 0 failed, 0 no entry
ItW on demand: 100.00%
ItW on access: 100.00%
False positives: 0
Stability: Solid
Fresh from celebrating an epic 100th VB100 pass, ESET returns this month to extend that splendid record of passes still further. The product is highly polished and professional-looking with plenty of data displayed and easy access to a comprehensive set of configuration options. Stability was impeccable once again with no wobbles even under seriously heavy loads, and speeds were good too, with fast scan times, light slowdown of file reads and a pretty reasonable impact on our sets of activities; resource use wasn't excessive either.
Detection was excellent with good scores even into the offline proactive sets, and yet another perfect run through the certification sets easily earns ESET its 101st VB100 award.
Main version: 3.0.1.3
Update versions: 16.7.12.1/606898.2016110222/7.67876/7724183.20161102, N/A 16.7.12.1/611979.2016112322/7.68135/7323290.20161123, 16.7.12.1/613740.2016113019/7.68254/7398571.20161130
Last 6 tests: 4 passed, 1 failed, 1 no entry
Last 12 tests: 9 passed, 1 failed, 2 no entry
ItW on demand: 100.00%
ItW on access: 100.00%
False positives: 0
Stability: Stable
ESTsoft has a pretty decent record in our tests, with some good runs of passes over the last few years. The current product is pleasant to look at overall, with decent controls available, although fonts look a little wonky in places. Stability was good, with only a single issue noted, related to log exporting. Scanning speeds were fairly fast, file read lag times mostly very low, although executables were held up rather longer than other file types, at least on first visit, with warm times much better. Our set of tasks was slowed down a little but not too much, with resource consumption barely detectable.
Using the Bitdefender engine, detection was, as expected, very solid indeed, and with no problems in the certification sets another VB100 award is comfortably earned by ESTsoft.
Main version: 5.4.1.0840
Update versions: 5.00233/40.00475, 40.00789, 40.00945, 41.00070
Last 6 tests: 5 passed, 0 failed, 1 no entry
Last 12 tests: 10 passed, 0 failed, 2 no entry
ItW on demand: 100.00%
ItW on access: 100.00%
False positives: 0
Stability: Fair
Fortinet's FortiClient is another extremely reliable participant in out tests, with passes in all Windows comparatives in the last few years. The product interface is fairly basic with minimal options provided and styling pared down for maximum simplicity. It proved mostly reliable, although a few update attempts failed and had to be re-run and we did see a couple of unexpected restarts. Scanning speeds were fairly slow, on-access lags a little high but showing some improvement on repeat visits to the same files, and our set of tasks was somewhat slowed down with resource consumption a little elevated at busy times.
Detection was very strong in the response sets, dropping considerably into the offline proactive sets, and the core certification sets were dealt with very tidily, earning Fortinet another VB100 award.
Main version: 14.0.1.122
Update versions: AVA 25.8921/GD 25.8081, AVA 25.9066/GD 25.8184, AVA 25.9174/GD 25.8237, AVA 25.9311/GD 25.8290
Last 6 tests: 5 passed, 0 failed, 1 no entry
Last 12 tests: 10 passed, 0 failed, 2 no entry
ItW on demand: 100.00%
ItW on access: 100.00%
False positives: 0
Stability: Solid
G DATA's business solution is a proper corporate offering with an MMC console to provide deployment and central control, and a local agent with limited configuration to keep the user informed of any issues. As usual, deployment and operation proved a little more involved than with straightforward monolithic solutions, but it seemed to work pretty well with some practice, and proved robustly resistant to the stresses of the test, earning a perfect rating for stability. Scanning speeds were reasonable initially and very fast indeed in the warm runs, with file read lags showing a similar improvement on repeat visits. Our set of activities was distinctly slower than the baseline measures, with pretty heavy use of resources too.
Detection was very strong as usual, with good scores across the sets, and another perfect showing in the core sets earns G DATA another VB100 award.
Main version: 2.13.19
Update versions: 98759, 98804, 98822, 98841
Last 6 tests: 3 passed, 2 failed, 1 no entry
Last 12 tests: 7 passed, 2 failed, 3 no entry
ItW on demand: 100.00%
ItW on access: 100.00%
False positives: 0
Stability: Solid
Ikarus seems slightly more prone to false positives than most, but has managed to pick up a decent scattering of passes of late. This month the product looked much the same as ever, the interface somewhat blocky and clunky but reasonably usable, and it proved impressively stable with no problems noted at all.
Scanning speeds started out decent and became excellent on repeat runs, while file lags were fairly significant on first seeing things but again improved impressively after initial settling in. Our set of tasks completed in very good time.
Detection was solid, with a sharpish drop into the proactive sets, and a good job handling the certification sets earns Ikarus another VB100 award.
