Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > alt.comp.os.windows-10 > #186666 > unrolled thread

Windows Defender Security After October

Started by"Bill Bradshaw" <bradshaw@gci.net>
First post2025-08-11 08:37 -0800
Last post2025-08-14 00:33 +0100
Articles 20 on this page of 30 — 16 participants

Back to article view | Back to alt.comp.os.windows-10


Contents

  Windows Defender Security After October "Bill Bradshaw" <bradshaw@gci.net> - 2025-08-11 08:37 -0800
    Re: Windows Defender Security After October VanguardLH <V@nguard.LH> - 2025-08-11 12:12 -0500
      Re: Windows Defender Security After October Marion <marion@facts.com> - 2025-08-11 19:17 +0000
        Re: Windows Defender Security After October Paul in Houston TX <Paul@Houston.Texas> - 2025-08-11 18:47 -0500
          Re: Windows Defender Security After October Joerg Walther <joerg.walther@magenta.de> - 2025-08-12 11:44 +0200
            Re: Windows Defender Security After October Marion <marion@facts.com> - 2025-08-12 16:58 +0000
              Re: Windows Defender Security After October Paul <nospam@needed.invalid> - 2025-08-12 18:37 -0400
              Re: Windows Defender Security After October wasbit <wasbit@REMOVEhotmail.com> - 2025-08-13 09:15 +0100
                Re: Windows Defender Security After October Marion <marion@facts.com> - 2025-08-13 21:21 +0000
                  Re: Windows Defender Security After October Hank Rogers <Hank@nospam.invalid> - 2025-08-13 19:14 -0500
        Re: Windows Defender Security After October "Carlos E. R." <robin_listas@es.invalid> - 2025-08-12 21:22 +0200
      Re: Windows Defender Security After October mick <nospam@junk.mail> - 2025-08-11 20:46 +0100
        Re: Windows Defender Security After October VanguardLH <V@nguard.LH> - 2025-08-11 19:47 -0500
        Re: Windows Defender Security After October wasbit <wasbit@REMOVEhotmail.com> - 2025-08-12 09:32 +0100
    Re: Windows Defender Security After October Paul <nospam@needed.invalid> - 2025-08-11 17:24 -0400
      Re: Windows Defender Security After October VanguardLH <V@nguard.LH> - 2025-08-11 19:59 -0500
        Re: Windows Defender Security After October Paul <nospam@needed.invalid> - 2025-08-12 01:39 -0400
          Re: Windows Defender Security After October wasbit <wasbit@REMOVEhotmail.com> - 2025-08-12 09:41 +0100
          Re: Windows Defender Security After October VanguardLH <V@nguard.LH> - 2025-08-12 12:49 -0500
        Re: Windows Defender Security After October Paul <nospam@needed.invalid> - 2025-08-12 01:51 -0400
          Re: Windows Defender Security After October VanguardLH <V@nguard.LH> - 2025-08-12 13:08 -0500
    Re: Windows Defender Security After October Windows 11 User <invalid@invalid.invalid> - 2025-08-12 00:01 +0000
    Re: Windows Defender Security After October knuttle <keith_nuttle@yahoo.com> - 2025-08-11 21:06 -0400
      Re: Windows Defender Security After October "J. P. Gilliver" <G6JPG@255soft.uk> - 2025-08-12 02:15 +0100
      Re: Windows Defender Security After October Paul <nospam@needed.invalid> - 2025-08-12 02:13 -0400
    Re: Windows Defender Security After October Chris <ithinkiam@gmail.com> - 2025-08-13 06:34 +0000
      Re: Windows Defender Security After October Paul <nospam@needed.invalid> - 2025-08-13 02:48 -0400
        Re: Windows Defender Security After October "J. P. Gilliver" <G6JPG@255soft.uk> - 2025-08-13 12:04 +0100
    Re: Windows Defender Security After October dillinger <dillinger@invalid.not> - 2025-08-13 20:38 +0200
      Re: Windows Defender Security After October Bloody Microshit <invalid@invalid.invalid> - 2025-08-14 00:33 +0100

Page 1 of 2  [1] 2  Next page →


#186666 — Windows Defender Security After October

From"Bill Bradshaw" <bradshaw@gci.net>
Date2025-08-11 08:37 -0800
SubjectWindows Defender Security After October
Message-ID<mfukj4F9colU1@mid.individual.net>
After using Windows 11 on a new mini computer I am worried about upgrading 
some of my windows 10 computers to 11. If you go through some contortions MS 
is going to provide defender upgrades but it appears you also have to have 
Microsoft accounts rather than local accounts.  Why not forget defender and 
go to a commercial antivirus?  So I would have pay for a license but that I 
am not concerned about that.

