Earlier quoted context omitted.
Encoders and compactors are not good actually they usually leave too many patterns that are easy to detect. The might work on some binaries in some cases but if you want to avoid evasion refactor the malware yourself. Encoders and compactors are intended to modify existing binaries only :)
That's what I'm seeing people doing (modify existing binaries): https://www.google.com/#q=shikata+ga+nai+antivirus Seems like it's pretty effective for bypassing AV according to how everyone is using it.
1st result 2012: "If you want to avoid detection, a 60% success rate is not good enough. Remember, our implant was caught by 40% of the products, not 40% of the targets. Assuming the better anti-virus products have a larger market share, our 40% product failure rate could look more like an 80 or 90% detection rate on target machines. - See more at: http://www.digitalthreat.net/2012/02/anti-virus-evasion-choo...
4th result 2014: "There are a couple of built in encoders in Metasploit (shikata ga nai is the most popular one), but these signatures have been updated in many Antivirus solutions, resulting in detection."
Every decent AV out there today has signatures of packers and encoders they are very easy to find since the artifacts of things like PE headers and binary cave of the encoded binaries will be identical every time you use them.
Most people who claim it works are simply rehashing the same old metasploit guides that are not really relevant in the real world anything that is wide used will be singnatured in a second by every AV company.
Yes if you encode it and upload it to VirusTotal even today you might get 50% or more evasion but those 50% of products will have maybe 5% of the market, and pretty much zero enterprise users.