Main version: 15.1.0330
Update versions: 9.244.21382, 9.245.21527, 9.245.21582, 9.245.21644
Last 6 tests: 5 passed, 0 failed, 1 no entry
Last 12 tests: 10 passed, 0 failed, 2 no entry
ItW on demand: 100.00%
ItW on access: 100.00%
False positives: 0
Stability: Stable
K7's history in our tests shows an impressive run of success of late, with passes in all Windows comparatives in the last couple of years. The product has a rugged appeal with a good set of controls within easy reach, and proved pretty stable once again with only a single glitch – a fairly minor one where an update failed to complete first time but got the job done without difficulty on re-running. Scanning speeds were slow to start with but a lot quicker on second attempt, while file read lag times were a little high, improving somewhat in the warm runs. Our set of tasks wasn't slowed down too much though, and resource usage was low.
Detection was reasonable, a little lower than the bulk of participants but still respectable, and the core certification sets were handled accurately, earning K7 a VB100 award.
Main version: 10.0.0.486
Update versions: N/A
Last 6 tests: 1 passed, 0 failed, 5 no entry
Last 12 tests: 6 passed, 0 failed, 6 no entry
ItW on demand: 100.00%
ItW on access: 100.00%
False positives: 0
Stability: Solid
Kaspersky's history in our tests is complicated somewhat by the vendor's large number of product lines, which appear in differing combinations depending on the test. The server solution is a full enterprise offering leveraging the MMC system for its main interface and controls, which are provided in the comprehensive depth one would expect and seem fairly simple to navigate and operate. There were no stability problems noted, earning the product a 'Solid' rating. Scanning speeds were not the fastest, and overheads seemed a little heavy too, with a long time taken to complete our set of tasks and fairly high use of RAM and CPU cycles.
The certification sets were nicely covered though, earning Kaspersky another VB100 award.
Main version: 1.0.46.78415 Pro
Update versions: 0.14.26.8452, 1.0.46.78415 Pro/0.14.26.8560, 1.0.70.78864 Pro /0.14.26.8596, 1.0.70.78864 Pro/0.14.26.8630
Last 6 tests: 4 passed, 0 failed, 2 no entry
Last 12 tests: 4 passed, 2 failed, 6 no entry
ItW on demand: 100.00%
ItW on access: 100.00%
False positives: 0
Stability: Solid
A relative newcomer to VB100 testing, NANO has accumulated a nice little set of passes. The product looks clean and simple, and managed to complete all tests without the slightest sign of instability. Scanning speeds were steady and not too slow, while file read lags were slow over archives but not bad elsewhere. Our set of tasks was somewhat slowed down, and resource usage was also noticeable, but not too heavy.
Detection still lags behind the leaders somewhat but continues to improve steadily, and with a good run through the certification sets, another VB100 award goes to NANO.
Main version: 2.0.0.6
Update versions: 2.0.0.6, 2.0.0.7
Last 6 tests: 0 passed, 4 failed, 2 no entry
Last 12 tests: 0 passed, 7 failed, 5 no entry
ItW on demand: 98.95%
ItW on access: 85.72%
False positives: 2174
Stability: Buggy
PC Pitstop's unusual whitelisting-heavy approach has earned it some stellar detection rates of late, although a tendency to false alarm has meant no certification for a while. The interface is focused on software vulnerabilities with some information on malware protection and basic configuration controls. The GUI itself remained reasonably stable, but we saw a number of fatal blue-screen incidents at all stages of the test (to be fair, we should note that the product is mainly geared towards the consumer market and not intended for use on server platforms). With so many issues noted no speed or performance data could be gathered, but we at least managed to complete all the detection tests, which showed once again some superb detection rates in the RAP sets, but a high FP rate and some issues with the WildList too, meaning there is no VB100 award for PC Pitstop once again.
Main version: 17.00 (1.0.0.4.3) 64bit
Update versions: N/A
Last 6 tests: 4 passed, 0 failed, 2 no entry
Last 12 tests: 8 passed, 0 failed, 4 no entry
ItW on demand: 100.00%
ItW on access: 100.00%
False positives: 0
Stability: Stable
Quick Heal's server version has a stark black-and-white colour scheme, leavened only occasionally with touches of green or red, and a clean, pared-down layout which nevertheless manages to provide a decent set of configuration options. Stability was good, with just a single incident observed of the scanner snagging. Scanning speeds were slowish, overheads not too bad to start with and barely discernible on repeat visits, while our set of activities wasn't too badly slowed down but resource consumption was on the high side.
Detection was strong, with a steady but not too steep decline through the sets, and the certification sets were nicely dealt with, earning Quick Heal a VB100 award.
Main version: 17.00 (10.0.5.3) 64bit
Update versions: N/A
Last 6 tests: 4 passed, 0 failed, 2 no entry
Last 12 tests: 8 passed, 0 failed, 4 no entry
ItW on demand: 100.00%
ItW on access: 100.00%
False positives: 0
Stability: Stable
Quick Heal's Seqrite product line is aimed at the larger enterprise, but the main interface closely resembles other Quick Heal products, once again using a monochrome look to lend gravitas. Stability was good again, with just that single file tripping up the scanner and, this time, an update attempt returning an error on first try. Scanning speeds and file access lag times were acceptable, with a fairly large hit on our set of activities and somewhat elevated resource consumption.
