We may earn affiliate commissions for the recommended products. Learn more

How we test and review antiviruses

How we test and review antiviruses

An antivirus software works quietly in the background, preventing cybersecurity threats, such as ransomware, spyware, and zero-day attacks, from infecting your device and abusing the data stored there. However, since the workings of an antivirus are mostly invisible, how can you know it is actually doing the promised job? And that is exactly why testing antivirus software is so important, as the gap between vendor claims and real-world performance can be gigantic.

Here at VPNpro, our cybersecurity testing team conducts hands-on evaluations of antivirus software. We use real malware samples, including phishing-based threats, spyware, and ransomware, to accurately assess how effectively each product detects and blocks active attacks in real-world scenarios. Our tests aim to deliver antivirus reviews with insights from real user experiences, so you know exactly what to expect. This includes assessing false positives to ensure your daily-use files and applications are not incorrectly flagged, as this can greatly interfere with your day-to-day device use. Additionally, we evaluate CPU usage and background activity while the antivirus is protecting your device. Lastly, for a truly in-depth outlook, we review usability, long-term reliability, and transparency, with particular attention to privacy practices and data-handling policies. Usually, testing spans several weeks, with timely retesting at least once a year or when new software updates are rolled out.

To deliver truly unbiased antivirus software reviews, we strictly follow our in-house testing processes rather than relying on vendor-provided benchmarks. Once our tests are completed, we compare our findings with independent labs such as AV-Test and AV-Comparatives to validate detection rates, false positives, and performance impact. Ultimately, this multi-pronged approach to testing is how we can ensure evidence-based reviews that are relevant and helpful to actual everyday users.

Why you can trust VPNpro reviews

All VPNpro reviews are carried out by our research team, who follow a clear, structured process. Every product is tested and scored based on real data and factual findings. We use strict guidelines for each product, which ensure a fair and consistent scoring process and evaluation process.

Every review is backed by a thorough, hands-on testing process. Our team tests products in real-world conditions as well as controlled environments to see how they actually perform in daily use. For antivirus testing, we use verified malware samples from Bazaar.abuse.ch, a trusted source used by cybersecurity experts and antivirus vendors, covering threats like ransomware, spyware, keyloggers, and miners. Each product is tested against 100 to 150 malware samples to measure how effectively it detects and blocks threats. We also review results from independent testing labs, such as AV-Comparatives and AV-Test, that regularly evaluate antivirus software across different platforms. Products are continuously retested as new threats appear and software updates roll out.

What we evaluate in antivirus software

Every antivirus software is reviewed using the same set of parameters and the same collection of tests to ensure a fair testing ground. Here’s what we consider during testing:

  • Malware detection rates. We test each antivirus against 100 to 150 real malware samples in a controlled environment, tracking how many threats the software catches and removes. A detection rate of 80% or above is considered solid performance, while top-tier AVs usually reach 90-100% effectiveness. We test both real-time protection, which blocks threats as they appear, and on-demand scanning, which finds threats during a manual scan.
  • Ransomware protection. We download real ransomware samples and run antivirus scans to see how well the software handles them. We use controlled environments for the test. We also look at any built-in ransomware features, such as file backup or recovery tools, that can help limit damage if an attack gets through.
Testing TotalAV ransomware protection accuracy
Testing TotalAV ransomware protection accuracy
  • Zero-day threat detection. Zero-day threats are brand-new attacks that security software has not yet seen or been updated to handle. We do not test these directly, but we reference results from independent labs like AV-Test, AV-Comparatives, and SE Labs, which regularly measure how well antivirus products respond to unknown threats
  • False positives. We track how often an antivirus mistakenly flags a safe file or program as a threat.
  • Web protection. We collect known phishing links and malicious URLs, including both domain-based and IP-based links, and attempt to visit them while the antivirus is running. We record how many are successfully blocked and calculate a score based on the percentage of harmful sites the software prevented access to.
Avast One phishing alerts during testing
  • Firewall. Where a firewall is included, we assess how well it monitors incoming and outgoing network traffic, its customization options, and whether it can prevent unauthorized access or port scanning. We also check if it monitors local applications for unusual network activity.
  • Additional features. We test any extra tools the antivirus includes using the same approach we apply when reviewing those tools as standalone products. This covers features like VPNs, password managers, and ad blockers.

The combination of the tested features and the outcome of tests allows us to form an unbiased conclusion on the effectiveness of the antivirus software. For a well-rounded review, we also compare our findings with those from independent testing labs, such as AV-Test and AV-Comparatives.