<Bill> 

[toc] | [next] | [standalone]


#186667

FromVanguardLH <V@nguard.LH>
Date2025-08-11 12:12 -0500
Message-ID<1qmtrjz7ekc3i$.dlg@v.nguard.lh>
In reply to#186666
Bill Bradshaw <bradshaw@gci.net> wrote:

> After using Windows 11 on a new mini computer I am worried about
> upgrading some of my windows 10 computers to 11. If you go through
> some contortions MS is going to provide defender upgrades but it
> appears you also have to have Microsoft accounts rather than local
> accounts.  Why not forget defender and go to a commercial antivirus? 
> So I would have pay for a license but that I am not concerned about
> that.

You could wait to see if Defender updates dry up.  If not, no need to
change.  If so, first try a free Av, like Bitdefender, or Avira*.

* I had problems with Avira.  Once I access removable storage (e.g., 
  floppy drive), all removable devices got re-polled at 1-minute 
  intervals.  Avira could not reproduce, so it never got addressed.  Few 
  users got hit with the defect, but I was not alone.

You could adding MalwareBytes Anti-Malware (MBAM), but not as the
primary protection layer, and make sure to disable its on-access
(realtime) scanner since only one should be active at a time.  Use MBAM
as a second opinion on-demand (manual) scanner.  However, MBAM has far
more false positives, even on tweaks you performed yourself to improve
security (they don't know you made those tweaks).

Don't waste time with Avast to endure their marketing campaigns, and AVG
is the same as Avast since Avast acquired AVG for $1.3 billion way back
in 2016.  Avoid McAfee and Norton.  If you're willing to pay for AV, you
get extra features and improved pest detection.  If you don't practice
safe hex, eventually you will get infected, so of importance may be how
well an AV santizes and heals your system.  Disinfection is never
perfect, so setup scheduled image backups permitting you to revert your
system back to a known and uninfected state.  Don't rely solely on an AV
to repair and mend your system.  Backups should be scheduled.  If they
are manual initiated, they don't happen at short enough intervals, or
may not happen at all.  Manual backups don't get done.  How granular are
the backups determines how much you lose in a restore.  Use a backup
program that lets you scheduled full, differential, and incremental
backups, so you can pick the granularity for restore, like monthly full,
weekly differential, and daily incremental.  If you do just fulls,
you'll run out of storage space which means you have to do less of them
to fit into available storage.

You could visit av-comparatives.org to see how each fares now for best
coverage, lowest false positives, and other attributes interest you.
However, understand they don't test freeware unless that is the only way
to get it.

[toc] | [prev] | [next] | [standalone]


#186677

FromMarion <marion@facts.com>
Date2025-08-11 19:17 +0000
Message-ID<107dfjd$11f8$1@nnrp.usenet.blueworldhosting.com>
In reply to#186667
On Mon, 11 Aug 2025 12:12:17 -0500, VanguardLH wrote :


> Don't waste time with Avast to endure their marketing campaigns, and AVG
> is the same as Avast since Avast acquired AVG for $1.3 billion way back
> in 2016.  Avoid McAfee and Norton.

When is the last time any of us, who've been here forever, got a virus?

[toc] | [prev] | [next] | [standalone]


#186684

FromPaul in Houston TX <Paul@Houston.Texas>
Date2025-08-11 18:47 -0500
Message-ID<107dven$2ur0t$1@dont-email.me>
In reply to#186677
Marion wrote:
> On Mon, 11 Aug 2025 12:12:17 -0500, VanguardLH wrote :
> 
> 
>> Don't waste time with Avast to endure their marketing campaigns, and AVG
>> is the same as Avast since Avast acquired AVG for $1.3 billion way back
>> in 2016.  Avoid McAfee and Norton.
> 
> When is the last time any of us, who've been here forever, got a virus?

Roughly 1995 for me.
I have never used any active antivirus on my machines and don't plan to. 
  All of my comps have accessed the web via multiple bridges, natting, 
and routers, each with a hardware or software firewall.
Running online scans or with updated Linux boot disk scanners once every 
few months have never turned up anything that I was not already aware of 
(virus simulators, etc.).  However, most of my work and friend 
acquaintances are not comp literate and they like to click on the little 
green buttons that say "Click here".

