Microsoft's OneCare takes last place in anti-virus evaluation


Recommended Posts

The top dog in the tests was G Data Security's AntiVirusKit

March 01, 2007 -- Microsoft's Windows Live OneCare came in dead last out of a group of 17 anti-virus programs tested against hundreds of thousands of worms, viruses, Trojan horses and other malware, an Austrian anti-virus researcher reported yesterday.

The AV Comparatives Web site, which is maintained by Andreas Cleminti from Innsbruck, Austria, posts quarterly results of tests that pit the top anti-virus products against a dynamic list of nearly half a million individual pieces of malware.

Top dog, according to Cleminti's tests, was G Data Security's AntiVirusKit (AVK), which nailed 99.5% of the malicious code. Not far behind were AEC's TrustPort AV WS, at 99.4%, Avira's AntiVir PE Premium, at 98.9%, MicroWorld's eScan Anti-Virus, at 97.9%, F-Secure's Anti-Virus, at 97.9%, and Kaspersky Labs' AV, which stopped 97.9% of the malware.

Better known products such as Symantec's Norton Anti-Virus and McAfee's VirusScan posted results of 96.8% and 91.6%, respectively.

Holding the bottom spot was Microsoft's Windows Live OneCare, the consumer security suite that the Redmond, Wash. developer launched last year. OneCare took care of just 82.4% of the malware.

Cleminti also tested the 17 products against polymorphic viruses, those which produce sometimes vast numbers of variants as they try to sneak by scanners. "The results of the polymorphic test are of importance because they how flexible an anti-virus scan engine is and how good the detection quality of complex viruses is," said Cleminti in his write-up.

Only Symantec's Norton AntiVirus and ESET's NOD32 Anti-Virus caught every variant of the 12 polymorphic families, he said. In that test, OneCare placed 15th, detecting every version of only two families, and missing seven of the polymorphic families completely.

Cleminti's report is available online (download PDF).

This is not the first evaluation to give a Microsoft security program a black eye. Last week, for example, Australian security company PC Tools released research that claimed Windows Defender -- Microsoft's anti-spyware title -- detected just 46% to 53% of spyware.

"We are looking closely at the methodology and results of the test to ensure that Windows Live OneCare performs better in future tests," a Microsoft spokesperson said.

Source: Computerworld

Not to be too off topic, but the antivirus programs that took top honours... I've never heard about them before and now I'm intrigued ;)

OneCare... well that's not surprising based on what has already been said about the program, I'm just curious how this would be allowed to happen. I would assume they'd have plenty to test their product against

Took me long to find it. (Well, 1 minute is long to find the real site of the "best" antivirus IMO)

http://www.gdata.de/trade/productview/727/16/

Btw, for people saying that it's good for MS's first entry, let me says that MS actually brought a company of Antivirus and a company of anti-spyware for making One Care in 2005...

http://www.pcpro.co.uk/news/72600/microsof...-consumers.html

Edited by Nienor
Took me long to find it. (Well, 1 minute is long to find the real site of the "best" antivirus IMO)

http://www.gdata.de/trade/productview/727/16/

Btw, for people saying that it's good for MS's first entry, let me says that MS actually brought a company of Antivirus and a company of anti-spyware for making One Care in 2005...

http://www.pcpro.co.uk/news/72600/microsof...-consumers.html

Well yes they bought the company to make the software. But its them who are doing the virus finding and updates yeh?

The previous team that was working on the previous software from the previous company with some new MS people to put this together :p

I simply mean that is not a "new" start...

to many charts

best antivirus is?

