Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > alt.comp.os.windows-10 > #186666 > unrolled thread
| Started by | "Bill Bradshaw" <bradshaw@gci.net> |
|---|---|
| First post | 2025-08-11 08:37 -0800 |
| Last post | 2025-08-14 00:33 +0100 |
| Articles | 20 on this page of 30 — 16 participants |
Back to article view | Back to alt.comp.os.windows-10
Windows Defender Security After October "Bill Bradshaw" <bradshaw@gci.net> - 2025-08-11 08:37 -0800
Re: Windows Defender Security After October VanguardLH <V@nguard.LH> - 2025-08-11 12:12 -0500
Re: Windows Defender Security After October Marion <marion@facts.com> - 2025-08-11 19:17 +0000
Re: Windows Defender Security After October Paul in Houston TX <Paul@Houston.Texas> - 2025-08-11 18:47 -0500
Re: Windows Defender Security After October Joerg Walther <joerg.walther@magenta.de> - 2025-08-12 11:44 +0200
Re: Windows Defender Security After October Marion <marion@facts.com> - 2025-08-12 16:58 +0000
Re: Windows Defender Security After October Paul <nospam@needed.invalid> - 2025-08-12 18:37 -0400
Re: Windows Defender Security After October wasbit <wasbit@REMOVEhotmail.com> - 2025-08-13 09:15 +0100
Re: Windows Defender Security After October Marion <marion@facts.com> - 2025-08-13 21:21 +0000
Re: Windows Defender Security After October Hank Rogers <Hank@nospam.invalid> - 2025-08-13 19:14 -0500
Re: Windows Defender Security After October "Carlos E. R." <robin_listas@es.invalid> - 2025-08-12 21:22 +0200
Re: Windows Defender Security After October mick <nospam@junk.mail> - 2025-08-11 20:46 +0100
Re: Windows Defender Security After October VanguardLH <V@nguard.LH> - 2025-08-11 19:47 -0500
Re: Windows Defender Security After October wasbit <wasbit@REMOVEhotmail.com> - 2025-08-12 09:32 +0100
Re: Windows Defender Security After October Paul <nospam@needed.invalid> - 2025-08-11 17:24 -0400
Re: Windows Defender Security After October VanguardLH <V@nguard.LH> - 2025-08-11 19:59 -0500
Re: Windows Defender Security After October Paul <nospam@needed.invalid> - 2025-08-12 01:39 -0400
Re: Windows Defender Security After October wasbit <wasbit@REMOVEhotmail.com> - 2025-08-12 09:41 +0100
Re: Windows Defender Security After October VanguardLH <V@nguard.LH> - 2025-08-12 12:49 -0500
Re: Windows Defender Security After October Paul <nospam@needed.invalid> - 2025-08-12 01:51 -0400
Re: Windows Defender Security After October VanguardLH <V@nguard.LH> - 2025-08-12 13:08 -0500
Re: Windows Defender Security After October Windows 11 User <invalid@invalid.invalid> - 2025-08-12 00:01 +0000
Re: Windows Defender Security After October knuttle <keith_nuttle@yahoo.com> - 2025-08-11 21:06 -0400
Re: Windows Defender Security After October "J. P. Gilliver" <G6JPG@255soft.uk> - 2025-08-12 02:15 +0100
Re: Windows Defender Security After October Paul <nospam@needed.invalid> - 2025-08-12 02:13 -0400
Re: Windows Defender Security After October Chris <ithinkiam@gmail.com> - 2025-08-13 06:34 +0000
Re: Windows Defender Security After October Paul <nospam@needed.invalid> - 2025-08-13 02:48 -0400
Re: Windows Defender Security After October "J. P. Gilliver" <G6JPG@255soft.uk> - 2025-08-13 12:04 +0100
Re: Windows Defender Security After October dillinger <dillinger@invalid.not> - 2025-08-13 20:38 +0200
Re: Windows Defender Security After October Bloody Microshit <invalid@invalid.invalid> - 2025-08-14 00:33 +0100
Page 1 of 2 [1] 2 Next page →
| From | "Bill Bradshaw" <bradshaw@gci.net> |
|---|---|
| Date | 2025-08-11 08:37 -0800 |
| Subject | Windows Defender Security After October |
| Message-ID | <mfukj4F9colU1@mid.individual.net> |
After using Windows 11 on a new mini computer I am worried about upgrading some of my windows 10 computers to 11. If you go through some contortions MS is going to provide defender upgrades but it appears you also have to have Microsoft accounts rather than local accounts. Why not forget defender and go to a commercial antivirus? So I would have pay for a license but that I am not concerned about that. <Bill>
[toc] | [next] | [standalone]
| From | VanguardLH <V@nguard.LH> |
|---|---|
| Date | 2025-08-11 12:12 -0500 |
| Message-ID | <1qmtrjz7ekc3i$.dlg@v.nguard.lh> |
| In reply to | #186666 |