Detection was pretty decent across the board, including in the certification sets where no issues were noted, duly earning Quick Heal's Seqrite another VB100 award.
Main version: 11.6.26315.901
Update versions: 11.6.26322.901, 12.1.26326.901, 12.1.26328.901
Last 6 tests: 4 passed, 0 failed, 2 no entry
Last 12 tests: 7 passed, 0 failed, 5 no entry
ItW on demand: 100.00%
ItW on access: 100.00%
False positives: 0
Stability: Stable
Chinese giant Tencent continues to build a steady run of passes in our tests. The latest edition looks bright and glossy with clear controls and a decent set of configuration options provided. Stability was dented only by an incident on one install where the on-access protection seemed to take rather a long time to kick in. Scanning speeds were on the slow side, and with minimal protection on-read our file access measures show low impact. Detection was strong, and with another good run through the certification sets, Tencent picks up another VB100 award.
Main version: 11.6.26311.901
Update versions: 11.6.26321.901, 12.1.26325.901, 12.1.26327.901
Last 6 tests: 3 passed, 0 failed, 3 no entry
Last 12 tests: 3 passed, 0 failed, 9 no entry
ItW on demand: 100.00%
ItW on access: 100.00%
False positives: 0
Stability: Solid
The 'TAV' edition of Tencent's PC Manager uses only in-house technology without the third-party engine that is enabled in the standard edition, and has been achieving certification fairly reliably over the last year or so. In look and feel it's not much different, with the same shiny, colourful interface. Stability this time was perfect, with no problems observed. Scanning speeds were a little faster than the mainline product, while once again on-read protection was largely absent. Our set of activities was minimally impacted, and resource use was low.
Detection figures are absent thanks to the developers requesting to be excluded from the RAP test, but the core certification sets were handled properly and a VB100 award is earned.
Main version: 16.02.5698
Update versions: 16.0.2.5705
Last 6 tests: 5 passed, 0 failed, 1 no entry
Last 12 tests: 9 passed, 0 failed, 3 no entry
ItW on demand: 100.00%
ItW on access: 100.00%
False positives: 0
Stability: Stable
TrustPort's products have been stalwarts of our tests for many years now and can usually be relied upon to produce excellent detection levels thanks to their multi-engine approach. This month, the GUI came in a fairly attractive pale blue, with some nice clear information on the surface and a good set of options under the hood.
Stability was dented by a single incident while scanning some clean files, bringing up an API error message but not apparently affecting the actual scan. Scanning speeds were a little slow, file read overheads fairly high at first but showing some serious improvement later on. Detection was excellent, with a little drop into the proactive sets, and another perfect run through the certification sets earns TrustPort a VB100 award.
Certification tests | On demand | On access | Clean sets | VB100 | |
Standard WildList | Standard WildList | FPs | Warnings | ||
AhnLab V3Net for Windows Server | 100.00% | 100.00% | |||
Avast Business Security | 100.00% | 100.00% | 3 | ||
Avira Antivirus Server | 100.00% | 99.68% | |||
Bitdefender Endpoint Security | 100.00% | 100.00% | |||
CYREN Command Anti-Malware | 100.00% | 100.00% | |||
Defenx Security Suite | 100.00% | 100.00% | |||
eScan Internet Security Suite Server Edition | 100.00% | 100.00% | |||
ESET Endpoint Antivirus | 100.00% | 100.00% | |||
ESTsoft ALYac | 100.00% | 100.00% | |||
Fortinet FortiClient | 100.00% | 100.00% | |||
G DATA Antivirus Business | 100.00% | 100.00% | |||
Ikarus anti.virus | 100.00% | 100.00% | |||
K7 Total Security | 100.00% | 100.00% | |||
