Serious Discussion Kaspersky received a compromise score of 0.003 in the 2026 AV Comparative malware test. What does this score mean for the average user?

nonamebob567

Level 1
Thread author
Apr 24, 2025
28
110
32
First of all, Kaspersky achieved a 99.97% protection level against 10k malware samples and only missed 3, and that is honestly impressive. Nice work, Kaspersky.

And to clarify, what I’m asking here is, what exactly does a 0.003 compromise score mean for the average Kaspersky user that relies on the security product to correct any mistakes he might make during his daily activities, such as checking emails, playing video games, and downloading necessary programs?

Should he be concerned about the compromise score in these lab tests when they involve an unrealistic amount of malware?

Does the malware that breached Kaspersky’s factory settings on the AV comparative test system include sophisticated or zero-day variants?

And theoretically speaking, do you think that maybe the Kaspersky default deny/trusted application mode fills the gap of the 99.97% protection score?

I get that if you intentionally run ten thousand pieces of malware on your computer all at once, even an antivirus made by God would not survive. Still, it might be best to get input from more knowledgeable users about the matter.

Thank you very much for helpful answers.
 
Last edited:
First of all, Kaspersky achieved a 99.97% protection level against 10k malware samples and only missed 3, and that is honestly impressive. Nice work, Kaspersky.

And to clarify, what I’m asking here is, what exactly does a 0.003 compromise score mean for the average Kaspersky user that relies on the security product to correct any mistakes he might make during his daily activities, such as checking emails, playing video games, and downloading necessary programs?

Should he be concerned about the compromise score?

AV-Comparatives tested Kaspersky Premium, version 21.24, using more than 10,000 malware samples.

Do the malware that breached Kaspersky’s factory settings on the AV comparative test system include sophisticated or zero-day variants?

And theoretically speaking, do you think that maybe the default deny/trusted application mode fills the gap of the excellent 99.97% protection score?

I get that if you intentionally run ten thousand pieces of malware on your computer all at once, even an antivirus made by God would not survive. Still, it might be best to get input from more knowledgeable users about the matter.

Thank you very much for helpful answers.
What the 0.003 compromise score means

A compromise score of 0.003 generally means that a very small number of test systems were considered compromised during that particular test. It does not mean that every Kaspersky user has a 0.3% chance of being compromised, nor that Kaspersky will block 99.97% of all malware encountered in real-world use.

The result is specific to:

  • The malware samples selected by AV-Comparatives
  • The test operating system and configuration
  • Kaspersky’s tested version and settings
  • The actions performed during the test
  • The time at which the test was conducted

If the result represents three failures out of approximately 10,000 samples, that is an excellent result. However, three samples are still important because they demonstrate that protection is not absolute. The result should be interpreted as a comparative laboratory measurement, not as an individual risk prediction.

Does this mean the average user should be concerned?

There is no reason to become alarmed based on this score alone. A user running a fully updated system with Kaspersky configured normally, automatic updates enabled, and sensible browsing habits is receiving a high level of protection according to that test.

The remaining risk is best reduced through layered practices:

  • Keep Windows, browsers, applications, and Kaspersky updated.
  • Avoid pirated software, cracks, keygens, and suspicious download portals.
  • Do not bypass warnings merely to run an unknown file.
  • Use a standard user account where practical.
  • Maintain current offline or otherwise protected backups.
  • Submit suspicious files to VirusTotal or a reputable security vendor for additional analysis.

An antivirus product is an important safety layer, but it cannot reliably compensate for every decision made by a user, particularly when a user explicitly allows an unknown program to run or disables a protection feature.

Were the missed samples sophisticated or zero-day malware?

That cannot be determined from the protection percentage or compromise score alone. Unless AV-Comparatives identifies the individual samples, their discovery dates, and their exploitation methods, it would be speculation to call them sophisticated, zero-day, or especially advanced.

A malware test set may contain a mixture of prevalent threats, newer samples, variants, and samples designed to test different protection layers. “Missed” also does not necessarily mean that the sample was completely invisible to every Kaspersky component. It may have been detected later, blocked after execution, prevented from causing significant damage, or classified as a compromise according to the test methodology.

The full AV-Comparatives report and methodology are needed to understand exactly what happened with each failed case.

Does Default Deny or Trusted Applications mode fill the gap?

A properly configured application-control or default-deny mechanism can reduce the chance that an undetected executable will run. It is therefore a useful additional layer, but it should not be considered a complete replacement for malware detection.

Its effectiveness depends on details such as:

  • Whether unknown applications are blocked or merely shown a prompt
  • How trusted applications and digitally signed files are classified
  • Whether scripts, document macros, installers, drivers, and child processes are controlled
  • Whether the user is allowed to approve the unknown program
  • Whether malware abuses an already trusted or vulnerable application

Strict default-deny configurations can also produce compatibility problems and false positives. A prompt-based mode may provide much less protection if the user routinely permits unknown applications.

Application control also cannot prevent every attack. Malware may exploit a vulnerability before an executable-control decision is made, abuse a legitimate signed program, use a trusted browser or script interpreter, steal credentials, or rely on the user voluntarily approving an action.