Bill Bradshaw <bradshaw@gci.net> wrote: > After using Windows 11 on a new mini computer I am worried about > upgrading some of my windows 10 computers to 11. If you go through > some contortions MS is going to provide defender upgrades but it > appears you also have to have Microsoft accounts rather than local > accounts. Why not forget defender and go to a commercial antivirus? > So I would have pay for a license but that I am not concerned about > that. You could wait to see if Defender updates dry up. If not, no need to change. If so, first try a free Av, like Bitdefender, or Avira*. * I had problems with Avira. Once I access removable storage (e.g., floppy drive), all removable devices got re-polled at 1-minute intervals. Avira could not reproduce, so it never got addressed. Few users got hit with the defect, but I was not alone. You could adding MalwareBytes Anti-Malware (MBAM), but not as the primary protection layer, and make sure to disable its on-access (realtime) scanner since only one should be active at a time. Use MBAM as a second opinion on-demand (manual) scanner. However, MBAM has far more false positives, even on tweaks you performed yourself to improve security (they don't know you made those tweaks). Don't waste time with Avast to endure their marketing campaigns, and AVG is the same as Avast since Avast acquired AVG for $1.3 billion way back in 2016. Avoid McAfee and Norton. If you're willing to pay for AV, you get extra features and improved pest detection. If you don't practice safe hex, eventually you will get infected, so of importance may be how well an AV santizes and heals your system. Disinfection is never perfect, so setup scheduled image backups permitting you to revert your system back to a known and uninfected state. Don't rely solely on an AV to repair and mend your system. Backups should be scheduled. If they are manual initiated, they don't happen at short enough intervals, or may not happen at all. Manual backups don't get done. How granular are the backups determines how much you lose in a restore. Use a backup program that lets you scheduled full, differential, and incremental backups, so you can pick the granularity for restore, like monthly full, weekly differential, and daily incremental. If you do just fulls, you'll run out of storage space which means you have to do less of them to fit into available storage. You could visit av-comparatives.org to see how each fares now for best coverage, lowest false positives, and other attributes interest you. However, understand they don't test freeware unless that is the only way to get it.
[toc] | [prev] | [next] | [standalone]
| From | Marion <marion@facts.com> |
|---|---|
| Date | 2025-08-11 19:17 +0000 |
| Message-ID | <107dfjd$11f8$1@nnrp.usenet.blueworldhosting.com> |
| In reply to | #186667 |
On Mon, 11 Aug 2025 12:12:17 -0500, VanguardLH wrote : > Don't waste time with Avast to endure their marketing campaigns, and AVG > is the same as Avast since Avast acquired AVG for $1.3 billion way back > in 2016. Avoid McAfee and Norton. When is the last time any of us, who've been here forever, got a virus?
[toc] | [prev] | [next] | [standalone]
| From | Paul in Houston TX <Paul@Houston.Texas> |
|---|---|
| Date | 2025-08-11 18:47 -0500 |
| Message-ID | <107dven$2ur0t$1@dont-email.me> |
| In reply to | #186677 |
Marion wrote: > On Mon, 11 Aug 2025 12:12:17 -0500, VanguardLH wrote : > > >> Don't waste time with Avast to endure their marketing campaigns, and AVG >> is the same as Avast since Avast acquired AVG for $1.3 billion way back >> in 2016. Avoid McAfee and Norton. > > When is the last time any of us, who've been here forever, got a virus? Roughly 1995 for me. I have never used any active antivirus on my machines and don't plan to. All of my comps have accessed the web via multiple bridges, natting, and routers, each with a hardware or software firewall. Running online scans or with updated Linux boot disk scanners once every few months have never turned up anything that I was not already aware of (virus simulators, etc.). However, most of my work and friend acquaintances are not comp literate and they like to click on the little green buttons that say "Click here".
[toc] | [prev] | [next] | [standalone]
| From | Joerg Walther <joerg.walther@magenta.de> |
|---|---|
| Date | 2025-08-12 11:44 +0200 |
| Message-ID | <153m9k1etktjphk3k86aksjelqgm3faj5b@joergwalther.my-fqdn.de> |
| In reply to | #186684 |
Paul in Houston TX wrote: >> When is the last time any of us, who've been here forever, got a virus? > >Roughly 1995 for me. >I have never used any active antivirus on my machines and don't plan to. > All of my comps have accessed the web via multiple bridges, natting, >and routers, each with a hardware or software firewall. >Running online scans or with updated Linux boot disk scanners once every >few months have never turned up anything that I was not already aware of >(virus simulators, etc.). However, most of my work and friend >acquaintances are not comp literate and they like to click on the little >green buttons that say "Click here". Apparently we both have been using the same virus scanner for ages then. It's called BRAIN 1.0. -jw- -- And now for something completely different...
[toc] | [prev] | [next] | [standalone]
| From | Marion <marion@facts.com> |
|---|---|
| Date | 2025-08-12 16:58 +0000 |
| Message-ID | <107frrr$28ue$1@nnrp.usenet.blueworldhosting.com> |
| In reply to | #186706 |
On Tue, 12 Aug 2025 11:44:03 +0200, Joerg Walther wrote : > most of my work and friend >>acquaintances are not comp literate and they like to click on the little >>green buttons that say "Click here". > > Apparently we both have been using the same virus scanner for ages then. > It's called BRAIN 1.0. I'm gonna agree most of us haven't gotten a virus in years for, oh, maybe two reasons, but the main reason is Brain 1.0 doesn't "click here now!". I'm not sure if the other reason might be that Windows Defender is on by default, it's updated by default, and maybe it's doing it's job???? Is it?
[toc] | [prev] | [next] | [standalone]
| From | Paul <nospam@needed.invalid> |
|---|---|
| Date | 2025-08-12 18:37 -0400 |
| Message-ID | <107gfnq$3j0jr$1@dont-email.me> |
| In reply to | #186713 |
On Tue, 8/12/2025 12:58 PM, Marion wrote:
> On Tue, 12 Aug 2025 11:44:03 +0200, Joerg Walther wrote :
>
>
>> most of my work and friend
>>> acquaintances are not comp literate and they like to click on the little
>>> green buttons that say "Click here".
>>
>> Apparently we both have been using the same virus scanner for ages then.
>> It's called BRAIN 1.0.
>
> I'm gonna agree most of us haven't gotten a virus in years for, oh, maybe
> two reasons, but the main reason is Brain 1.0 doesn't "click here now!".
>
> I'm not sure if the other reason might be that Windows Defender is on by
> default, it's updated by default, and maybe it's doing it's job????
>
> Is it?
>
It would find a way of reporting to you, if it was actually under attack.
When it complains about ProduKey being "hackerware", you are informed. You can
try testing with that, by downloading it, and having it instantly disappear
as it is scooped out of your grasp. I keep my copy in an encrypted 7Z file.
Like I worked for the bomb squad or something :-)
While a number of AVs react to EICAR, not all do. Some products have
a public policy, to not react to it. I've used that before,
to check that some of the more "lethargic" products, are actually loaded
and running.
Load into Virustotal.com (owned by Google), and search with it. EICAR SHA256
275A021BBFB6489E54D471899F7DB9D1663FC695EC2FE2A2C4538AABF651FD0F
The fleet reacts pretty good, to a test.