Kaspersky Anti-Virus 10 for Windows Servers | 100.00% | 100.00% | |||
NANO Antivirus Pro | 100.00% | 100.00% | |||
PC Pitstop PC Matic Home Security | 98.95% | 85.72% | 2174 | ||
Quick Heal AntiVirus Server Edition | 100.00% | 100.00% | |||
Quick Heal Seqrite Antivirus Server Edition | 100.00% | 100.00% | |||
Tencent PC Manager | 100.00% | 100.00% | |||
Tencent PC Manager - TAV | 100.00% | 100.00% | |||
TrustPort Antivirus 2016 | 100.00% | 100.00% |
Product information | Install time (m)* | Reboot required | Fully 64-bit | Third-party engine technology§ | Stability score | Stability rating |
AhnLab V3Net for Windows Server | 5:45 | √ | X | 1 | Stable | |
Avast Business Security | 5:15 | √ | √ | 2.5 | Stable | |
Avira Antivirus Server | 6:45 | X | X | 0 | Solid | |
Bitdefender Endpoint Security | 7:00 | √ | X | 2.5 | Stable | |
CYREN Command Anti-Malware | 3:30 | √ | X | 4.0 | Stable | |
Defenx Security Suite | 3:00 | √ | X | K7 | 0 | Solid |
eScan Internet Security Suite Server Edition | 11:45 | X | X | Bitdefender | 3 | Stable |
ESET Endpoint Antivirus | 4:45 | √ | X | 0 | Solid | |
ESTsoft ALYac | 13:00 | √ | X | Bitdefender | 1 | Stable |
Fortinet FortiClient | 4:30 | X | X | 6 | Fair | |
G DATA Antivirus Business | 48:45 | X | X | Bitdefender | 0 | Solid |
Ikarus anti.virus | 2:00 | X | X | 0 | Solid | |
K7 Total Security | 1:30 | X | X | 1 | Stable | |
Kaspersky Anti-Virus 10 for Windows Servers | 4:15 | X | X | 0 | Solid | |
NANO Antivirus Pro | 11:15 | X | X | 0 | Solid | |
PC Pitstop PC Matic Home Security | 3:30 | X | X | 20 | Buggy | |
Quick Heal AntiVirus Server Edition | 28:15 | √ | X | 3 | Stable | |
Quick Heal Seqrite Antivirus Server Edition | 26:00 | √ | X | 1 | Stable | |
Tencent PC Manager | 19:00 | X | X | Bitdefender | 2 | Stable |
Tencent PC Manager - TAV | 2:45 | X | X | 0 | Solid | |
TrustPort Antivirus 2016 | 11:45 | X | √ | Bitdefender | 1 | Stable |
0 = Solid 0.1 – 4.9 = Stable 5 – 14.9 = Fair 15 – 29.9 = Buggy 30+ = Flaky
* Install time includes initial updates and time to enable on-access protection (assuming reasonable typing speed and familiarity with product operation)
§ Only records presence of third-party scanning engines, most products will include additional in-house technologies
Archive scanning | ACE | CAB | EXE-RAR | EXE-ZIP | JAR | LZH | RAR | TGZ | ZIP | 7z | TBZ2 | ZIPX | EXT* | |
AhnLab V3Net for Windows Server | OD | 1 | 5 | X | X | 5 | X | 1 | 2 | 1 | 1 | 1 | 1 | √ |
OA | X | X | X | X | X | X | X | X | X | X | X | X | √ | |
Avast Business Security | OD | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ |
OA | X/√ | X/√ | 1/√ | X/√ | X/√ | X/√ | X/√ | X/√ | X/√ | X/√ | X/√ | X/√ | X/√ | |
Avira Antivirus Server | OD | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ |
OA | X/√ | X/√ | X/√ | X/√ | X/√ | X/√ | X/√ | X/√ | X/√ | X/√ | X/√ | X/√ | X/√ | |
Bitdefender Endpoint Security | OD | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ |
OA | X | X | X | X | 1 | X | X | X | 1 | X | X | 1 | √ | |
CYREN Command Anti-Malware | OD | 5 | 5 | 5 | 5 | 5 | √ | 5 | 2 | 5 | 3 | 2 | 5 | √ |
OA | 2/4 | 2/4 | 2/4 | 2/4 | 2/4 | √ | 2/4 | 1/2 | 2/4 | 1/1 | 1/2 | 2/4 | √ | |
Defenx Security Suite | OD | √ | √ | X | X | √ | X | √ | X | √ | √ | X | √ | √ |
OA | X | X | X | X | X | X | X | X | X | X | X | X | √ | |
eScan Internet Security Suite Server Edition | OD | √ | X/√ | 5/8 | 5/8 | 7/√ | X/√ | X/√ | 5/8 | 1/√ | X/√ | X/8 | √ | √ |
OA | √ | X/√ | X/√ | X/√ | √ | X/√ | X/√ | X/√ | 1/√ | X/√ | X/√ | X/√ | √ | |
ESET Endpoint Antivirus | OD | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ |
OA | X | X | X | X | X | X | X | X | X | X | X | X | √ | |
ESTsoft ALYac | OD | √ | √ | X | X | X | X | √ | X | X | √ | X | X | √ |
OA | √ | √ | X | X | 1 | X | √ | X | 1 | √ | X | X | √ | |
Fortinet FortiClient | OD | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ |
OA | √ | X | √ | √ | √ | X | X | X | X | X | √ | √ | √ | |
G DATA Antivirus Business | OD | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ |
OA | 3/√ | 2/√ | √ | √ | 2/√ | 3/√ | 3/√ | 1/8 | 2/√ | 2/√ | 1/8 | 2/√ | √ | |
Ikarus anti.virus | OD | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ |
OA | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | |
K7 Total Security | OD | √ | √ | √ | √ | √ | X | √ | X | √ | √ | X | √ | √ |
OA | X | X | X | X | X | X | X | X | X | X | X | X | √ | |
Kaspersky Anti-Virus 10 for Windows Servers | OD | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ |
OA | X/√ | X/√ | √ | √ | X/√ | X/√ | X/√ | X/√ | X/√ | X/√ | X/√ | X/√ | √ | |
NANO Antivirus Pro | OD | 8/√ | 8/√ | 4/√ | 4/√ | 8/√ | X | 8/√ | 4/√ | 8/√ | 8/√ | 4/√ | 8/√ | √ |
OA | X | X | X | X | X | X | X | X | X | X | X | X | √ | |
PC Pitstop PC Matic Home Security | OD | X | X | √ | √ | X | X | X | X | X | X | X | X | X |
OA | X | X | √ | √ | X | X | X | X | X | X | X | X | X | |
Quick Heal AntiVirus Server Edition | OD | 2/5 | X/5 | 2/2 | 2/2 | 2/5 | 3/6 | 2/5 | X/2 | 2/5 | 2/5 | X/2 | 2/5 | √ |
OA | X | X | X | X | 1 | X | X | X | 1 | X | X | X | √ | |
Quick Heal Seqrite Antivirus Server Edition | OD | 2/5 | X/5 | 2/2 | 2/2 | 2/5 | 3/6 | 2/5 | X/2 | 2/5 | 2/5 | X/2 | 2/5 | √ |
OA | X | X | X | X | 1 | X | X | X | 1 | X | X | X | √ | |
Tencent PC Manager | OD | √ | √ | 7 | 7 | √ | √ | √ | 7 | √ | √ | 7 | √ | √ |
OA | X/2 | X/2 | X/1 | X/1 | X/2 | X/2 | X/2 | X/1 | X/2 | X/2 | X/1 | X/2 | 1/√ | |
Tencent PC Manager - TAV | OD | √ | √ | √ | √ | √ | X | √ | √ | √ | √ | X | √ | √ |
OA | X/√ | X/√ | X/√ | X/√ | X/√ | X | X/√ | X/√ | X/√ | X/√ | X | X/√ | 1/√ | |
TrustPort Antivirus 2016 | OD | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ |
OA | √ | √ | 7/√ | 8/√ | 1/√ | √ | √ | √ | 1/√ | √ | √ | 1/√ | √ |
Key:
√ - Detection of EICAR test file up to ten levels of nesting
X - No detection of EICAR test file
X/√ - default settings/all files
1-9 - Detection of EICAR test file up to specified nesting level
If just z-exe detection in ext, then X
*Detection of EICAR test file with randomly chosen file extension
Performance measures | Idle RAM usage increase | Busy RAM usage increase | Busy CPU usage increase | Standard activities - time increase |
AhnLab V3Net for Windows Server | 9.52% | 1.45% | 11.26% | 74.17% |
Avast Business Security | 7.16% | 0.31% | 32.84% | 65..52% |
Avira Antivirus Server | 14.90% | 8.32% | 24.89% | 65.88% |
Bitdefender Endpoint Security | 4.78% | 0.34% | -6.56% | 30.02% |
CYREN Command Anti-Malware | 4.72% | -3.97% | 23.40% | 523.69% |
Defenx Security Suite | 3.41% | 2.75% | 0.62% | 26.84% |
eScan Internet Security Suite Server Edition | 13.27% | 7.31% | 18.09% | 47.64% |
ESET Endpoint Antivirus | 7.75% | 6.86% | 15.90% | 29.84% |
ESTsoft ALYac | 0.49% | -0.42% | 5.10% | 48.23% |
Fortinet FortiClient | 11.38% | 6.70% | 13.24% | 43.42% |
G DATA Antivirus Business | 32.47% | 27.82% | 76.70% | 93.38% |
Ikarus anti.virus | 12.65% | 10.64% | -0.19% | 20.84% |
K7 Total Security | 4.78% | 2.71% | 1.22% | 25.87% |
Kaspersky Anti-Virus 10 for Windows Servers | 16.37% | 8.31% | 34.22% | 80.13% |
NANO Antivirus Pro | 13.26% | 10.06% | 30.88% | 47.93% |
PC Pitstop PC Matic Home Security | N/T | N/T | N/T | N/T |
Quick Heal AntiVirus Server Edition | 29.28% | 21.62% | 105.07% | 48.54% |
Quick Heal Seqrite Antivirus Server Edition | 30.53% | 20.59% | 17.49% | 74.68% |
Tencent PC Manager | 8.84% | 7.69% | 5.69% | 14.88% |
Tencent PC Manager - TAV | 5.65% | 4.19% | 9.48% | 7.82% |
TrustPort Antivirus 2016 | 5.24% | 6.65% | 2.44% | 67.44% |
Microsoft Windows Defender* | 11.99% | 6.65% | 10.83% | 53.85% |
*Product not fully tested, only speed and performance data available. N/T = Not tested.