[toc] | [prev] | [next] | [standalone]


#186706

FromJoerg Walther <joerg.walther@magenta.de>
Date2025-08-12 11:44 +0200
Message-ID<153m9k1etktjphk3k86aksjelqgm3faj5b@joergwalther.my-fqdn.de>
In reply to#186684
Paul in Houston TX wrote:

>> When is the last time any of us, who've been here forever, got a virus?
>
>Roughly 1995 for me.
>I have never used any active antivirus on my machines and don't plan to. 
>  All of my comps have accessed the web via multiple bridges, natting, 
>and routers, each with a hardware or software firewall.
>Running online scans or with updated Linux boot disk scanners once every 
>few months have never turned up anything that I was not already aware of 
>(virus simulators, etc.).  However, most of my work and friend 
>acquaintances are not comp literate and they like to click on the little 
>green buttons that say "Click here".

Apparently we both have been using the same virus scanner for ages then.
It's called BRAIN 1.0.

-jw-
-- 
And now for something completely different...

[toc] | [prev] | [next] | [standalone]


#186713

FromMarion <marion@facts.com>
Date2025-08-12 16:58 +0000
Message-ID<107frrr$28ue$1@nnrp.usenet.blueworldhosting.com>
In reply to#186706
On Tue, 12 Aug 2025 11:44:03 +0200, Joerg Walther wrote :


> most of my work and friend 
>>acquaintances are not comp literate and they like to click on the little 
>>green buttons that say "Click here".
> 
> Apparently we both have been using the same virus scanner for ages then.
> It's called BRAIN 1.0.

I'm gonna agree most of us haven't gotten a virus in years for, oh, maybe
two reasons, but the main reason is Brain 1.0 doesn't "click here now!".

I'm not sure if the other reason might be that Windows Defender is on by
default, it's updated by default, and maybe it's doing it's job????

Is it?

[toc] | [prev] | [next] | [standalone]


#186727

FromPaul <nospam@needed.invalid>
Date2025-08-12 18:37 -0400
Message-ID<107gfnq$3j0jr$1@dont-email.me>
In reply to#186713
On Tue, 8/12/2025 12:58 PM, Marion wrote:
> On Tue, 12 Aug 2025 11:44:03 +0200, Joerg Walther wrote :
> 
> 
>> most of my work and friend 
>>> acquaintances are not comp literate and they like to click on the little 
>>> green buttons that say "Click here".
>>
>> Apparently we both have been using the same virus scanner for ages then.
>> It's called BRAIN 1.0.
> 
> I'm gonna agree most of us haven't gotten a virus in years for, oh, maybe
> two reasons, but the main reason is Brain 1.0 doesn't "click here now!".
> 
> I'm not sure if the other reason might be that Windows Defender is on by
> default, it's updated by default, and maybe it's doing it's job????
> 
> Is it?
> 

It would find a way of reporting to you, if it was actually under attack.

When it complains about ProduKey being "hackerware", you are informed. You can
try testing with that, by downloading it, and having it instantly disappear
as it is scooped out of your grasp. I keep my copy in an encrypted 7Z file.
Like I worked for the bomb squad or something :-)

While a number of AVs react to EICAR, not all do. Some products have
a public policy, to not react to it. I've used that before,
to check that some of the more "lethargic" products, are actually loaded
and running.

Load into Virustotal.com (owned by Google), and search with it. EICAR SHA256

    275A021BBFB6489E54D471899F7DB9D1663FC695EC2FE2A2C4538AABF651FD0F

The fleet reacts pretty good, to a test.

https://www.virustotal.com/gui/file/275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f

   Paul

[toc] | [prev] | [next] | [standalone]


#186737

Fromwasbit <wasbit@REMOVEhotmail.com>
Date2025-08-13 09:15 +0100
Message-ID<107hhj9$3piu9$1@dont-email.me>
In reply to#186713
On 12/08/2025 17:58, Marion wrote:
> On Tue, 12 Aug 2025 11:44:03 +0200, Joerg Walther wrote :
> 
> 
>> most of my work and friend
>>> acquaintances are not comp literate and they like to click on the little
>>> green buttons that say "Click here".
>>
>> Apparently we both have been using the same virus scanner for ages then.
>> It's called BRAIN 1.0.
> 
> I'm gonna agree most of us haven't gotten a virus in years for, oh, maybe
> two reasons, but the main reason is Brain 1.0 doesn't "click here now!".
> 
> I'm not sure if the other reason might be that Windows Defender is on by
> default, it's updated by default, and maybe it's doing it's job????
> 
> Is it?
> 

Or maybe the router is doing it's job.