https://www.virustotal.com/gui/file/275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f
Paul
[toc] | [prev] | [next] | [standalone]
| From | wasbit <wasbit@REMOVEhotmail.com> |
|---|---|
| Date | 2025-08-13 09:15 +0100 |
| Message-ID | <107hhj9$3piu9$1@dont-email.me> |
| In reply to | #186713 |
On 12/08/2025 17:58, Marion wrote: > On Tue, 12 Aug 2025 11:44:03 +0200, Joerg Walther wrote : > > >> most of my work and friend >>> acquaintances are not comp literate and they like to click on the little >>> green buttons that say "Click here". >> >> Apparently we both have been using the same virus scanner for ages then. >> It's called BRAIN 1.0. > > I'm gonna agree most of us haven't gotten a virus in years for, oh, maybe > two reasons, but the main reason is Brain 1.0 doesn't "click here now!". > > I'm not sure if the other reason might be that Windows Defender is on by > default, it's updated by default, and maybe it's doing it's job???? > > Is it? > Or maybe the router is doing it's job. -- Regards wasbit
[toc] | [prev] | [next] | [standalone]
| From | Marion <marion@facts.com> |
|---|---|
| Date | 2025-08-13 21:21 +0000 |
| Message-ID | <107ivl9$kno$1@nnrp.usenet.blueworldhosting.com> |
| In reply to | #186737 |
On Wed, 13 Aug 2025 09:15:38 +0100, wasbit wrote : > On 12/08/2025 17:58, Marion wrote: >> On Tue, 12 Aug 2025 11:44:03 +0200, Joerg Walther wrote : >> >>> most of my work and friend >>>> acquaintances are not comp literate and they like to click on the little >>>> green buttons that say "Click here". >>> >>> Apparently we both have been using the same virus scanner for ages then. >>> It's called BRAIN 1.0. >> >> I'm gonna agree most of us haven't gotten a virus in years for, oh, maybe >> two reasons, but the main reason is Brain 1.0 doesn't "click here now!". >> >> I'm not sure if the other reason might be that Windows Defender is on by >> default, it's updated by default, and maybe it's doing it's job???? >> >> Is it? >> > > Or maybe the router is doing it's job. Hi wasbit, You know your stuff, particularly free software, which I respect. I really don't know routers. I just set them up once every few years as I buy the penultimate version (as I wait a few years for the prices to drop). My current router is an older Netgear Nighthawk RAX200, where I never added anything in particular for the router to do firewalling or AV tasks. Other than block direct attacks by default, what does the router block? All I can tell that it blocks might be a. NAT (keeping my network away from the Internet) b. Direct intrusion attempt blocking by stateful packet inspection c. Logging (but I almost never check the logs but I see attacks when I do) d. Anything else? Without subscriptions to protection like Netgear Armor or other addons, as far as I know, a router is not scanning for malware, phishing attacks, or malicious domains as the router, by default anyway, is just doing the front gate work of keeping random inbound connections out. Am I setting up my router wrongly? Can I do anything else, for free, to prevent attacks?
[toc] | [prev] | [next] | [standalone]
| From | Hank Rogers <Hank@nospam.invalid> |
|---|---|
| Date | 2025-08-13 19:14 -0500 |
| Message-ID | <107j9pp$6ho8$2@dont-email.me> |
| In reply to | #186748 |
Marion wrote on 8/13/2025 4:21 PM: > On Wed, 13 Aug 2025 09:15:38 +0100, wasbit wrote : > > >> On 12/08/2025 17:58, Marion wrote: >>> On Tue, 12 Aug 2025 11:44:03 +0200, Joerg Walther wrote : >>> >>>> most of my work and friend >>>>> acquaintances are not comp literate and they like to click on the little >>>>> green buttons that say "Click here". >>>> >>>> Apparently we both have been using the same virus scanner for ages then. >>>> It's called BRAIN 1.0. >>> >>> I'm gonna agree most of us haven't gotten a virus in years for, oh, maybe >>> two reasons, but the main reason is Brain 1.0 doesn't "click here now!". >>> >>> I'm not sure if the other reason might be that Windows Defender is on by >>> default, it's updated by default, and maybe it's doing it's job???? >>> >>> Is it? >>> >> >> Or maybe the router is doing it's job. > > Hi wasbit, > > You know your stuff, particularly free software, which I respect. > > I really don't know routers. I just set them up once every few years as I > buy the penultimate version (as I wait a few years for the prices to drop). > > My current router is an older Netgear Nighthawk RAX200, where I never added > anything in particular for the router to do firewalling or AV tasks. > > Other than block direct attacks by default, what does the router block? > All I can tell that it blocks might be > a. NAT (keeping my network away from the Internet) > b. Direct intrusion attempt blocking by stateful packet inspection > c. Logging (but I almost never check the logs but I see attacks when I do) > d. Anything else? > > Without subscriptions to protection like Netgear Armor or other addons, as > far as I know, a router is not scanning for malware, phishing attacks, or > malicious domains as the router, by default anyway, is just doing the front > gate work of keeping random inbound connections out. > > Am I setting up my router wrongly? > Can I do anything else, for free, to prevent attacks? > Damn, I thought you knew everything! What happened?