On-demand throughput (MB/s) | System drive* | Archive files | Binaries and system files | Media and documents | Other file types | ||||||||
Default (cold) | Default (warm) | All files | Default (cold) | Default (warm) | All files | Default (cold) | Default (warm) | All files | Default (cold) | Default (warm) | All files | ||
AhnLab V3Net for Windows Server | 97.62 | 7.78 | 5.47 | N/A | 6.69 | 9.70 | 6.69 | 14.16 | 14.16 | 14.16 | 11.12 | 15.54 | 11.12 |
Avast Business Security | 10.88 | 2.30 | 2.39 | 2.30 | 3.18 | 2.98 | 3.18 | 11.30 | 11.08 | 11.30 | 8.83 | 7.58 | 8.83 |
Avira Antivirus Server | 8.15 | 9.15 | 7.32 | 9.15 | 4.21 | 4.34 | 4.21 | 8.94 | 10.03 | 8.94 | 7.83 | 8.20 | 7.83 |
Bitdefender Endpoint Security | 38.17 | 13.49 | 1366.06 | 13.49 | 9.51 | 3157.44 | 9.51 | 13.95 | 1429.88 | 13.95 | 15.19 | 1906.56 | 15.19 |
CYREN Command Anti-Malware | 3.87 | 3.56 | 3.35 | 3.56 | 1.57 | 2.15 | 1.57 | 4.17 | 6.51 | 4.17 | 4.46 | 6.17 | 4.46 |
Defenx Security Suite | 24.56 | 8.88 | 546.34 | 8.88 | 3.88 | 420.99 | 3.88 | 8.41 | 268.12 | 8.41 | 5.34 | 224.30 | 5.34 |
eScan Internet Security Suite | 13.74 | 44.41 | 86.71 | 14.57 | 8.08 | 36.15 | 7.61 | 9.83 | 31.66 | 12.33 | 9.12 | 25.71 | 12.38 |
ESET Endpoint Antivirus | 98.43 | 15.43 | 35.24 | 15.43 | 16.36 | 32.33 | 16.36 | 14.52 | 214.49 | 14.52 | 14.72 | 381.31 | 14.72 |
ESTsoft ALYac | 5.62 | 2.09 | 53.56 | 23.35 | 7.23 | 11.15 | 10.79 | 5.42 | 13.32 | 14.67 | 5.00 | 10.85 | 11.18 |
Fortinet FortiClient | 5.68 | 8.67 | 9.53 | 8.67 | 1.61 | 1.99 | 1.61 | 11.63 | 11.95 | 11.63 | 6.24 | 5.91 | 6.24 |
G DATA Antivirus Business | 9.61 | 7.92 | 42.35 | 7.92 | 5.25 | 120.67 | 5.25 | 9.73 | 56.07 | 9.73 | 11.05 | 95.33 | 11.05 |
Ikarus anti.virus | 35.87 | 12.39 | 780.52 | 12.39 | 6.07 | 291.47 | 6.07 | 12.71 | 295.86 | 12.71 | 9.26 | 381.31 | 9.26 |
K7 Total Security | 22.86 | 1.73 | 606.99 | 1.73 | 5.33 | 462.09 | 5.33 | 9.17 | 268.12 | 9.17 | 5.13 | 309.18 | 5.13 |
Kaspersky Anti-Virus 10 for Windows Servers | 5.39 | 1.71 | 1.73 | 1.71 | 2.72 | 12.30 | 2.72 | 6.89 | 39.17 | 6.89 | 5.83 | 75.26 | 5.83 |
NANO Antivirus Pro | 17.36 | 9.95 | 9.93 | 9.95 | 5.19 | 5.12 | 5.19 | 0.90 | 0.91 | 0.90 | 15.56 | 17.07 | 15.56 |
PC Pitstop PC Matic Home Security | N/T | N/T | N/T | N/T | N/T | N/T | N/T | N/T | N/T | N/T | N/T | N/T | N/T |
Quick Heal AntiVirus Server Edition | 5.71 | 9.10 | 12.79 | 1.31 | 4.26 | 3.87 | 2.71 | 6.23 | 6.83 | 6.36 | 6.74 | 4.43 | 3.68 |
Quick Heal Seqrite Antivirus Server Edition | 5.81 | 12.91 | 11.43 | 1.21 | 2.55 | 2.93 | 3.10 | 5.05 | 5.53 | 5.54 | 2.36 | 4.33 | 3.56 |
Tencent PC Manager | 4.61 | 2.39 | 2.41 | 2.39 | 2.85 | 2.38 | 2.85 | 8.80 | 8.79 | 8.80 | 7.94 | 8.21 | 7.94 |
Tencent PC Manager - TAV | 13.47 | 14.23 | 14.34 | 14.23 | 4.73 | 8.43 | 4.73 | 9.05 | 9.63 | 9.05 | 10.06 | 12.05 | 10.06 |
TrustPort Antivirus 2016 | 2.24 | 3.37 | 5.40 | 3.37 | 1.84 | 1.40 | 1.84 | 7.13 | 7.19 | 7.13 | 2.17 | 3.04 | 2.17 |
*System drive size measured before product installation. N/T = Not tested.
