Recent Results in March 2026

Latest DATA FROM the advanced in-the-wild malware test

ico top recent results

Summary of March 2026

11

tested
solutions

334

unique
SAMPLES

316

malware hosted over HTTP

21

malware hosted over HTTPS

121

average malicious changes [1]

WEB-LAYER PROTECTION

81 %

RUNTIME DEFENSE

3 %

average blocked malware [2]

100 %

Potential data breaches

0
2.99 s

Average Industry
Remediation Time

* based on data telemetry

0 s

The quickest average remediation time

mks vir logo
Bitdefender logo
ESET logo
[1] The number of harmful changes made to Windows during dynamic analysis of the malware sample.
[2] Average blocking of malware by all tested solutions, regardless of level of prevention or protection.

TOP 3

HIJACKED SERVERS LOCATION

flag deutch
45
flag china
61
flag usa
34

TOP 3

TLD COMPROMISED DOMAINS​

.com

14

.de

1

.net

1

Examples illustrating the blocking of malware in the test

LOLBins in statistical terms

Legitimate and trusted software and built-in components in Windows are often used by cybercriminals to hide malicious activity. The so-called “Living off the Land Binaries” (LOLBin) are necessary for the proper functioning of the operating system. During a cyberattack, it can be difficult or impossible to block them, making them a very attractive method for malware developers. Below we present the most commonly used LOLBin in this edition of the test.

svchost.exe
12910
msedge.exe
8556
certutil.exe
8007
explorer.exe
4914
sh.exe
4137
taskhostw.exe
2955

Malware Comparison Table in March 2026

The following summary shows a comparison of tested solutions to protect workstations against malware. We encourage you to become familiar with a detailed description and read our testing methodology in order to understand the results.

WEB-LAYER PROTECTION: The classification concerns detecting malware samples before they are launched in the system.
RUNTIME DEFENSE: The analysis level, i.e. a virus has been run and blocked by a tested product.
SYSTEM COMPROMISE: The failure, i.e. a virus hasn’t been blocked and it has infected a system.
Sandbox Column: Number of indicators, i.e. malicious changes made to the system without the anti-virus installed.

Automatic Average Remediation Time (RT): The time expressed in seconds counted from the introduction of malware into the system by the browser, through the launch to the detecting and resolving a security incident.

Remediation Time (RT) Legend
The time expressed in seconds from the introduction of malware into the system by a browser, through the launch, to detection and reaction by product on a security incident. The Remediation Time may depend on the real activity of the malware, which may increase calculated time.

remediation time diagram
Remediation time vertical
avlab-2026-march-excellent

EXCELLENT Certificate

Awarded to security solutions that demonstrate a high level of protection, achieving a minimum 99.6% malware blocking rate through effective Web-Layer and Runtime Defense, including automated remediation.

Recent Results in March2026

ico info
Starting in January 2026, we changed the names of malware blocking levels from Pre-Launch to Web-Layer Protection and from Post-Launch to Runtime Defense.

enterprise products

logo elastic
Elastic Defend
excellent
WEB-LAYER
96.67%
RUNTIME DEFENSE
3.33%

Blocked: 421/421
Total: 100%
RT: 3.05 seconds

Emsisoft logo
Emsisoft Enterprise Security + EDR
excellent
WEB-LAYER
80.29%
RUNTIME DEFENSE
19.71%

Blocked: 421/421
Total: 100%
RT: 4.67 seconds

microsoft defender logo
Microsoft Defender Business + EDR
excellent
WEB-LAYER
99.76%
RUNTIME DEFENSE
0.24%

Blocked: 421/421
Total: 100%
RT: 0.12 seconds

mks vir logo
mks_vir Endpoint Security + EDR
excellent
WEB-LAYER
100%
RUNTIME DEFENSE
0%

Blocked: 421/421
Total: 100%
RT: 0 second

threatdown logo
ThreatDown Endpoint Protection + EDR
excellent
WEB-LAYER
94.06%
POST-LAUNCH:
5.94%

Blocked: 421/421
Total: 100%
RT: 1.46 seconds

home products

Avast primary logo
Avast Free Antivirus
excellent
WEB-LAYER
99.76%
RUNTIME DEFENSE
0%
SYSTEM COMPROMISE
0.24%

Blocked: 420/421
Total: 99.76%
RT: 0 second
FAIL: 1

CatchPulse black
CatchPulse Pro
excellent
WEB-LAYER
74.35%
RUNTIME DEFENSE
25.65%

Blocked: 421/421
Total: 100%
RT: 26 seconds

Bitdefender logo
Bitdefender Total Security
excellent
WEB-LAYER
99.29%
RUNTIME DEFENSE
0.71%

Blocked: 421/421
Total: 100%
RT: 0 seconds

ESET logo
Eset Smart Security
excellent
WEB-LAYER
100%
RUNTIME DEFENSE
0%

Blocked: 421/421
Total: 100%
RT: 0 seconds

f secure logo
F-Secure Total
excellent
WEB-LAYER
81.95%
RUNTIME DEFENSE
18.05%

Blocked: 421/421
Total: 100%
RT: 7.6 seconds

k7 logo company
K7 Total Security
excellent
WEB-LAYER
93.59%
RUNTIME DEFENSE
6.41%

Blocked: 421/421
Total: 100%
RT: 0.415 second

kaspersky logo
Kaspersky Plus
excellent
WEB-LAYER
99.29%
RUNTIME DEFENSE
0.71%

Blocked: 421/421
Total: 100%
RT: 0.28 second

Malwerbytes logo 2025
Malwarebytes Premium
excellent
WEB-LAYER
97.86%
RUNTIME DEFENSE
2.14%

Blocked: 421/421
Total: 100%
RT: 0.508 seconds

NortonLifeLock logo
Norton Antivirus Plus
excellent
WEB-LAYER
98.81%
RUNTIME DEFENSE
1.19%

Blocked: 421/421
Total: 100%
RT: 0.969 second

Surfshark logo
Surfshark One
WEB-LAYER
70.78%
RUNTIME DEFENSE
28.74%
SYSTEM COMPROMISE
0.48%

Blocked: 419/421
Total: 99.52%
RT: 14.9 second
FAIL: 2

Trend Micro Logo
Trend Micro Internet Security
EXCELLENT
WEB-LAYER
98.81%
RUNTIME DEFENSE
0.95%
SYSTEM COMPROMISE
0.24%

Blocked: 420/421
Total: 99.76%
RT: 0.192 seconds
FAIL: 1

webroot antivirus
Webroot Antivirus
excellent
WEB-LAYER
96.91%
RUNTIME DEFENSE
3.09%

Blocked: 421/421
Total: 100%
RT: 0.308 second

Related Publication in Details

Dive into our latest publication, dedicated to security test against malware. Uncover analyses, methodology, and results that provide invaluable insights into the latest edition of the Advanced In-The-Wild Malware Test.

MVI logo pion
amtso STANDARD

The Advanced In-The-Wild Malware Test is conducted in accordance with AMTSO testing guidelines and complies with Microsoft Virus Initiative requirements.