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E. R." <robin_listas@es.invalid> |
|---|---|
| Date | 2025-08-12 21:22 +0200 |
| Message-ID | <mg1iirFo5fbU1@mid.individual.net> |
| In reply to | #186677 |
On 2025-08-11 21:17, Marion wrote:
> On Mon, 11 Aug 2025 12:12:17 -0500, VanguardLH wrote :
>
>
>> Don't waste time with Avast to endure their marketing campaigns, and AVG
>> is the same as Avast since Avast acquired AVG for $1.3 billion way back
>> in 2016. Avoid McAfee and Norton.
>
> When is the last time any of us, who've been here forever, got a virus?
1988.
One of the reasons is I do use an antivirus when using Windows (not
necessarily "scan on load").
--
Cheers,
Carlos E.R.
[toc] | [prev] | [next] | [standalone]
| From | mick <nospam@junk.mail> |
|---|---|
| Date | 2025-08-11 20:46 +0100 |
| Message-ID | <107dhb4$2qvlk$1@dont-email.me> |
| In reply to | #186667 |
VanguardLH used his keyboard to write : > Bill Bradshaw <bradshaw@gci.net> wrote: > >> After using Windows 11 on a new mini computer I am worried about >> upgrading some of my windows 10 computers to 11. If you go through >> some contortions MS is going to provide defender upgrades but it >> appears you also have to have Microsoft accounts rather than local >> accounts. Why not forget defender and go to a commercial antivirus? >> So I would have pay for a license but that I am not concerned about >> that. > > You could wait to see if Defender updates dry up. If not, no need to > change. If so, first try a free Av, like Bitdefender, or Avira*. > > * I had problems with Avira. Once I access removable storage (e.g., > floppy drive), all removable devices got re-polled at 1-minute > intervals. Avira could not reproduce, so it never got addressed. Few > users got hit with the defect, but I was not alone. > > You could adding MalwareBytes Anti-Malware (MBAM), but not as the > primary protection layer, and make sure to disable its on-access > (realtime) scanner since only one should be active at a time. Use MBAM > as a second opinion on-demand (manual) scanner. However, MBAM has far > more false positives, even on tweaks you performed yourself to improve > security (they don't know you made those tweaks). > > Don't waste time with Avast to endure their marketing campaigns, and AVG > is the same as Avast since Avast acquired AVG for $1.3 billion way back > in 2016. Avoid McAfee and Norton. What are your reasons for avoiding McAfee and Norton? A friend of mine uses McAfee and swears by it. I have used Norton since before the turn of the century and it has never caused me a problem (contrary to the claims that is slows down your pc). -- mick
[toc] | [prev] | [next] | [standalone]
| From | VanguardLH <V@nguard.LH> |
|---|---|
| Date | 2025-08-11 19:47 -0500 |
| Message-ID | <1vpkdasmgw7kk.dlg@v.nguard.lh> |
| In reply to | #186678 |
mick <nospam@junk.mail> wrote: > What are your reasons for avoiding McAfee and Norton? When Norton's transparent proxy becomes unresponsive, web traffic halts. Users don't know it's Norton causing the outage. They reboot, and the problem goes away. I reported the issue, and how to reproduce it to Symantec. They were mute. I finally figured out a way to stop the service, kill which processes, and in which order, and in which order to restart or reload them to get their transparent proxy functional again. McAfee: Way too many false positives. No free version, either. And trials are not freeware. Both are extremely difficult to eradicate from your system. Their uninstall is very dirty. In fact, the Norton devs said the only reason anyone uninstall their software was as a troubleshooting step, and absolutely always would reinstall right after uninstall, so leaving a bunch of crap in the registry facilitated the re-setup. Artifacts of their dirty uninstall were shell extensions that were no longer valid, but would screw up explorer.exe when trying to load them. The vast majority of users don't have the expertise to overcome dirty uninstalls, know what might be the source of a problem, or diagnose a problem. They're lost when a problem arises, and don't even know it's due to the AV software. They're good as long as they always function, and you never uninstall them. Both are good for pest detection, but more trouble than worth the effort when compared to other free solutions. While the OP hinted he may pay for a 3rd-party anti-malware product, why pay for