-- 
Regards
wasbit

[toc] | [prev] | [next] | [standalone]


#186748

FromMarion <marion@facts.com>
Date2025-08-13 21:21 +0000
Message-ID<107ivl9$kno$1@nnrp.usenet.blueworldhosting.com>
In reply to#186737
On Wed, 13 Aug 2025 09:15:38 +0100, wasbit wrote :


> On 12/08/2025 17:58, Marion wrote:
>> On Tue, 12 Aug 2025 11:44:03 +0200, Joerg Walther wrote :
>> 
>>> most of my work and friend
>>>> acquaintances are not comp literate and they like to click on the little
>>>> green buttons that say "Click here".
>>>
>>> Apparently we both have been using the same virus scanner for ages then.
>>> It's called BRAIN 1.0.
>> 
>> I'm gonna agree most of us haven't gotten a virus in years for, oh, maybe
>> two reasons, but the main reason is Brain 1.0 doesn't "click here now!".
>> 
>> I'm not sure if the other reason might be that Windows Defender is on by
>> default, it's updated by default, and maybe it's doing it's job????
>> 
>> Is it?
>> 
> 
> Or maybe the router is doing it's job.

Hi wasbit,

You know your stuff, particularly free software, which I respect.

I really don't know routers. I just set them up once every few years as I 
buy the penultimate version (as I wait a few years for the prices to drop).

My current router is an older Netgear Nighthawk RAX200, where I never added 
anything in particular for the router to do firewalling or AV tasks.

Other than block direct attacks by default, what does the router block?
All I can tell that it blocks might be 
 a. NAT (keeping my network away from the Internet)
 b. Direct intrusion attempt blocking by stateful packet inspection
 c. Logging (but I almost never check the logs but I see attacks when I do)
 d. Anything else?

Without subscriptions to protection like Netgear Armor or other addons, as 
far as I know, a router is not scanning for malware, phishing attacks, or 
malicious domains as the router, by default anyway, is just doing the front 
gate work of keeping random inbound connections out.

Am I setting up my router wrongly? 
Can I do anything else, for free, to prevent attacks?

[toc] | [prev] | [next] | [standalone]


#186751

FromHank Rogers <Hank@nospam.invalid>
Date2025-08-13 19:14 -0500
Message-ID<107j9pp$6ho8$2@dont-email.me>
In reply to#186748
Marion wrote on 8/13/2025 4:21 PM:
> On Wed, 13 Aug 2025 09:15:38 +0100, wasbit wrote :
> 
> 
>> On 12/08/2025 17:58, Marion wrote:
>>> On Tue, 12 Aug 2025 11:44:03 +0200, Joerg Walther wrote :
>>>
>>>> most of my work and friend
>>>>> acquaintances are not comp literate and they like to click on the little
>>>>> green buttons that say "Click here".
>>>>
>>>> Apparently we both have been using the same virus scanner for ages then.
>>>> It's called BRAIN 1.0.
>>>
>>> I'm gonna agree most of us haven't gotten a virus in years for, oh, maybe
>>> two reasons, but the main reason is Brain 1.0 doesn't "click here now!".
>>>
>>> I'm not sure if the other reason might be that Windows Defender is on by
>>> default, it's updated by default, and maybe it's doing it's job????
>>>
>>> Is it?
>>>
>>
>> Or maybe the router is doing it's job.
> 
> Hi wasbit,
> 
> You know your stuff, particularly free software, which I respect.
> 
> I really don't know routers. I just set them up once every few years as I
> buy the penultimate version (as I wait a few years for the prices to drop).
> 
> My current router is an older Netgear Nighthawk RAX200, where I never added
> anything in particular for the router to do firewalling or AV tasks.
> 
> Other than block direct attacks by default, what does the router block?
> All I can tell that it blocks might be
>   a. NAT (keeping my network away from the Internet)
>   b. Direct intrusion attempt blocking by stateful packet inspection
>   c. Logging (but I almost never check the logs but I see attacks when I do)
>   d. Anything else?
> 
> Without subscriptions to protection like Netgear Armor or other addons, as
> far as I know, a router is not scanning for malware, phishing attacks, or
> malicious domains as the router, by default anyway, is just doing the front
> gate work of keeping random inbound connections out.
> 
> Am I setting up my router wrongly?
> Can I do anything else, for free, to prevent attacks?
> 

Damn, I thought you knew everything!   What happened?