On-access lag time (s/GB) | System drive¶ |
Archive files | Binaries and system files | Media and documents | Other file types | ||||||||
Default (cold) | Default (warm) | All files | Default (cold) | Default (warm) | All files | Default (cold) | Default (warm) | All files | Default (cold) | Default (warm) | All files | ||
AhnLab V3Net for Windows Server | 71.11 | 17.78 | 13.02 | N/A | 455.32 | 91.01 | 455.32 | 67.76 | 58.68 | 67.76 | 253.37 | 54.52 | 253.37 |
Avast Business Security | 13.74 | 54.64 | 13.09 | 211.81 | 65.72 | 62.98 | 293.15 | 37.82 | 36.32 | 92.78 | 47.15 | 46.29 | 133.43 |
Avira Antivirus Server | 6.33 | 0.07 | 0.11 | 0.14 | 11.74 | 13.05 | 6.75 | 7.85 | 7.81 | 4.89 | 6.97 | 6.26 | 5.75 |
Bitdefender Endpoint Security | 14.50 | 153.65 | 9.66 | N/A | 77.26 | 27.69 | 77.26 | 41.57 | 10.09 | 41.57 | 26.19 | 10.57 | 26.19 |
CYREN Command Anti-Malware | 172.46 | 309.04 | 197.07 | 186.95 | 349.60 | 347.57 | 353.76 | 141.35 | 139.10 | 140.21 | 123.11 | 122.52 | 122.96 |
Defenx Security Suite | 28.64 | 10.10 | 0.62 | N/A | 174.18 | 9.01 | 174.18 | 38.75 | 35.82 | 38.75 | 82.38 | 35.99 | 82.38 |
eScan Internet Security Suite | 19.21 | 7.65 | 0.91 | 44.59 | 166.86 | 7.31 | 15.41 | 101.97 | 6.38 | 34.46 | 92.88 | 5.03 | 15.42 |
ESET Endpoint Antivirus | 17.24 | 6.92 | 6.90 | N/A | 74.49 | 41.56 | 74.49 | 26.17 | 25.43 | 26.17 | 19.44 | 19.29 | 19.44 |
ESTsoft ALYac | 47.06 | 31.84 | 0.81 | N/A | 390.78 | 7.87 | 390.78 | 36.67 | 8.08 | 36.67 | 62.77 | 8.57 | 62.77 |
Fortinet FortiClient | 30.84 | 21.16 | 9.52 | 21.16 | 288.66 | 73.97 | 288.66 | 52.64 | 37.52 | 52.64 | 98.15 | 48.32 | 98.15 |
G DATA Antivirus Business | 264.98 | 215.52 | 15.34 | 9.82 | 357.89 | 48.38 | 58.13 | 115.40 | 26.20 | 23.86 | 132.89 | 23.62 | 20.70 |
Ikarus anti.virus | 43.37 | 155.38 | 7.99 | 155.38 | 236.75 | 17.75 | 236.75 | 84.24 | 16.15 | 84.24 | 49.03 | 15.43 | 49.03 |
K7 Total Security | 29.90 | 13.30 | 30.30 | N/A | 215.14 | 136.32 | 215.14 | 75.02 | 40.28 | 75.02 | 129.44 | 77.16 | 129.44 |
Kaspersky Anti-Virus 10 for Windows Servers | 87.76 | 28.46 | 20.54 | 148.22 | 294.26 | 43.26 | 229.31 | 106.15 | 46.46 | 115.33 | 129.48 | 37.93 | 113.15 |
NANO Antivirus Pro | 145.91 | 6.63 | 6.37 | N/A | 452.63 | 393.04 | 452.63 | 71.16 | 60.11 | 71.16 | 52.64 | 47.98 | 52.64 |
PC Pitstop PC Matic Home Security | N/T | N/T | N/T | N/T | N/T | N/T | N/T | N/T | N/T | N/T | N/T | N/T | N/T |
Quick Heal AntiVirus | 47.04 | 4.78 | 1.72 | N/A | 184.54 | 19.56 | 184.54 | 67.50 | 23.77 | 67.50 | 81.73 | 19.59 | 81.73 |
Quick Heal Seqrite Antivirus | 50.02 | 10.69 | 6.03 | N/A | 222.79 | 27.23 | 222.79 | 75.84 | 31.36 | 75.84 | 100.46 | 22.73 | 100.46 |
Tencent PC Manager | 11.23 | 1.77 | 1.96 | 3.67 | 7.41 | 6.44 | 5.27 | 5.84 | 5.44 | 4.85 | 5.61 | 5.69 | 4.27 |
Tencent PC Manager - TAV | 6.13 | 3.57 | 0.83 | 4.57 | 19.88 | 15.25 | 6.68 | 10.12 | 10.32 | 5.51 | 10.07 | 9.50 | 5.57 |
TrustPort Antivirus 2016 | 59.94 | 52.71 | 0.79 | 182.98 | 422.79 | 23.85 | 432.71 | 113.41 | 20.02 | 127.59 | 148.39 | 17.55 | 156.50 |
Microsoft Windows Defender* | 32.55 | 44.63 | 46.40 | N/T | 396.08 | 347.58 | N/T | 86.90 | 85.19 | N/T | 158.16 | 153.58 | N/T |
¶System drive size measured before product installation.
