Windows Defender Is Becoming the Powerful Antivirus That Windows 10 Needs

Discussion in 'other anti-virus software' started by Secondmineboy, Jan 30, 2016.

  1. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,666
    Location:
    USA
    It was probably checking for malicious links. I'd actually call it fair that it scanned this, but if it was slow to do so they should work on the speed.
     
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,602
    Location:
    The Netherlands
    To be honest, they have no business checking the links in my bookmarks file LOL. But this just shows how dumb Win Defender really is. I wouldn't be surprised if they have even send the file to the cloud, which is a breach of privacy if you ask me.
     
  3. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,666
    Location:
    USA
    I guarantee they sent it to the cloud. If there were any they weren't already familiar with, they tried to connect to them as well. They do that with Skype also. If you send someone a link to a server you control you can see in the logs that they connected to it when you sent the link.
     
  4. SeriousHoax

    SeriousHoax Registered Member

    Joined:
    Mar 27, 2019
    Posts:
    101
    Location:
    Bangladesh
    Actually, malware from local HTML files is not uncommon nowadays, mainly in the business field where for example, it may come as an email attachment pretending to be companies' login site. In my short experience, ESET are the best at detecting local malicious HTML files followed by Bitdefender. Microsoft Defender and Kaspersky are the worst, where Kaspersky's file av component avoids scanning local HTML files 99% of the time.
     
  5. plat

    plat Registered Member

    Joined:
    Dec 19, 2018
    Posts:
    2,233
    Location:
    Brooklyn, NY
    Did you mean the enterprise version of Defender? Because the home version is much less sophisticated as it is.
     
  6. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    5,955
    some users often forget to tell which additional security is also installed ;)
     
  7. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,373
    Location:
    Italy
    1.jpg

    Updated virus definitions.
    Does anyone have this problem with Paint.net?

     
  8. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,071
    Location:
    Canada
    Can you exclude the file extension from Defender's scan options, or at least the folder the file resides in? Sorry my memory is fading on what options are available for Defender, since I've been running Linux 98% of the time for several months now, and barely missing Windows at all.
     
  9. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,184
    Location:
    UK
  10. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,666
    Location:
    USA
  11. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,373
    Location:
    Italy
  12. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    5,955
    you can exclude files, folders, filetypes, processes.

    but its not recommended to exclude html at all, more than to create a special folder and exclude this one.

    bookmarks.html contains a lot of html in bad case, any browser will have timeouts while importing because they are analysed on reading. for me i cannot second this behavior here for html, but for import.
     
  13. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,071
    Location:
    Canada
    Thanks, I kind of thought that was the case. In my scenario, and probably that of Rasheed's, I know 100% for sure the bookmarks.html file I export from my browser is safe, therefore he might want to export it to a dedicated, specific folder that's excluded form Defender's scanning, which, if I'm not mistaken, is what you might be suggesting.
     
  14. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,602
    Location:
    The Netherlands
    Good one, thanks for the tip, totally forgot about this. And this is probably because of WD's horrible GUI. I also noticed that WD is for some reason scanning XnView's databases, I can often see a small delay when opening picture thumbnails. I don't see any reason for it to scan pics.

    I still think it's dumb as hell! I have now made an exclusion.

    Yes, I have just seen the latest report about data transmission performed by multiple AV's, and surprise, surprise, WD is actually pretty bad from what I understood. Perhaps I should make the switch to some third party AV after all.
     
    Last edited: Aug 5, 2023
  15. plat

    plat Registered Member

    Joined:
    Dec 19, 2018
    Posts:
    2,233
    Location:
    Brooklyn, NY
  16. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
  17. plat

    plat Registered Member

    Joined:
    Dec 19, 2018
    Posts:
    2,233
    Location:
    Brooklyn, NY
    Oh wow. OK thanks, @itman
     
  18. Bertazzoni

    Bertazzoni Registered Member

    Joined:
    Apr 13, 2018
    Posts:
    658
    Location:
    Milan, Italia
  19. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,602
    Location:
    The Netherlands
    True, but I still think it's shocking it was this simple to bypass MS Defender, even the corporate version. Who knows how many companies are hacked, without them even knowing about it, with these kind of tricks. Also see this topic, about another way to bypass corporate AV's:

    https://www.wilderssecurity.com/thr...ing-and-eager-ransomware-double-agent.452197/
     
  20. 3x0gR13N

    3x0gR13N Registered Member

    Joined:
    May 1, 2008
    Posts:
    850
    I had configured "Turn off routine remediation" to "on" in GPEdit yet Defender deleted a file without my confirmation. Anyone else seeing the same? The file was configured to run at startup if it matters. Good job Microsoft, you 1d10ts.
     
  21. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,666
    Location:
    USA
    Anything can be bypassed by a skilled hacker. If they want you, they will get you. I only win by being a worthless target.
     
  22. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,602
    Location:
    The Netherlands
    The thing is, it seems like companies like Apple and Microsoft rely on third party security researchers instead of its own employees to point out flaws in built-in security in Windows and macOS. At the end of the day, these are design errors.
     
  23. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,666
    Location:
    USA
    Their own employees are less likely to catch the design flaws that they themselves made, else they would not have happened. Rule 1 of testing software. Never be the last word on testing your own work. This is why I disagree with anyone that suggests that Defender should be better because they made the OS. It's the very reason why it should be worse. If I had a nickel for every time one of my programmers said "It works on my machine"... I'd have some nickels.
     
  24. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,602
    Location:
    The Netherlands
    Yes, but that's exactly my point, companies like Apple and MS should have special ''hacker'' teams that weren't involved with actually developing OS built-in security. Now it seems they rely on third party bug hunters, it's a bit silly, especially when you see how easy it is to bypass this stuff.
     
  25. Freki123

    Freki123 Registered Member

    Joined:
    Jan 20, 2015
    Posts:
    337
    The other question is do they pay better than the zero day brokers? If you would find a nice bug and MS would pay 250k and a broker 400k were would you sell it? (Random numbers used for an example)
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.