I understand that malware sample testing is done using a representative set of common and deadly. Obviously the average user is not usually in contact with the most lethal unless they have bad luck or lack common sense. Nor does the average user manipulate the settings of the product, only looking for the feeling of being protected by installing an antimalware product. In the end, no antimalware product is enough to rid the user of himself.
Many times I have heard from a user "accept because it did not let me continue" when browsing. Not long ago a user asked me for help because he lost $ 25,000 in an attack using malware that steals bank credentials. An assistant performed web searches for "baby names". In the results came infection. Where is the common sense?