*Product not fully tested, only speed and performance data available.
N/T = Not tested. N/A = Not applicable (e.g. product does not have an applicable option).
Reactive and Proactive (RAP) tests | VB100 | Reactive | Proactive | Reactive average | Proactive average | Weighted average‡ | ||
Set 1* | Set 2* | Set 1§ | Set 2§ | |||||
AhnLab V3Net for Windows Server | 93.3% | 91.1% | 54.5% | 48.3% | 92.2% | 51.4% | 78.6% | |
Avast Business Security | 96.2% | 93.7% | 62.0% | 55.2% | 94.9% | 58.6% | 82.8% | |
Avira Antivirus Server | 88.8% | 86.5% | 62.5% | 59.6% | 87.6% | 61.1% | 78.8% | |
Bitdefender Endpoint Security | 95.7% | 92.6% | 69.3% | 66.6% | 94.1% | 67.9% | 85.4% | |
CYREN Command Anti-Malware | 98.6% | 95.8% | 59.8% | 56.8% | 97.2% | 58.3% | 84.2% | |
Defenx Security Suite | 79.5% | 77.6% | 52.4% | 46.4% | 78.5% | 49.4% | 68.8% | |
eScan Internet Security Suite Server Edition | 94.9% | 91.9% | 69.0% | 65.9% | 93.4% | 67.4% | 84.8% | |
ESET Endpoint Antivirus | 95.8% | 94.9% | 77.9% | 70.3% | 95.3% | 74.1% | 88.2% | |
ESTsoft ALYac | 97.3% | 95.3% | 69.5% | 66.7% | 96.3% | 68.1% | 86.9% | |
Fortinet FortiClient | 95.4% | 92.7% | 62.5% | 56.4% | 94.0% | 59.4% | 82.5% | |
G DATA Antivirus Business | 98.5% | 96.8% | 76.2% | 68.4% | 97.7% | 72.3% | 89.2% | |
Ikarus anti.virus | 94.9% | 93.4% | 63.4% | 60.7% | 94.1% | 62.0% | 83.4% | |
K7 Total Security | 84.7% | 78.3% | 55.6% | 51.2% | 81.5% | 53.4% | 72.1% | |
Kaspersky Anti-Virus 10 for Windows Servers | N/T | N/T | N/T | N/T | N/T | N/T | N/T | |
NANO Antivirus Pro | 82.1% | 62.4% | 47.3% | 43.2% | 72.3% | 45.2% | 63.3% | |
PC Pitstop PC Matic Home Security | 99.9% | 99.9% | 99.98% | 99.97% | 99.91% | 99.97% | 99.9% | |
Quick Heal AntiVirus Server Edition | 93.6% | 89.3% | 69.1% | 67.3% | 91.4% | 68.2% | 83.7% | |
Quick Heal Seqrite Antivirus Server Edition | 93.5% | 89.3% | 69.1% | 67.3% | 91.4% | 68.2% | 83.7% | |
Tencent PC Manager | 95.5% | 91.9% | 68.4% | 66.6% | 93.7% | 67.5% | 85.0% | |
Tencent PC Manager - TAV | N/T | N/T | N/T | N/T | N/T | N/T | N/T | |
TrustPort Antivirus 2016 | 98.8% | 99.0% | 71.4% | 68.9% | 98.9% | 70.2% | 89.3% |
*Set -1 = Samples discovered 1 to 5 days before testing; Set -2 = Samples discovered 6 to 10 days before testing.
§Set +1 = Samples discovered 1 to 5 days after updates frozen; Set +2 = Samples discovered 6 to 10 days after updates frozen.
‡Weighted average gives equal emphasis to the two reactive weeks and the whole proactive part. N/T = Not tested.
Another VB100 comparative completed, and once again pass rates were pleasingly high with most products reaching the standard required for certification. Of those that didn't make it, one was hit by a freak error of the sort that hits everyone from time to time, while the other provides a rather different approach to protection which doesn't fit too well with the rigid requirements of the VB100 scheme.
Elsewhere, detection rates were mostly good and stability was impressive too, with most products rated higher than 'Fair'. Our speed measures proved something of a headache this month thanks to the newness of the platform, but hopefully still provided some fairly clear and actionable data for admins and purchasers.
We return next time with our annual visit to Linux, generally a far smaller field of products but always an interesting experience for the test team.
All tests were run on identical systems with AMD A6-3670K Quad Core 2.7GHz processors, 4GB DUAL DDR3 1600MHz RAM, dual 500GB and 1TB SATA hard drives and gigabit networking, running Microsoft Windows Server 2016, Standard edition.