I have lost faith in signature AV and CVE feeds for that matter. Attackers test against scanners until they come back clean and avoid known fingerprints. The only way I see to catch things now is behaviour diffing through static analysis.
Disclosure: I build Vigilance, which does this.
The point of AV is to catch that PCI DSS stamp of approval, not catch malware. Regulatory capture is the best marketing strategy