Recent Results in November 2025

Latest DATA FROM the advanced in-the-wild malware test

ico top recent results

Summary of November 2025

11

tested
solutions

234

unique
SAMPLES

204

malware hosted over HTTP

14

malware hosted over HTTPS

121

average malicious changes [1]

PRE-LAUNCH level prevention

81 %

POST-LAUNCH level protection

5 %

average blocked malware [2]

100 %

Potential data breaches

0
4 s

Average Industry
Remediation Time

* based on data telemetry

0 s

The quickest average remediation time

Bitdefender logo
ESET logo
[1] The number of harmful changes made to Windows during dynamic analysis of the malware sample.
[2] Average blocking of malware by all tested solutions, regardless of level of prevention or protection.

TOP 3

HIJACKED SERVERS LOCATION

flag nederlanden
55
flag china
51
flag deutch
23

TOP 3

TLD COMPROMISED DOMAINS​

.com

24

.dev

1

.sbs

2

Examples illustrating the blocking of malware in the test

LOLBins in statistical terms

Legitimate and trusted software and built-in components in Windows are often used by cybercriminals to hide malicious activity. The so-called “Living off the Land Binaries” (LOLBin) are necessary for the proper functioning of the operating system. During a cyberattack, it can be difficult or impossible to block them, making them a very attractive method for malware developers. Below we present the most commonly used LOLBin in this edition of the test.

svchost.exe
5443
msedge.exe
4443
certutil.exe
3044
explorer.exe
1908
sh.exe
1878
taskhostw.exe
1143

Malware Comparison Table in November 2025

The following summary shows a comparison of tested solutions to protect workstations against malware. We encourage you to become familiar with a detailed description and read our testing methodology in order to understand the results.

PRE-LAUNCH: The classification concerns detecting malware samples before they are launched in the system.
POST-LAUNCH: The analysis level, i.e. a virus has been run and blocked by a tested product.
FAIL: The failure, i.e. a virus hasn’t been blocked and it has infected a system.
Sandbox Column: Number of indicators, i.e. malicious changes made to the system without the anti-virus installed.

Automatic Average Remediation Time (RT): The time expressed in seconds counted from the introduction of malware into the system by the browser, through the launch to the detecting and resolving a security incident.

avlab 2025 november

Certificates are granted to solutions that are characterized by a high level of security, with a rating of at least 99% of blocked threats in the Advanced In-The-Wild Malware Test.

amtso STANDARD

Our tests comply with the guidelines of the Anti-Malware Testing Standards Organization.
Details about the test are available at this website as well as in our methodology.

Recent Results in November 2025

enterprise products

Emsisoft logo
Emsisoft Enterprise Security + EDR
excellent
PRE-LAUNCH:
85.25%
POST-LAUNCH:
14.75%

Blocked: 244/244
Total: 100%
RT: 1.752 seconds

mks vir logo
mks_vir Endpoint Security + EDR
excellent
PRE-LAUNCH:
97.95%
POST-LAUNCH:
2.05%

Blocked: 244/244
Total: 100%
RT: 9.3 seconds

threatdown logo
ThreatDown Endpoint Protection + EDR
excellent
PRE-LAUNCH:
98.77%
POST-LAUNCH:
1.23%

Blocked: 244/244
Total: 100%
RT: 8.013 seconds

watchguard logo
WatchGuard Endpoint Security
excellent
PRE-LAUNCH:
94.26%
POST-LAUNCH:
4.92%
FAIL:
0.82%

Blocked: 222/224
Total: 99.18%
RT: 32.6 seconds
FAIL: 2

home products

Avast primary logo
Avast Free Antivirus
excellent
PRE-LAUNCH:
98.36%
POST-LAUNCH:
1.64%

Blocked: 244/244
Total: 100%
RT: 8.094 seconds

Bitdefender logo
Bitdefender Total Security
excellent
PRE-LAUNCH:
100%
POST-LAUNCH:
0%

Blocked: 244/244
Total: 100%
RT: 0 seconds

ESET logo
Eset Smart Security
excellent
PRE-LAUNCH:
95.71%
POST-LAUNCH:
4.29%

Blocked: 244/244
Total: 100%
RT: 0 seconds

f secure logo
F-Secure Total
excellent
PRE-LAUNCH:
13.52%
POST-LAUNCH:
86.48%

Blocked:244/244
Total: 100%
RT: 106 seconds

g data total security
G Data Internet Security
excellent
PRE-LAUNCH:
99.59%
POST-LAUNCH:
0.41%

Blocked: 244/244
Total: 100%
RT: 0.11 seconds

Malwerbytes logo 2025
Malwarebytes Premium
excellent
PRE-LAUNCH:
99.59%
POST-LAUNCH:
0.41%

Blocked: 244/244
Total: 100%
RT:   seconds

microsoft defender logo
Microsoft Defender
excellent
PRE-LAUNCH:
97.95%
POST-LAUNCH:
2.05%

Blocked: 244/244
Total: 100%
RT: 1.342 seconds

NortonLifeLock logo
Norton Antivirus Plus
excellent
PRE-LAUNCH:
98.36%
POST-LAUNCH:
1.64%

Blocked: 244/244
Total: 100%
RT: 1.657 seconds

Trend Micro Logo
Trend Micro Internet Security
excellent
PRE-LAUNCH:
98.36%
POST-LAUNCH:
1.64%

Blocked: 244/244
Total: 100%
RT: 0.192 seconds

webroot antivirus
Webroot Antivirus
excellent
PRE-LAUNCH:
85.25%
POST-LAUNCH:
14.75%

Blocked: 244/244
Total: 100%
RT: 33 seconds

Related Publication in Details

Dive into our latest publication, dedicated to security test against malware. Uncover analyses, methodology, and results that provide invaluable insights into the latest edition of the Advanced In-The-Wild Malware Test.