[toc] | [prev] | [next] | [standalone]


#186722

From"Carlos E. R." <robin_listas@es.invalid>
Date2025-08-12 21:22 +0200
Message-ID<mg1iirFo5fbU1@mid.individual.net>
In reply to#186677
On 2025-08-11 21:17, Marion wrote:
> On Mon, 11 Aug 2025 12:12:17 -0500, VanguardLH wrote :
> 
> 
>> Don't waste time with Avast to endure their marketing campaigns, and AVG
>> is the same as Avast since Avast acquired AVG for $1.3 billion way back
>> in 2016.  Avoid McAfee and Norton.
> 
> When is the last time any of us, who've been here forever, got a virus?

1988.

One of the reasons is I do use an antivirus when using Windows (not 
necessarily "scan on load").

-- 
Cheers,
        Carlos E.R.

[toc] | [prev] | [next] | [standalone]


#186678

Frommick <nospam@junk.mail>
Date2025-08-11 20:46 +0100
Message-ID<107dhb4$2qvlk$1@dont-email.me>
In reply to#186667
VanguardLH used his keyboard to write :
> Bill Bradshaw <bradshaw@gci.net> wrote:
>
>> After using Windows 11 on a new mini computer I am worried about
>> upgrading some of my windows 10 computers to 11. If you go through
>> some contortions MS is going to provide defender upgrades but it
>> appears you also have to have Microsoft accounts rather than local
>> accounts.  Why not forget defender and go to a commercial antivirus? 
>> So I would have pay for a license but that I am not concerned about
>> that.
>
> You could wait to see if Defender updates dry up.  If not, no need to
> change.  If so, first try a free Av, like Bitdefender, or Avira*.
>
> * I had problems with Avira.  Once I access removable storage (e.g., 
>   floppy drive), all removable devices got re-polled at 1-minute 
>   intervals.  Avira could not reproduce, so it never got addressed.  Few 
>   users got hit with the defect, but I was not alone.
>
> You could adding MalwareBytes Anti-Malware (MBAM), but not as the
> primary protection layer, and make sure to disable its on-access
> (realtime) scanner since only one should be active at a time.  Use MBAM
> as a second opinion on-demand (manual) scanner.  However, MBAM has far
> more false positives, even on tweaks you performed yourself to improve
> security (they don't know you made those tweaks).
>
> Don't waste time with Avast to endure their marketing campaigns, and AVG
> is the same as Avast since Avast acquired AVG for $1.3 billion way back
> in 2016.  Avoid McAfee and Norton.

What are your reasons for avoiding McAfee and Norton?
A friend of mine uses McAfee and swears by it.  I have used Norton 
since before the turn of the century and it has never caused me a 
problem (contrary to the claims that is slows down your pc).

-- 
mick

[toc] | [prev] | [next] | [standalone]


#186688

FromVanguardLH <V@nguard.LH>
Date2025-08-11 19:47 -0500
Message-ID<1vpkdasmgw7kk.dlg@v.nguard.lh>
In reply to#186678
mick <nospam@junk.mail> wrote:

> What are your reasons for avoiding McAfee and Norton?

When Norton's transparent proxy becomes unresponsive, web traffic halts.
Users don't know it's Norton causing the outage.  They reboot, and the
problem goes away.  I reported the issue, and how to reproduce it to
Symantec.  They were mute.  I finally figured out a way to stop the
service, kill which processes, and in which order, and in which order to
restart or reload them to get their transparent proxy functional again.

McAfee: Way too many false positives.  No free version, either.  And
trials are not freeware.

Both are extremely difficult to eradicate from your system.  Their
uninstall is very dirty.  In fact, the Norton devs said the only reason
anyone uninstall their software was as a troubleshooting step, and
absolutely always would reinstall right after uninstall, so leaving a
bunch of crap in the registry facilitated the re-setup.  Artifacts of
their dirty uninstall were shell extensions that were no longer valid,
but would screw up explorer.exe when trying to load them.  The vast
majority of users don't have the expertise to overcome dirty uninstalls,
know what might be the source of a problem, or diagnose a problem.
They're lost when a problem arises, and don't even know it's due to the
AV software.  They're good as long as they always function, and you
never uninstall them.

