VOGONS


First post, by kotel

User metadata
Rank Oldbie
Rank
Oldbie

This project took me too long to finish.
Hopefully this went in the correct forum and the info will be used by someone.
Link to the result spreadsheet.

This is the ranking for the best AV vendor for low end XP machines.

!ALL TESTS WERE DONE ON REAL HARDWARE!
Specs:
Intel celeron M 1.4gHz; SATA I 5400RPM HDD; 512MB DDR2 PC2-4200; Integrated Intel i945GE GPU

These tests were to see which vendor combines effectiveness, lightweightness and ease of use.

Notes:

All AV's couldn't be updated to latest defenitions due to their update servers being long dead
Avast v8 needs to be activated using this key Avast gave for free to their discontinued AV products: https://www.avast.com/registration-free-antivirus#pc

Rules:

1. AV is disqualified when:
a) let's through the biggest ammount of sample viruses
b) Renders the PC unusuable due to being resource heavy

---------------------

The award for best Real Time detection rate goes to....

Avast! Free v8

Second: MSE 4.4.13 with Kaspersky Free 2018 and ESET NOD32 v6 (same % score)
Third: GDATA 14.1.1.54
Fourth: Avira antivir 13

The award for best Scan detecion rate goes to.....

Avast! Free v8 and ESET Endpoint protection v6.5 right behind it

Second: Kaspersky free 2018
Third: MSE 4.4.13 and GDATA Client 14.1.1.54
Fourth: ESET NOD32 v6

Personal award for lightweightness, effectiveness and ease of use (with configuration) goes to.....

MSE 4.4.13

Second: Avast! Free v8
Third: ESET Endpoint protection v6.5
Fourth: ESET NOD32 v6
-----------------------

Disqualification:

ClamWin: too much RAM usage (512MB + ~120MB swap) when scanning and downloading defenitions
Norton AV 2009: broken scanner, not usable on these specs (lack of working installer to redo tests)
Trend PC cillin 2002: outdated defenitions (cannot update due to servers being long dead)

-----------------------

Overall, I though MSE 4.4.13 would be the worst, but turns out it's pretty darn good at being an AV!
Had higher hopes for ESET endpoint protection v6.5 tho.... It even let CIH launch when doing real time testing! None AV vendors let the CIH samples through beside eset endpoint.

"All my efforts were in vain...
Let that be my disappointment."
-Kotel

Reply 1 of 4, by Masaw

User metadata
Rank Newbie
Rank
Newbie

did you create log/report files for each AV, especially Kaspersky 2018 scan? i'm curious to see which ones were missed and detected. also if I have them in my collection. Can you send me the log/report file?

VCheck+ Portable Antivirus for DOS
=========================
Main: https://archive.org/details/VCHECK/
====
Updated! : http://old-dos.ru/index.php?page=files&mode=f … =show&id=103705
======

Reply 2 of 4, by kotel

User metadata
Rank Oldbie
Rank
Oldbie
Masaw wrote on 2025-07-24, 00:18:

did you create log/report files for each AV, especially Kaspersky 2018 scan? i'm curious to see which ones were missed and detected. also if I have them in my collection. Can you send me the log/report file?

Hi, sorry I didn't create log files for AVs during testing. The results in the table were only for scan detection. But I can tell you what was left undetected and some other technical info about the samples for Kaspersky 2018 (and other if you would like to).

Undetected scan samples:
Sality samples: one stealthily infected google chrome installer (most didn't pick this one up, tbh I think this one has only some code of sality inside that isn't "harmful" but still enough to get detected)
Trojan getdwonloader (aka WMAWimad): all
Adwgen: missed "Bearshare" installer
Bolzano-S: these are files which AVG reported infected from "SDISK2.IMG" file. Unsure what those are since the file inside the IMG looks to be an ELF executable (and I suck at linux)

Undetected real time detection samples:
Same sality infected chrome installer
Bearshare adware installer

"All my efforts were in vain...
Let that be my disappointment."
-Kotel

Reply 3 of 4, by Masaw

User metadata
Rank Newbie
Rank
Newbie

regarding the Sality infected files, it's possible these files could contain only traces or part of the virus that was not completly removed or the file was corrupted when it was disinfected rendering the file non-executable.
That Adwgen is a "not-a-virus" it's a PUA (possible unwanted app), there is an option for kaspersky to be able to detect these kind of files otherwise if that option is not set it will not scan for it.
That Bolzano-S infected file could be a text or script (script.ini) file created by the virus to spread but not the actual virus, since this virus was written during the time when mIRC was still a popular chat client

VCheck+ Portable Antivirus for DOS
=========================
Main: https://archive.org/details/VCHECK/
====
Updated! : http://old-dos.ru/index.php?page=files&mode=f … =show&id=103705
======

Reply 4 of 4, by kotel

User metadata
Rank Oldbie
Rank
Oldbie
Masaw wrote on 2025-07-24, 10:32:

regarding the Sality infected files, it's possible these files could contain only traces or part of the virus that was not completly removed or the file was corrupted when it was disinfected rendering the file non-executable.
That Adwgen is a "not-a-virus" it's a PUA (possible unwanted app), there is an option for kaspersky to be able to detect these kind of files otherwise if that option is not set it will not scan for it.
That Bolzano-S infected file could be a text or script (script.ini) file created by the virus to spread but not the actual virus, since this virus was written during the time when mIRC was still a popular chat client

By "...when it was disinfected rendering the file non-executable" you mean the virus code or the chrome installer? The installer is operational in some way but since it's the online and not offline installer, I won't connect it to my network.
Adwgen (adware generic) is infact an PUP, but it was only one sample that was undetected (Bearshare) while an torrent installer was blocked. Highly unlikely the PUP/PUA detection was off.
Bolzano-S files is one .data and one "pavlc) ELF executable (cannot run it on windows). As for the .INI files, I had a few "autorun" ini files which were detected as vbs malware generic (they all point to some random file I never saw).

Since these tests were done on low end hardware, one must account for lack of resources leading to misses.

"All my efforts were in vain...
Let that be my disappointment."
-Kotel