what you can get for free? He indicated nothing that infers he needs more than the default feature set in freeware AV. That you and your friend have good luck with Norton AV and McAfee AV does not obviate all the complaints about them. If you want more reasons, do the research yourself. You can visit av-comparatives.org to compare various anti-malware products, like looking at: https://www.av-comparatives.org/consumer/comparison/ Hover over each data point to get quick stats on each AV, like: Bitdefender - Blocked: 99.8% - User dependent (user still had option to run malware): 0% - Compromised: 0.2% - False positives: 3 Avira - Blocked: 99.3% - User dependent: 0% - Compromised: 0.7% - False positives: 5 Norton - Blocked: 99.5% - User dependent: 0% - Compromised: 0.5% - False positives: 9 McAfee - Blocked: 99.3% - User dependent: 0% - Compromised: 0.7% - False positives: 9 High pest detection is nice, but false positives will waste your time trying to determine they were false positives, or having to research just what is the cause of the alert. If you have a car with TPMS (Tire Pressure Monitoring System), would you want it telling you there was a flat when there wasn't? Or your doorbell ringing when no one pushed the doorbell button? With Norton and McAfee, you can report false positives. You first have to determine it was a false positive, and how many users are going to report it? Most users can't even do the first step. You want an AV with high pest detection AND low[est] false positives. Security for the end user should be transparent, not a job.
[toc] | [prev] | [next] | [standalone]
| From | wasbit <wasbit@REMOVEhotmail.com> |
|---|---|
| Date | 2025-08-12 09:32 +0100 |
| Message-ID | <107eu7d$350hn$1@dont-email.me> |
| In reply to | #186678 |
On 11/08/2025 20:46, mick wrote: > VanguardLH used his keyboard to write : >> Bill Bradshaw <bradshaw@gci.net> wrote: >> >>> After using Windows 11 on a new mini computer I am worried about >>> upgrading some of my windows 10 computers to 11. If you go through >>> some contortions MS is going to provide defender upgrades but it >>> appears you also have to have Microsoft accounts rather than local >>> accounts. Why not forget defender and go to a commercial antivirus? >>> So I would have pay for a license but that I am not concerned about >>> that. >> >> You could wait to see if Defender updates dry up. If not, no need to >> change. If so, first try a free Av, like Bitdefender, or Avira*. >> >> * I had problems with Avira. Once I access removable storage (e.g., >> floppy drive), all removable devices got re-polled at 1-minute >> intervals. Avira could not reproduce, so it never got addressed. Few >> users got hit with the defect, but I was not alone. >> >> You could adding MalwareBytes Anti-Malware (MBAM), but not as the >> primary protection layer, and make sure to disable its on-access >> (realtime) scanner since only one should be active at a time. Use MBAM >> as a second opinion on-demand (manual) scanner. However, MBAM has far >> more false positives, even on tweaks you performed yourself to improve >> security (they don't know you made those tweaks). >> >> Don't waste time with Avast to endure their marketing campaigns, and AVG >> is the same as Avast since Avast acquired AVG for $1.3 billion way back >> in 2016. Avoid McAfee and Norton. > > What are your reasons for avoiding McAfee and Norton? > A friend of mine uses McAfee and swears by it. I have used Norton since > before the turn of the century and it has never caused me a problem > (contrary to the claims that is slows down your pc). > Bloat. -- Regards wasbit
[toc] | [prev] | [next] | [standalone]
| From | Paul <nospam@needed.invalid> |
|---|---|
| Date | 2025-08-11 17:24 -0400 |
| Message-ID | <107dn2c$2sfp2$1@dont-email.me> |
| In reply to | #186666 |