Both are good for pest detection, but more trouble than worth the effort
when compared to other free solutions.  While the OP hinted he may pay
for a 3rd-party anti-malware product, why pay for what you can get for
free?  He indicated nothing that infers he needs more than the default
feature set in freeware AV.

That you and your friend have good luck with Norton AV and McAfee AV
does not obviate all the complaints about them.  If you want more
reasons, do the research yourself.  You can visit av-comparatives.org to
compare various anti-malware products, like looking at:

https://www.av-comparatives.org/consumer/comparison/

Hover over each data point to get quick stats on each AV, like:

Bitdefender
  - Blocked: 99.8%
  - User dependent (user still had option to run malware): 0%
  - Compromised: 0.2%
  - False positives: 3
  
Avira
  - Blocked: 99.3%
  - User dependent: 0%
  - Compromised: 0.7%
  - False positives: 5
  
Norton
  - Blocked: 99.5%
  - User dependent: 0%
  - Compromised: 0.5%
  - False positives: 9
  
McAfee
  - Blocked: 99.3%
  - User dependent: 0%
  - Compromised: 0.7%
  - False positives: 9
  
High pest detection is nice, but false positives will waste your time
trying to determine they were false positives, or having to research
just what is the cause of the alert.  If you have a car with TPMS (Tire
Pressure Monitoring System), would you want it telling you there was a
flat when there wasn't?  Or your doorbell ringing when no one pushed the
doorbell button?

With Norton and McAfee, you can report false positives.  You first have
to determine it was a false positive, and how many users are going to
report it?  Most users can't even do the first step.  You want an AV
with high pest detection AND low[est] false positives.  Security for the
end user should be transparent, not a job.

[toc] | [prev] | [next] | [standalone]


#186704

Fromwasbit <wasbit@REMOVEhotmail.com>
Date2025-08-12 09:32 +0100
Message-ID<107eu7d$350hn$1@dont-email.me>
In reply to#186678
On 11/08/2025 20:46, mick wrote:
> VanguardLH used his keyboard to write :
>> Bill Bradshaw <bradshaw@gci.net> wrote:
>>
>>> After using Windows 11 on a new mini computer I am worried about
>>> upgrading some of my windows 10 computers to 11. If you go through
>>> some contortions MS is going to provide defender upgrades but it
>>> appears you also have to have Microsoft accounts rather than local
>>> accounts.  Why not forget defender and go to a commercial antivirus? 
>>> So I would have pay for a license but that I am not concerned about
>>> that.
>>
>> You could wait to see if Defender updates dry up.  If not, no need to
>> change.  If so, first try a free Av, like Bitdefender, or Avira*.
>>
>> * I had problems with Avira.  Once I access removable storage (e.g.,   
>> floppy drive), all removable devices got re-polled at 1-minute   
>> intervals.  Avira could not reproduce, so it never got addressed.  Few 
>>   users got hit with the defect, but I was not alone.
>>
>> You could adding MalwareBytes Anti-Malware (MBAM), but not as the
>> primary protection layer, and make sure to disable its on-access
>> (realtime) scanner since only one should be active at a time.  Use MBAM
>> as a second opinion on-demand (manual) scanner.  However, MBAM has far
>> more false positives, even on tweaks you performed yourself to improve
>> security (they don't know you made those tweaks).
>>
>> Don't waste time with Avast to endure their marketing campaigns, and AVG
>> is the same as Avast since Avast acquired AVG for $1.3 billion way back
>> in 2016.  Avoid McAfee and Norton.
> 
> What are your reasons for avoiding McAfee and Norton?
> A friend of mine uses McAfee and swears by it.  I have used Norton since 
> before the turn of the century and it has never caused me a problem 
> (contrary to the claims that is slows down your pc).
> 

Bloat.


-- 
Regards
wasbit

[toc] | [prev] | [next] | [standalone]


#186680

FromPaul <nospam@needed.invalid>
Date2025-08-11 17:24 -0400
Message-ID<107dn2c$2sfp2$1@dont-email.me>
In reply to#186666
On Mon, 8/11/2025 12:37 PM, Bill Bradshaw wrote:
> After using Windows 11 on a new mini computer I am worried about upgrading 
> some of my windows 10 computers to 11. If you go through some contortions MS 
> is going to provide defender upgrades but it appears you also have to have 
> Microsoft accounts rather than local accounts.  Why not forget defender and 
> go to a commercial antivirus?  So I would have pay for a license but that I 
> am not concerned about that.
> 
> <Bill> 
> 
> 

Observe the file pattern here.

   https://www.microsoft.com/en-us/wdsi/defenderupdates

There is more to the story, the story has details

1) Defender signature definitions (the above files). Free, but signature definitions
   are not a very strong method of protection.

