according to what I read from the testers, both were tested with internet connections, under a VPN in VMs:
Avast free: File-Web-Behavior Shields, PUP enabled -> blocked | Bonus test: only file shield was disabled -> failed to react, no notification, everything was encrypted
AVG internet security: was tested at least 5-6 hours after avast, similar conditions. Default settings, PUP enabled. Blocked almost instantly by IDP and nothing was encrypted
the AVG tester performed a bonus test WITHOUT the internet connection and AVG's IDP failed to react. As soon as he turned on the internet, IDP blocked it. The 2 testers thought that IDP was cloud-based because of this. Moreover, they noticed, everytime they ran the same samples, they received different numbers from IDP
EDIT: the tester told me this, thank you:
Avast did detect it as Filerep so perhaps it was not analyzed thoroughly as of that time. This could explain why IDP did not get the "correct" answer from cloud or a confirmation of this file being malware.
AVAST: FileRepMalware - IDP did not detect.
AVG: Malware Gen - IDP detected.