Overall assessment

The test result indicates very strong protection under AV-Comparatives’ conditions, while the compromise score reminds us that no security product blocks every threat. The score should not be converted into a personal infection probability, and there is insufficient information to characterize the missed samples as zero-days or highly sophisticated threats.

For most users, keeping Kaspersky and the operating system updated, leaving protective components enabled, avoiding deliberate overrides, and maintaining reliable backups are more valuable than switching to an overly restrictive configuration. Application control can provide extra protection for users who understand and can manage its prompts, but it should be regarded as an additional layer rather than a guarantee.
 
And to clarify, what I’m asking here is, what exactly does a 0.003 compromise score mean for the average Kaspersky user
It means Kaspersky is very good at detecting workaday criminal malware, almost perfect. But against government APT or advanced hackers you will always struggle no matter what AV you have..... I prefer to run KVRT though not a full K suite. Politics aside K is very good at what is does but the problem is really actually politics. I can't justify using a fully installed suite and giving full access to a banned AV. If their is 000.0001% chance that using K will get you compromised by the Kremlin then I can't use it.
 
When viewing any AV test result, especially as it pertains to Kaspersky, it is important to consider a couple of things:

1). it is not so much the number of samples used, but instead the time since the malware was released into the Wild of importance. Although the samples used are surely recent, it is not realistic to view many (if any) as true freshly released zero day threats. K has an advantage in the detection of new malware as they have (I assure you) a separate division staffed by coders, hackers, and criminals that scan the Dark Web for emerging ("beta malware", if you will) threats.

2). Pro tests are primarily composed of PE32 type files, with a much lesser amount of Scriptors in various forms used, against which some AM products aren't that savvy (K is).

Considering this, it would be reasonable to expect that with a more robust malware sampling by the Pro Testers K would shine more brightly.
 
a separate division staffed by coders, hackers, and criminals that scan the Dark Web for emerging ("beta malware", if you will) threats.
I remember reading elsewhere that K employs hackers to find vulnerabilities in their application. In another forum, people asked hackers of varying skill levels which antivirus caused them the most headache, and the majority agreed it was Kaspersky. Thanks for confirming my suspicion, "cruelsister".
 
Last edited:
Best AV I have ever used, if its illegal in your country then personally I would not use it, here its not so its on this PC.
Agreed. And thankfully Kaspersky is not illegal where I'm from 😊. I can’t imagine not having Kaspersky show me how reputable a program is before I install it. I always look for alternatives if a program I plan to use has fewer than 1,000 Kaspersky users.
 
It means it's time to av-hop, because over here we don't accept anything below 99.98%
LOL...and every month switch to the AV that achieved 100% in that one months test.

I'm really boring, I'm still not sure how to download malware on my devices. I guess it's time to start downloading 10,000 files in the next month or two, so I can see if F-Secure Total or Bitdefender free are really protecting me 😅 Still malware free since the days of XP.
 
In simple terms....
Best of the Best!
 

Attachments

  • Screenshot_20260810-102743_(1).png
    Screenshot_20260810-102743_(1).png
    462.1 KB · Views: 67
And if you're in the US, there are other AV's that can protect us just as well, along with good browsing habits and "common sense". (I was once reproved on this forum for using the term, "common sense" :rolleyes:)
You ain't talking about Comodo right? Your post already got disclaimers. Like an AV saying use me but from time to time I might get infected. Hehe
 
On a serious note K isn't perfect. Zscaler latest blog post on this new malware isn't detected by K yet albeit pretty certain it would be detected dynamically!
C2s are detected so in that way it has done its job!
 
It means Kaspersky is very good at detecting workaday criminal malware, almost perfect. But against government APT or advanced hackers you will always struggle no matter what AV you have..... I prefer to run KVRT though not a full K suite. Politics aside K is very good at what is does but the problem is really actually politics. I can't justify using a fully installed suite and giving full access to a banned AV. If their is 000.0001% chance that using K will get you compromised by the Kremlin then I can't use it.
I completely understand your caution, and given the current geopolitical climate, it makes total sense to weigh those risks. You’re also spoton about two things: Kaspersky’s engine is undeniably top-tier for everyday threats, and no AV is a magic shield against a targeted APT.

But let’s look at the actual math and logic behind the setup you're choosing. You’re essentially trading the best in class defense against the 99.9% of common malware you’re highly likely to encounter, just to avoid a hypothetical 0.0001% risk of a Kremlin backdoor.

since you already agree that no AV can fully stop an APT, dropping Kaspersky doesn’t actually make you immune to state actors. It just means you’re handing that exact same deep, kernel-level system access to a different vendor headquartered in a different country (like the US or Romania). You’re just trading one theoretical 0.0001% state-actor risk for another, while statistically lowering your shield against the everyday ransomware you will face.

Also, from a purely technical standpoint, KVRT still requires full Admin/System privileges to scan and delete files. If the vendor’s code was truly malicious or compromised, an on-demand scanner would be just as easily weaponized as a full suite.

isn't it statistically riskier to downgrade your actual, everyday protection against guaranteed threats, just to hand the exact same system access to a different nation-state that also has a history of cyber-espionage?