2) Defender Engine Update (not available necessarily that way, might be a separate package).
3) Patch Tuesday security updates for known CVE
   ($30, MSA account, only lasts one year, limited duration)
   Or as an alternative, 0Patch subscription (select CVE patched by a third party company).
4) The $30 likely buys you other sorts of files or packages, but not new features.
   Maybe you'd still get certificate updates or something. IDK the details.
   Perhaps a certificate helps the SChannel to work (Firefox does not use the SChannel and
   has its own certificate store). There might be the odd third-party Windows utility,
   that relies on the SChannel for TLS/SSL.

  Paul

[toc] | [prev] | [next] | [standalone]


#186689

FromVanguardLH <V@nguard.LH>
Date2025-08-11 19:59 -0500
Message-ID<b96qcqs79n9p$.dlg@v.nguard.lh>
In reply to#186680
Paul <nospam@needed.invalid> wrote:

> Observe the file pattern here.
> 
>    https://www.microsoft.com/en-us/wdsi/defenderupdates

What pattern?  A history of update dates is not listed, so no way to
determine there how often or at what intervals Defender gets updated.

> There is more to the story, the story has details
> 
> 1) Defender signature definitions (the above files). Free, but signature definitions
>    are not a very strong method of protection.

Signature databases are updated at very short intervals, sometimes
daily.  Heuristics, however, often don't change until the next major
version update.  With Defender, its engine is updated with major version
releases of Windows, not before.  While signatures can cause false
positives (the hash to match is not against all bytes in a file), aging
heuristics can generate more false positives.

[toc] | [prev] | [next] | [standalone]


#186699

FromPaul <nospam@needed.invalid>
Date2025-08-12 01:39 -0400
Message-ID<107ek37$32nl0$2@dont-email.me>
In reply to#186689
On Mon, 8/11/2025 8:59 PM, VanguardLH wrote:
> Paul <nospam@needed.invalid> wrote:
> 
>> Observe the file pattern here.
>>
>>    https://www.microsoft.com/en-us/wdsi/defenderupdates
> 
> What pattern?  A history of update dates is not listed, so no way to
> determine there how often or at what intervals Defender gets updated.

Windows 7 still receives updates.

   Paul

[toc] | [prev] | [next] | [standalone]


#186705

Fromwasbit <wasbit@REMOVEhotmail.com>
Date2025-08-12 09:41 +0100
Message-ID<107eunm$35a9b$1@dont-email.me>
In reply to#186699
On 12/08/2025 06:39, Paul wrote:
> On Mon, 8/11/2025 8:59 PM, VanguardLH wrote:
>> Paul <nospam@needed.invalid> wrote:
>>
>>> Observe the file pattern here.
>>>
>>>     https://www.microsoft.com/en-us/wdsi/defenderupdates
>>
>> What pattern?  A history of update dates is not listed, so no way to
>> determine there how often or at what intervals Defender gets updated.
> 
> Windows 7 still receives updates.
> 

As does Windows 8.1, although my routine is to update the definitions 
manually every day after turning on the PC, then either scanning or 
walking away for 10 minutes allowing Defender to automatically start a 
scan when it detects no PC activity.



-- 
Regards
wasbit

[toc] | [prev] | [next] | [standalone]


#186716

FromVanguardLH <V@nguard.LH>
Date2025-08-12 12:49 -0500
Message-ID<pio5ch67cx44.dlg@v.nguard.lh>
In reply to#186699
Paul <nospam@needed.invalid> wrote:

> VanguardLH wrote:
>
>> Paul <nospam@needed.invalid> wrote:
>> 
>>> Observe the file pattern here.
>>>
>>>    https://www.microsoft.com/en-us/wdsi/defenderupdates
>> 
>> What pattern?  A history of update dates is not listed, so no way to
>> determine there how often or at what intervals Defender gets updated.
> 
> Windows 7 still receives updates.