Malware detection testing

Malware detection is the fundamental function of any antivirus software, and determining it is one of the most important factors in evaluating the effectiveness of device protection. For our malware detection testing, we use real malware samples from bazaar.abuse.ch, which are widely used in security research and threat analysis. For each product, we use 100-150 malware samples and test the software’s accuracy and responsiveness in a controlled environment while recreating real-world attack scenarios.

Real-time protection assessment includes introducing active threats and observing whether the antivirus blocks or neutralizes the malicious files immediately. Our top-performing software typically detects and successfully blocks 90-100% of threats in real time. Such results prove high effectiveness in protection against active attacks. Then, we perform on-demand scans using the same set of malware samples, measuring how accurately each software detects threats during manual or scheduled scans.

Ultimately, we combine our findings from the real-time and on-demand scans, evaluate them against independent testing labs' results, and identify which antivirus software can provide reliable real-world protection.

Performance impact testing

All of our performance impact tests are done in a controlled environment using standardized devices, such as:

  • Windows. Virtualbox VM with Windows 11 (10 GB RAM, 120 GB dynamic HDD, and 2 CPU cores) installed on a Lenovo ThinkPad T14S Gen2 device (AMD Ryzen 5 PRO 5650U processor, 16 GB RAM, 256 GB SSD, Windows 11 Pro OS). Or, Virtualbox VM with Windows 11 (20 GB RAM and 4 CPU cores) on Lenovo ThinkStation (AMD Ryzen Threadripper PRO 3945WX 12-core processor, 3.99 GHz, 64 GB RAM, 3TB SSD, Windows 11).
  • MacBook Pro. M2 16 GB RAM, 500 GB storage, macOS Tahoe 26.2, running a virtual machine with 4GB allocated RAM and 64 GB storage.
  • Android. Google Pixel 9, 128 GB storage, 12 GB RAM, with Google Tensor G4 chip, running on Android 16.
  • iOS. iPhone 7 (model MN8X2), with iOS version 15.7.1., 32GB internal storage, 2GB RAM, CPU Quad-core 2.34 GHz (2x Hurricane + 2x Zephyr).
Total Defense performance impact test
Total Defense performance impact test

Using the same devices for testing every antivirus software ensures consistent and comparable results. Moreover, we use clean systems under easily repeatable conditions to accurately measure both performance impact and malware detection behavior.

First, we measure how much CPU and RAM the antivirus uses during scans. This gives us insight into how resource-intensive each product is. In our tests, well-optimized software typically keeps CPU usage below 20–30% during full scans, while less efficient solutions can exceed 50%, causing noticeable slowdowns. Similarly, most top-tier antivirus software uses under 300–500 MB of RAM, allowing for comfortable multitasking.

Eset performance impact test
Eset performance impact test

We also assess overall system responsiveness by observing how smoothly everyday tasks, such as browsing, file transfers, and application launches, run while the antivirus operates in the background. Lastly, we measure startup impact by tracking how long the software takes to fully load after boot. A well-optimized antivirus should add only a few seconds to startup time, while heavier software may significantly delay system loading.

False Positive Testing

False positives happen when an antivirus incorrectly flags completely secure files or applications, such as VPNs, as potentially dangerous or even malicious. If a software misidentifies files and applications frequently, the user will receive numerous annoying false-positive warnings that can severely obstruct day-to-day device use. So, while no antivirus software is completely immune to occasional false positives, testing for them is essential for real-world usability.

We evaluate how often each antivirus flags legitimate files during everyday scenarios, such as installing trusted software, downloading common file types, and running standard system processes. This helps us assess how well each product balances security and accuracy.

To provide you with some perspective, independent testing from AV-Comparatives shows that top-tier antivirus solutions typically generate up to 10 false positives per test, a finding we confirmed in our in-house testing under the same conditions. Meanwhile, low-quality antivirus software may generate up to 80 false positives during a single test. As you can imagine, this number of false notifications and blocking of useful applications can really impact your device use.

Antivirus software is typically grouped into the following tiers based on false positive frequency:

Performance tier Typical false positive range What it means for everyday users
Top-tier antivirus 0-10 Minimal disruptions with highly accurate detections
Strong performers 10-20 Occasional false alerts, but generally manageable
Average performers 20-40 Noticeable interruptions that may affect usability
Below-average performers 40-80+ Frequently, highly disruptive alerts

After evaluating the frequency of false positives, we also note their impact. This is done by assessing the importance of blocked applications and the ease of restoring or whitelisting misidentified safe files. This part of the testing is important for ensuring the software will not disrupt everyday use or erode user trust.