Check the summary PDF? The answer depends on your needs. Not only detection accuracy plays a role, but feature sets too.

http://www.av-comparatives.org/seiten/erge...summary2006.pdf

I personally use and recommend NOD32 for great detection rates, fast speed, configurability, and frequent updates. That AV also takes the prize as Overall Winner in this test. Kaspersky is often brought forward as having near top scores in accuracy, but it lacks e.g. heuristic scans like NOD32 that can occasionally be useful in very sudden virus outbreaks. I'd avoid anything Symantec/Norton as many agree it has low performance. We also missed good enterprise-scale monitoring features in the Corporate Edition of Symantec Antivirus here. Try AVG or Avast! if you're a home user that can't stomach paying for it. :)

Edited by Jugalator
Check the summary PDF? The answer depends on your needs. Not only detection accuracy plays a role, but feature sets too.

http://www.av-comparatives.org/seiten/erge...summary2006.pdf

The 2006 tests are totally outdated, and the test results are not valid anymore!

Look at the actual test results from February 2007 which just got released, things changed quite a bit:

http://www.av-comparatives.org/

Here are the results from the 2007 report pdf:

av-comparatives-feb07.png

As you can see, Nod32 did even worse than Symantec! :blink:

Anyone ever use this AntiVirusKit? If so, how is it?

I'm actually using it since last december (screenshot) and the system resources usage is pretty acceptable IMO (the maker claims this 2007 version is around 30% lighter from previous version). However, I had to make some tweaking on it disabling certain options (did also a custom install) in order to suit AVK 2007 to my needs.

Btw, AVK uses two antivirus engines, the current 2007 version includes the Kaspersky+Avast! engines.

Former 2006v. was Kasp+BitDefender :shiftyninja:

The BBC has just picked this up: http://news.bbc.co.uk/1/hi/technology/6418965.stm

Windows fails second virus test

The OneCare software has failed two independent tests. Microsoft's Live OneCare security software has failed tests which check how well it spots and stops malicious programs designed to attack Windows.

OneCare was the only failure among 17 anti-virus programs tested by the AV Comparatives organisation. Microsoft's software only spotted 82.4% of the 500,000 viruses that the independent group subjected it to. The test is the second in less than a month that Microsoft's anti-virus software has failed.

Batfink

Who really uses CareOne! If you really want a antivirus program, you are better off buying a third party software, then using CareOne.

Exactly. No one with at least one working brain cell left would use that OneCare crap :x

Absolutely any other AV is better - even Norton :pinch:

Exactly. No one with at least one working brain cell left would use that OneCare crap :x

Absolutely any other AV is better - even Norton :pinch:

I have several working brain cells and I use OneCare on my laptop. It works fine for me, not to mention that I'm very good about avoiding any suspicious files. Please don't assume that everyone who uses this program doesn't know any better.

I have several working brain cells and I use OneCare on my laptop. It works fine for me, not to mention that I'm very good about avoiding any suspicious files. Please don't assume that everyone who uses this program doesn't know any better.

You mean you knowingly wasted money on a crap program that placed last in the AV test, even though you knew better? :blink:

That doesn't sound very smart to me, not at all :pinch:

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Simple answer is yes, you will still get the Windows updates and as long as browser is up to date, you will be good. Only thing secure boot does is protect you against boot level threats and make it harder to install other OS's. I've been looking into this pretty thoroughly lately myself as wifes computer has secure boot disabled plus my other, older computers that run Linux, don't have secure boot enabled. Have seen all kinds of questions about this on the Linux Mint and MX Linux forums. Just don't suddenly enable secure boot now.
    • How many other companies will follow Ford's lead? Or, have they already gotten lazy and become enslaved to AI--and now can't figure out how to get out of that mess.
    • Why would any self-respecting intelligent person follow any recommendation by Donald's GOP administration? With almost two years of fabrications, deceit, and blatantly illegal behavior, why believe them now? They had best be gone after the November 2026 election, so we'll wait and see.
    • AltSendme 0.4.1 by Razvan Serea AltSendme is a minimal, cross-platform application designed for fast, secure, and private peer-to-peer file transfers. It allows users to send files or entire directories directly between devices without relying on cloud servers, accounts, or any personal information. Everything is encrypted end-to-end using modern protocols like QUIC and TLS 1.3, ensuring both strong security and low-latency performance. Transfers are verified with BLAKE3 for data integrity, and interrupted downloads automatically resume, making the experience reliable even on unstable connections. You can transfer anything—images, videos, documents, and more. Integrity checks are performed on both ends, so your files are automatically verified for correctness during both sending and receiving. AltSendme works seamlessly across local networks or long-distance links, capable of saturating multi-gigabit connections for extremely fast delivery. With built-in NAT traversal and encrypted relay fallback, it connects devices almost anywhere. The app integrates with the Sendme CLI and will soon support mobile and web platforms. Fully free and open-source, AltSendme offers a lightweight, privacy-first alternative to traditional cloud-based services, removing size limits, upload costs, and unnecessary data exposure. AltSendme 0.4.1 changelog: Release Highlights Self-hosted relays: Run your own iroh relay so transfers don't rely on public infrastructure. Includes a full deployment template in deploy/relay/ with Docker Compose for a VPS and configuration examples for production use. Fly.io support: One-click deploy template for Fly.io, including a quick-start config (fly.dev.toml) for testing without a custom domain, plus production setup with Let's Encrypt and your own hostname. Relay settings UI: New Settings → Network panel to choose how AltSendme connects: automatic public relays, custom self-hosted URLs (with optional auth token), or disabled. Test connections, verify latency, and see live relay status in the footer. Disable relays: Turn off relay servers entirely when you only need same-network transfers (e.g. LAN). Direct connections only. No relay hop required when devices can reach each other. Android graduates from beta: Android is now part of the regular release cycle alongside desktop. APKs ship with each version (universal, arm64, and armv7). Other improvements Private relay access control via shared auth token Relay fallback notifications when a custom relay is unreachable Broadcast mode toggle in sharing settings Android release build fixes (split-per-ABI APKs, universal APK preservation) UI polish: mobile safe-area insets, dropzone layout, transfer progress animation Bug fixes for minification-related serialization issues and system tray icon loading What's Changed feat(relay): add relay status functionality and settings UI (a120cdf) feat(relay): implement custom relay server configuration and verification (51276c7) feat(relay): add configuration for private relay access and enhance observability features (48fbabf) feat(relay): enhance relay URL validation, display connection status (d4fffa0) feat(relay): add RelayChangeGuard component and enhance relay-related translations (16ba514) feat(broadcast): add toggle setting for broadcast mode in sharing UI (ca6d977) fix(relay): correct QUIC discovery port, pin image, templatize fly.dev (52a2ba5) fix: More broken serialization due to minification (67491a9) fix(android): preserve true universal APK across per-ABI builds (e9f256f) fix(ui): conditional safe-area insets padding on mobile (1182f0e) refactor(transfer): CircularRing component animation fix (944572b) chore(android): drop x86 and x86_64 release APKs, keep universal+arm64+armv7 (34ada0b) Download: AltSendme 0.4.1 | ARM64 | ~9.0 MB (Open Source) Download: AltSendme for MacOS | Android Links: AltSendme Home Page | GitHub | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • You are mostly right about the ephemeral nature of it. As I mention in the article, if you dont add a second device or take a backup of your account before uninstalling it, then yes you will lose access to your account. That said, in terms of actual user experience when you sync multiple devices your message history carries across and there's also a Saved Messages chat like there is on Telegram to send messages and attachments between your installs. But yh, what you point out are correct and its not trying to emulate Messenger or Telegram.
  • Recent Achievements

    • Week One Done
      flexorcist earned a badge
      Week One Done
    • One Month Later
      Woland13 earned a badge
      One Month Later
    • Week One Done
      Woland13 earned a badge
      Week One Done
    • One Year In
      bernmeister earned a badge
      One Year In
    • Week One Done
      Scoobystu earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      495
    2. 2
      +Edouard
      225
    3. 3
      PsYcHoKiLLa
      150
    4. 4
      Steven P.
      75
    5. 5
      FloatingFatMan
      71
  • Tell a friend

    Love Neowin? Tell a friend!