Ok honestly, I do have my doubts. I'm happy with the idea, but I have some questions.
1) some products use the cloud, so cutting the internet connection will not test the products real detection capabilities.
2) how do you separate the real malware from false positives ?
3) although I'm happy you test 64 bit, some products could've different results under 32 bit (sandboxing and stuff)
4) speaking of sandboxing, considering that the malware runs in a sandbox but will appear on task manager --> pass or not ?
5) how are you planning on reacting to pop-ups ? Paranoid - advanced user - newbie - ...
thanks and good luck,
eXp