We always aim to ensure a fair testing ground by applying the same conditions across all products. After our in-house tests are complete, we validate our findings against independent labs, such as AV-Test and AV-Comparatives. This way, we can easily deliver a data-based identification of antiviruses that provide accurate protection without interfering with your daily device use.

User experience and customer support

As part of our tests, we assess how easy the software is to use, particularly for non-technical users. This includes evaluating how easy it is to install the software, noting how quickly the process is, and whether it is intuitive and well-guided. Then, we check how well the interface is laid out, whether all features are accessible in one place, and whether clear guidance or tutorials are provided.

Norton 360 dashboard as part of usability testing
Norton 360 dashboard as part of usability testing

After the initial usability evaluations, we test scan options and scheduling to determine how flexible and user-friendly they are. This includes determining whether users can easily run quick, full, or custom scans and automate them without confusion. An important part of this stage is assessing alert clarity. We do this by observing how clearly threats and notifications are presented, ensuring they are informative without being overly intrusive to normal use.

For customer support evaluations, we first check what support channels are available, such as live chat, email, phone line, or knowledge bases, and how easy it is to access them. We then proceed to test response times and the quality of assistance provided. In the end, we can get a fair picture of how quickly a user should expect their problems to be solved and whether they will receive clear, knowledgeable guidance when needed.

Privacy and data handling

All antivirus software collects a level of user data, as this is a fundamental part of how modern threat detection works. However, it is crucial to know that the amount and type of data collected can vary significantly between products and providers. Understanding the exact level of data collection and privacy when using a particular antivirus may influence your ultimate choice of software.

As part of our testing process, we evaluate each product’s data collection practices by analyzing privacy policies. Such documentation can be found on the provider’s official website; if we do not find it, it immediately flags the brand as unreliable. Additionally, during real-world testing, we monitor the data transmitted during installation, use, and threat-detection scenarios. This also includes whether telemetry is enabled by default and what information is shared, including usage data, device identifiers, or threat reports. This way, we can observe whether providers truthfully limit data sharing to anonymized metadata or if they transmit more detailed diagnostic data without making adjustments.

In addition to the steps above, we also test the cloud scanning behavior of each software. This is done by introducing suspicious files and observing what is sent to external servers; most importantly, whether it’s limited to file hashes or includes full file uploads. Hash-based checks are much more privacy-friendly; however, some antiviruses upload full files. While the latter provides a deeper analysis, it does have greater privacy risks. Lastly, we evaluate how clearly these processes are disclosed and whether users can opt out or at least adjust privacy settings.

Once we are done testing an antivirus software, we match our findings with accepted data protection principles, such as those defined under frameworks like the General Data Protection Regulation (GDPR). This way, we can come to a highly informed conclusion and identify software with both strong protection and privacy-friendly processes.

How we assign antivirus ratings

Our final rating reflects how a product performs across all areas of testing. We place the greatest weight on core protection, as this is the primary function of any antivirus. Additionally, we factor in performance impact, ease of use, additional features, value for money, customer support, and privacy practices.

For our scoring to be consistent and fair, we use a weighted scoring system, which ensures objective comparisons. Antivirus software scores are based on actual and measurable results from our in-house testing, including detection rates, false positives, performance impact, and usability. While security effectiveness and accuracy have the highest impact on the final score, performance, feature set, and support also contribute to the overall evaluation.

Scoring breakdown:

  • Security: 40%
  • Performance: 20%
  • Features and value: 20%
  • Usability: 10%
  • Support: 10%

Antivirus software is ever-evolving with consistent update rollouts. To keep up and ensure the relevancy of our reviews, we regularly retest software at least once a year or right after a major update is released, including such as seucurity improvement or added features. If we find the product performance has changed after our retesting sessions, we update our reviews with information on performance or malware detection accuracy in a timely manner.

VPNpro Tech Analysts-Writers Team

The VPNpro tech analysts-writers team is made up of experienced cybersecurity professionals specializing in antivirus software and VPN testing, as well as other relevant online security topics. To provide readers with insightful, unbiased, and actionable product reviews, the team conducts hands-on testing and seeks further insights through in-depth research.

Justė Kairytė – Barkauskienė
Senior tech copywriter

Justė specializes in antivirus software and VPN performance, as well as privacy testing.



Djordje Djordjevic
Cybersecurity analyst and writer

Djordje is a verified expert in VPNs and antivirus software, online privacy, cybercrime, safe torrenting, and bypassing geo-restrictions.

Chris Bluvshtein

Chris Bluvhstein
Senior tech writer/analyst

Chris has analyzed various cybersecurity tools, their capabilities, and their performance, focusing mostly on antivirus software and VPNs.

Jump to section