Do you also mean that samples posted here in MT are not that representative of the real threat scene?@Adz.: Each AV's have own struggles on which threats should be detected and everything rely on final backup option ---> HIPS/BB or whitelisting that deals of user interaction pop-up.
Information sometimes is limited and varies from region to region.
great explanation. thanks@Nikos751: What I'm trying to say is that AV's way to gather information are difficult, since the threat nowadays are smart enough to hide like in polymorphic algorithm/obfuscation.
Samples on MT and other organization must be representative of the real threat scene and AV's should perform more extensive effort.