Online criminal activities are gaining momentum faster than ever. Both the rate at which new types and modifications of malicious programs appear and the complexity of malware are on the rise. Cybercriminals use increasingly sophisticated methods, including masking the presence of a malicious program in the system, compression, encryption and incapacitating antivirus solutions.
Social engineering techniques make it easy to entice users to download and launch malicious programs as yet unknown by antivirus solutions. In such cases, in order to gain complete and uninterrupted control over the system, malicious programs search for an antivirus program, firewall or other protective solution in order to disrupt its operation.
Consequently, contemporary antivirus products should be able to resist such attempts, that is, they should include self-protection functionality. This helps them to resist even the most complicated attacks, such as when malicious programs use a variety of methods to disable protection, and remove the infection using standard tools after receiving the appropriate antivirus database updates.
In the test described below, we analyzed the self-protection capabilities of antivirus solutions that run under Microsoft Windows XP with Service Pack 2. Self-protection from the following types of attacks was analyzed:
- Modification of file and registry key access permissions.
- Modification / removal of modules.
- Deletion of antivirus databases.
- Modification / deletion of important registry keys.
- Process termination.
- Modification of processes / code.
- Driver unloading.
Antivirus product self-protection testing methodology »
Analysis of self-protection test results and awards »
Test results (September 11, 2007)
| Award |
Products |
|

Gold Self-Protection Award
Download GIF image (500х500px)
|
Kaspersky Internet Security 7.0 (97%) |
|

Silver Self-Protection Award
Download GIF image (500х500px)
|
VBA32 Antivirus 3.11 (71%)
Symantec Internet Security 2007 (71%)
F-Secure Internet Security 2007 (61%) |
|

Bronze Self-Protection Award
Download GIF image (500х500px)
|
ZoneAlarm Internet Security 7.0 (58%)
Panda Internet Security 2007 (48%)
McAfee Internet Security 2007 (47%)
ESET Smart Security 3.0 Beta (44%)
Trend Micro PC-Cillin 2007 (42%) |
| Failed |
Avast! Professional Edition 4.7 (33%)
Avira Premium Security Suite 7.0 (33%)
Sophos Anti-Virus 6.0 (33%)
DrWeb 4.44 (32%)
Microsoft Windows Live OneCare 1.6 (32%)
BitDefender Internet Security 10 (30%) |
Key results of the testing of antivirus products in HTML»
Complete results for each antivirus product are available only in PDF or Microsoft Excel format:
Complete testing results in PDF format »
Complete testing results in Microsoft Excel format »
Recent comments
49 weeks 1 day ago
2 years 1 week ago
2 years 2 weeks ago
2 years 5 weeks ago
2 years 15 weeks ago
2 years 19 weeks ago
2 years 19 weeks ago
2 years 19 weeks ago
2 years 34 weeks ago
2 years 45 weeks ago