Wouldn't that just be signature updates?  And those are not for virus,
or other malware, just spyware (see last paragraph).  I thought Defender
got engine updates with new versions (builds) of Windows, but the
following Microsoft article lists when there were engine & platform
updates:

https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-updates

July-2025 (Platform: 4.18.25070.5 | Engine: 1.1.25070.4)
  August 5, 2025 (Engine) / August 6, 2025 (Platform)
June-2025 (Platform: 4.18.25060.7 | Engine: 1.1.25060.6)
  July 22, 2025 (Engine) / July 22, 2025 (Platform)
May-2025 (Platform: 4.18.25050.5 | Engine: 1.1.25050.6)
  June 13, 2025 (Engine) / June 13, 2025 (Platform)
April-2025 (Platform: 4.18.25040.2 | Engine: 1.1.25040.1)
  May 14, 2025 (Engine) / May 22, 2025 (Platform)

That is as far back as that list shows.  Maybe there is another list
showing older history.  So, about once per month Defender gets engine
and platform updates.  

That article does not list versions of Windows, just "Windows" for the
supported platform.

https://www.microsoft.com/en-us/wdsi/definitions/antimalware-definition-release-notes

By picking different versions, it looks like sig updates occur on the
same day (zero days), or every 1 to 2 days, not after a month.  
Algorithms (heuristics) are not signatures, so presumably those are in
the engine/platform updates at monthly intervals.

Before Windows 8, Defender was just a spyware detector.  In Vista and 7,
users were pointed at MS Security Essentials (MSE) to get AV protection.
MSE was discontinued back with Windows 7, and its updates supposedly
ceased in Feb 2025.  

https://en.wikipedia.org/wiki/Microsoft_Security_Essentials#Discontinuation
  Although support for Windows 7[36] ended on 14 January 2020 Microsoft 
  will continue to update virus definitions for existing users until 
  2023."

Since you say you are using the old spyware-only Defender back in
Windows 7, you are no longer an existing MSE user; however, updates
supposedly ceased for MSE a while ago.

Not until Windows 8 did Microsoft roll their Endpoint client into
Windows to make Defender a true AV product, not just for spyware.  

https://en.wikipedia.org/wiki/Microsoft_Defender_Antivirus#Conversion_to_full_antivirus

If you are using Defender under Windows 7, it was only a spyware
detector, and you should really switch to a 3rd-party AV.  You probably
cannot get a new install of MSE on Windows, anymore.

[toc] | [prev] | [next] | [standalone]


#186700

FromPaul <nospam@needed.invalid>
Date2025-08-12 01:51 -0400
Message-ID<107ekp4$32t1b$1@dont-email.me>
In reply to#186689
On Mon, 8/11/2025 8:59 PM, VanguardLH wrote:
> Paul <nospam@needed.invalid> wrote:
> 
>> Observe the file pattern here.
>>
>>    https://www.microsoft.com/en-us/wdsi/defenderupdates
> 
> What pattern?  A history of update dates is not listed, so no way to
> determine there how often or at what intervals Defender gets updated.
> 
>> There is more to the story, the story has details
>>
>> 1) Defender signature definitions (the above files). Free, but signature definitions
>>    are not a very strong method of protection.
> 
> Signature databases are updated at very short intervals, sometimes
> daily.  Heuristics, however, often don't change until the next major
> version update.  With Defender, its engine is updated with major version
> releases of Windows, not before.  While signatures can cause false
> positives (the hash to match is not against all bytes in a file), aging
> heuristics can generate more false positives.
> 

Not all AVs have heuristics (that is how bad some of them are).
Some of them, you can kinda tell by how clueless the product
is, that they are just signature analysis programs.

Malwarebytes started by designing some heuristic protections
with their product, and no signatures. Signature analysis was
added later. Not many other products have worked in that order.
It's just so much easier to clone the ClamAV database and use
that.

I think AV-comparatives may have had a test for heuristic detection
at some point. Maybe ESET was known at the time, to have some
heuristic means.

Microsoft has on a couple of occasions, made reference to some
magic they have, but there is never any real-world event
that correlates with their description. For example, Microsoft
claims they can turn off your computer "in 10 microseconds"
in the event Windows Defender detects something it cannot
stop by conventional means. As a user, if you were not informed
of that possibility, you might never guess what such a scenario meant.
You would not know how to interpret that sort of dirty shutdown.
It implies the shutdown is fast enough, there would be nothing
in the Event Viewer. They also did not give any examples of
triggers that would cause that to happen. To the user, you would
not be able to tell that, from a THERMTRIP. Or a bad PSU.

   Paul

[toc] | [prev] | [next] | [standalone]


Page 1 of 2  [1] 2  Next page →

Back to top | Article view | alt.comp.os.windows-10


csiph-web