Running a malware sample directly from the desktop is a fundamentally flawed testing method for the same reason a simple script is, it ignores the context of the attack.
Sometimes this can depend on the purpose of the test. It is a common method of showing concrete weakness or vulnerability in protection. Such a test is a warning that the presented attack vector can be used as part of a dangerous attack in the wild. Of course, those tests usually do not affect the overall efficiency of the AV. Unfortunately, they are commonly misunderstood, similarly to Malware Protection tests.
Last edited:



