Unsolved
This post is more than 5 years old
5 Journeyman
•
5.8K Posts
•
17.3K Points
0
9346
May 10th, 2013 12:00
AV-Comparatives: AV Impact on System Performance
AV-C has released its results of tests done in April 2013, of 21 popular standalone AVs (both free and paid), to determine how much they slow down various tasks on a Windows 7 Professional 64 bit system:
http://www.av-comparatives.org/wp-content/uploads/2013/05/avc_per_201304_en.pdf
Comments:
- This report also includes the benchmark results from PC Mark 7 Professional Edition testing suite, which evaluates pretty much the same thing. Curiously AV-c combines their test results with PC Mark test results to achieve a final score, upon which various AV-C Award levels are based.
- Although Microsoft Security Essentials (MSE) is tested, and got a respectable score, it was excluded from competition for an Award level, being used instead as a baseline for comparison to other AVs. (MSE ranked 8th out of 21 for lowest impact). Had it been included, it would have achieved an "Advanced" award. Avast 8 Free ranked 5th, andwas awarded "Advanced+" status.
- If you look at the raw individual results, you will be surprised (at least I was) at how little impact most of these AVs have on modern system performance. I'm not sure the small differences noted are significant, or would be noticed by most users of recently purchased PCs. It was only a few years ago that various AVs were labelled "resource hogs" but I see no such evidence in these tests. (I note the testbed PC used an Intel Core i5-3330 CPU and 4GB of RAM.) Results on older/slower PCs would likely be different.
- Buried in the "Test Methods" is an interesting finding - only 5 AVs loaded sufficiently early in the bootup to block malware in the startup folder from executing. MSE was the only free AV to do so. (This finding was not germane to these performance tests).
- Finally, these results apply only to standalone AVs, not to security suites.


ky331
5 Journeyman
•
15.6K Posts
•
45K Points
0
May 10th, 2013 14:00
"an interesting finding - only 5 AVs loaded sufficiently early in the bootup to block malware in the startup folder from executing. MSE was the only free AV to do so".
Not a good sign for the rest :emotion-7: You gotta wonder, since there's obviously a way to prioritize what gets loaded/executed first, why an A-V isn't always the first thing to load immediately after the essential Windows system files...
ky331
5 Journeyman
•
15.6K Posts
•
45K Points
0
May 10th, 2013 17:00
I've done more thinking on this issue... and while I still believe it's possible and appropriate for an A-V program to "get its claws" into the bootup sequence very early... I don't believe failure to do so is as problematic as it might seem:
In order for malware to be IN the startup folder at bootup, it had to be PLACED THERE previously. So, unless it was "spontanesouly generated" during the bootup process, prior to Windows looking into the startup folder, its creation and placement there (perhaps using a different name) would have had to been made during the user's previous session --- and if so, it should have been caught by one's [active] anti-virus at that point! Or am I being naive???
[I'm not saying anything about virus/malware that's unknown to the A-V... if it's not in the database/heurisitics, then obviously the A-V can't detect it, neither upon creation nor in the earliest of bootups. But for items known to the A-V, the A-V should be able to detect the malware upon a file's download and/or creation, quarantining (or otherwise handling) it at that point, leaving nothing around for the subsequent bootup...]
joe53
5 Journeyman
•
5.8K Posts
•
17.3K Points
0
May 10th, 2013 18:00
Your logic is impeccable, ky.
If your AV didn't detect a given malware in the previous session, it is unlikely to detect it at bootup, no matter how early it loads. This assumes the (undetectable) malware at startup is the same as in the previous session, however, which might not be the case. I'm out of my league here, but is it plausible that the undetected malware might inject other, known malware (such as a boot sector virus) into the startup folder, which the AV would detect? And would your AV alert you? In any event, in such a scenario your system is already compromised.
I don't know how important an early load of your AV at bootup is - I only mentioned it because AV-C seemed to think it worth noting.
dalem29
2 Intern
•
2.2K Posts
0
May 11th, 2013 06:00
On my main system, according to the icons that appear in the tray...Avira is the last thing to load. However, MBAM Pro is the first, even beating out WinPatrol. So I have no idea if its early appearance, with it's "Realtime Proactive Protection" compensates in some way from Avira's tardiness. Hoping it does. At any rate, glad I made the investment in this program.