On Mon, 8/11/2025 12:37 PM, Bill Bradshaw wrote: > After using Windows 11 on a new mini computer I am worried about upgrading > some of my windows 10 computers to 11. If you go through some contortions MS > is going to provide defender upgrades but it appears you also have to have > Microsoft accounts rather than local accounts. Why not forget defender and > go to a commercial antivirus? So I would have pay for a license but that I > am not concerned about that. > > <Bill> > > Observe the file pattern here. https://www.microsoft.com/en-us/wdsi/defenderupdates There is more to the story, the story has details 1) Defender signature definitions (the above files). Free, but signature definitions are not a very strong method of protection. 2) Defender Engine Update (not available necessarily that way, might be a separate package). 3) Patch Tuesday security updates for known CVE ($30, MSA account, only lasts one year, limited duration) Or as an alternative, 0Patch subscription (select CVE patched by a third party company). 4) The $30 likely buys you other sorts of files or packages, but not new features. Maybe you'd still get certificate updates or something. IDK the details. Perhaps a certificate helps the SChannel to work (Firefox does not use the SChannel and has its own certificate store). There might be the odd third-party Windows utility, that relies on the SChannel for TLS/SSL. Paul
[toc] | [prev] | [next] | [standalone]
| From | VanguardLH <V@nguard.LH> |
|---|---|
| Date | 2025-08-11 19:59 -0500 |
| Message-ID | <b96qcqs79n9p$.dlg@v.nguard.lh> |
| In reply to | #186680 |
Paul <nospam@needed.invalid> wrote: > Observe the file pattern here. > > https://www.microsoft.com/en-us/wdsi/defenderupdates What pattern? A history of update dates is not listed, so no way to determine there how often or at what intervals Defender gets updated. > There is more to the story, the story has details > > 1) Defender signature definitions (the above files). Free, but signature definitions > are not a very strong method of protection. Signature databases are updated at very short intervals, sometimes daily. Heuristics, however, often don't change until the next major version update. With Defender, its engine is updated with major version releases of Windows, not before. While signatures can cause false positives (the hash to match is not against all bytes in a file), aging heuristics can generate more false positives.
[toc] | [prev] | [next] | [standalone]
| From | Paul <nospam@needed.invalid> |
|---|---|
| Date | 2025-08-12 01:39 -0400 |
| Message-ID | <107ek37$32nl0$2@dont-email.me> |
| In reply to | #186689 |
On Mon, 8/11/2025 8:59 PM, VanguardLH wrote: > Paul <nospam@needed.invalid> wrote: > >> Observe the file pattern here. >> >> https://www.microsoft.com/en-us/wdsi/defenderupdates > > What pattern? A history of update dates is not listed, so no way to > determine there how often or at what intervals Defender gets updated. Windows 7 still receives updates. Paul
[toc] | [prev] | [next] | [standalone]
| From | wasbit <wasbit@REMOVEhotmail.com> |
|---|---|
| Date | 2025-08-12 09:41 +0100 |
| Message-ID | <107eunm$35a9b$1@dont-email.me> |
| In reply to | #186699 |
On 12/08/2025 06:39, Paul wrote: > On Mon, 8/11/2025 8:59 PM, VanguardLH wrote: >> Paul <nospam@needed.invalid> wrote: >> >>> Observe the file pattern here. >>> >>> https://www.microsoft.com/en-us/wdsi/defenderupdates >> >> What pattern? A history of update dates is not listed, so no way to >> determine there how often or at what intervals Defender gets updated. > > Windows 7 still receives updates. > As does Windows 8.1, although my routine is to update the definitions manually every day after turning on the PC, then either scanning or walking away for 10 minutes allowing Defender to automatically start a scan when it detects no PC activity. -- Regards wasbit
[toc] | [prev] | [next] | [standalone]
| From | VanguardLH <V@nguard.LH> |
|---|---|
| Date | 2025-08-12 12:49 -0500 |
| Message-ID | <pio5ch67cx44.dlg@v.nguard.lh> |
| In reply to | #186699 |
Paul <nospam@needed.invalid> wrote: > VanguardLH wrote: > >> Paul <nospam@needed.invalid> wrote: >> >>> Observe the file pattern here. >>> >>> https://www.microsoft.com/en-us/wdsi/defenderupdates >> >> What pattern? A history of update dates is not listed, so no way to >> determine there how often or at what intervals Defender gets updated. > > Windows 7 still receives updates. Wouldn't that just be signature updates? And those are not for virus, or other malware, just spyware (see last paragraph). I thought Defender got engine updates with new versions (builds) of Windows, but the following Microsoft article lists when there were engine & platform updates: https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-updates July-2025 (Platform: 4.18.25070.5 | Engine: 1.1.25070.4) August 5, 2025 (Engine) / August 6, 2025 (Platform) June-2025 (Platform: 4.18.25060.7 | Engine: 1.1.25060.6) July 22, 2025 (Engine) / July 22, 2025 (Platform) May-2025 (Platform: 4.18.25050.5 | Engine: 1.1.25050.6) June 13, 2025 (Engine) / June 13, 2025 (Platform) April-2025 (Platform: 4.18.25040.2 | Engine: 1.1.25040.1) May 14, 2025 (Engine) / May 22, 2025 (Platform) That is as far back as that list shows. Maybe there is another list showing older history. So, about once per month Defender gets engine and platform updates. That article does not list versions of Windows, just "Windows" for the supported platform. https://www.microsoft.com/en-us/wdsi/definitions/antimalware-definition-release-notes By picking different versions, it looks like sig updates occur on the same day (zero days), or every 1 to 2 days, not after a month. Algorithms (heuristics) are not signatures, so presumably those are in the engine/platform updates at monthly intervals. Before Windows 8, Defender was just a spyware detector. In Vista and 7, users were pointed at MS Security Essentials (MSE) to get AV protection. MSE was discontinued back with Windows 7, and its updates supposedly ceased in Feb 2025. https://en.wikipedia.org/wiki/Microsoft_Security_Essentials#Discontinuation Although support for Windows 7[36] ended on 14 January 2020 Microsoft will continue to update virus definitions for existing users until 2023." Since you say you are using the old spyware-only Defender back in Windows 7, you are no longer an existing MSE user; however, updates supposedly ceased for MSE a while ago. Not until Windows 8 did Microsoft roll their Endpoint client into Windows to make Defender a true AV product, not just for spyware. https://en.wikipedia.org/wiki/Microsoft_Defender_Antivirus#Conversion_to_full_antivirus If you are using Defender under Windows 7, it was only a spyware detector, and you should really switch to a 3rd-party AV. You probably cannot get a new install of MSE on Windows, anymore.
[toc] | [prev] | [next] | [standalone]
| From | Paul <nospam@needed.invalid> |
|---|---|
| Date | 2025-08-12 01:51 -0400 |
| Message-ID | <107ekp4$32t1b$1@dont-email.me> |
| In reply to | #186689 |
On Mon, 8/11/2025 8:59 PM, VanguardLH wrote: > Paul <nospam@needed.invalid> wrote: > >> Observe the file pattern here. >> >> https://www.microsoft.com/en-us/wdsi/defenderupdates > > What pattern? A history of update dates is not listed, so no way to > determine there how often or at what intervals Defender gets updated. > >> There is more to the story, the story has details >> >> 1) Defender signature definitions (the above files). Free, but signature definitions >> are not a very strong method of protection. > > Signature databases are updated at very short intervals, sometimes > daily. Heuristics, however, often don't change until the next major > version update. With Defender, its engine is updated with major version > releases of Windows, not before. While signatures can cause false > positives (the hash to match is not against all bytes in a file), aging > heuristics can generate more false positives. > Not all AVs have heuristics (that is how bad some of them are). Some of them, you can kinda tell by how clueless the product is, that they are just signature analysis programs. Malwarebytes started by designing some heuristic protections with their product, and no signatures. Signature analysis was added later. Not many other products have worked in that order. It's just so much easier to clone the ClamAV database and use that. I think AV-comparatives may have had a test for heuristic detection at some point. Maybe ESET was known at the time, to have some heuristic means. Microsoft has on a couple of occasions, made reference to some magic they have, but there is never any real-world event that correlates with their description. For example, Microsoft claims they can turn off your computer "in 10 microseconds" in the event Windows Defender detects something it cannot stop by conventional means. As a user, if you were not informed of that possibility, you might never guess what such a scenario meant. You would not know how to interpret that sort of dirty shutdown. It implies the shutdown is fast enough, there would be nothing in the Event Viewer. They also did not give any examples of triggers that would cause that to happen. To the user, you would not be able to tell that, from a THERMTRIP. Or a bad PSU. Paul
[toc] | [prev] | [next] | [standalone]
Page 1 of 2 [1] 2 Next page →
Back to top | Article view | alt.comp.os.windows-10
csiph-web