Windows Defender Is Becoming the Powerful Antivirus That Windows 10 Needs

Discussion in 'other anti-virus software' started by Secondmineboy, Jan 30, 2016.

  1. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    My postings and comments about certificate bypasses were directed to SmartScreen which uses them in its reputation analysis determination.
     
  2. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
  3. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    The Bad Rabbit link you posted and further expounded upon in reply #1524 clearly notes that static machine analysis/learning(ML) is being done in the cloud. All the major AV vendors excluding Panda do their static ML locally. They also likewise will upload and perform additional more through analysis on their respective cloud servers as WD does. As such, the major AV vendors do not have to "lock" the executable for more than a few milliseconds which is undetectable to the user.

    WD does perform local based signature analysis based on recently detected and prevalent malware.
     
    Last edited: Dec 20, 2017
  4. OverDivine

    OverDivine Registered Member

    Joined:
    Jan 16, 2009
    Posts:
    24
    i tried both adguard extension and adguard for windows and none worked for me. i guess you can't inject anything in protected more
     
  5. guest

    guest Guest

    +1
     
  6. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,008
    Windows 10 Pro: Windows Defender Application Guard support coming
    https://www.ghacks.net/2017/12/21/windows-10-pro-windows-defender-application-guard-support-coming/

     
  7. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,072
    Location:
    Texas
    Several off topic posts removed. If another topic other than the thread topic need to be discussed, start another thread.
     
  8. Martin_C

    Martin_C Registered Member

    Joined:
    Dec 4, 2014
    Posts:
    525
    Oh, sweet joy once again.

    VBS/HVCI capable hardware will be auto-detected and VBS/HVCI enabled automatically during clean installations of Windows 10 from RS4 branch and onwards.

    As Dave Weston tweets :
    https://mobile.twitter.com/dwizzzleMSFT/status/943898254151790592

    This is bigger then huge. Microsoft takes security to new heights. :thumb::thumb:

    (This are the continuation of the great news from Microsoft mentioned in this post and in this post. )
     
  9. Buddel

    Buddel Registered Member

    Joined:
    Apr 28, 2015
    Posts:
    1,951
    The uninitiated home users will jump for joy.:cautious:
     
  10. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Thanks for the interesting info, this makes it all easier to understand. But I don't believe I misunderstood the post. Fact of the matter is that it took 14 minutes before WD started to block Bad Rabbit via the cloud. This means that local behavior blocking/ML should be improved, to reduce false positives and it should also be able to block malware post-execution, but this can be a bit tricky. So perhaps it's better to leave this to the specialized behavior blockers. But cool to see that WD can already block a lot of stuff with local AV technologies. I don't care for the cloud, any tool can submit malware to some online sandbox and come up with a verdict, that's not impressive to me, you know what I mean?
     
  11. TairikuOkami

    TairikuOkami Registered Member

    Joined:
    Oct 10, 2005
    Posts:
    3,438
    Location:
    Slovakia
    Still can not get it, then again I do not run WD nonstop, I guess that update is just picky.
     

    Attached Files:

  12. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    It arrives via a Win Update for WD definitions. If your using a metered connection, you have to manually initiate a Win Update. You also have to have WD set at a minimum to perform periodic scanning.
     
  13. Zorak

    Zorak Registered Member

    Joined:
    Jan 2, 2010
    Posts:
    182
    Location:
    Australian Capital Territory
    It used to trigger warnings for me on the MS recommended test site (smartscreentestratings2.net), along with others that have been listed in this thread, but now it doesn't. Looking back through my Event Viewer, 22 November was the last time an Event ID 1126 successful block was recorded for me.

    The test site still triggers a smartscreen block using the Edge browser. Maybe MS broke something in the recent Defender engine update?
     
    Last edited: Dec 24, 2017
  14. chrcol

    chrcol Registered Member

    Joined:
    Apr 19, 2006
    Posts:
    982
    Location:
    UK
    this still a heavy resource hog, on my mining rig when downloading blockchains the cpu was ramped at 100% on the windows defender process, the poor cpu is only a g4400 but shouldnt be that heavy on resources. Had to exclude the folder. I then tested with avast, nod32, and emsisoft and none of them had the same resource usage for the same activity. But they all uninstalled now as I decided to do away with a/v on everything except my laptop.
     
  15. chrcol

    chrcol Registered Member

    Joined:
    Apr 19, 2006
    Posts:
    982
    Location:
    UK
    Still waiting for applocker tho which is probably more potent than the lot put together.
     
  16. chrcol

    chrcol Registered Member

    Joined:
    Apr 19, 2006
    Posts:
    982
    Location:
    UK
    Good god that is bad practice, why on earth have microsoft started doing that,

    First of all ProgramData has always supposed to be for non executable files, its the admin location of AppData basically which is also not supposed to host executables.

    But to then give each new binary its own unique path will create havoc on firewall's, dont know what is in developers heads at times.
     
  17. chrcol

    chrcol Registered Member

    Joined:
    Apr 19, 2006
    Posts:
    982
    Location:
    UK
    yeah SRP is buggy, but its what we got since MS refuse to unlock applocker for non enterprise users :(
     
  18. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    I am running Windows 10 Pro v1703, and I have got it. I guess you are unlucky to not have it, yet. I have it running continuously.

    WindowsDefender_latest version_01.JPG
     
  19. ance

    ance formerly: fmon

    Joined:
    May 5, 2013
    Posts:
    1,359
    Is it possible that PUA registry tweak degrade system performance? :(
     
  20. ArchiveX

    ArchiveX Registered Member

    Joined:
    Apr 7, 2014
    Posts:
    1,501
    Location:
    .
    Did you check System Performance without the PUA Registry Tweak?
     
  21. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    Tested today with Chrome and Firefox latest versions. The test page was not blocked here. Can anyone else check?

    Confirmed here also.

    #1468

    Edit: Also here - #1472

    Thanks.
     
    Last edited: Jan 3, 2018
  22. Pirate_fin

    Pirate_fin Guest

    Works fine for me with Firefox 57.0.3 and test page blocked succesfully.
     
  23. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    Thanks. I tested on one machine and it works but not this machine for some reason. It used to.

    Does anyone know why it isn't working or how I fix it, preferably without reinstalling Windows?

    I have re-entered the cmdlet:
    Code:
    Set-MpPreference -EnableNetworkProtection Enabled
    ... but no joy
    Maybe @Martin_C ?

    Thanks.
     
  24. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    I should mention I have Windows 10 1709 Home Edition. If anyone knows how I can check that Network Protection is enabled, or another way to enable it I would appreciate it.

    I have downloaded Policy Plus but I don't know how to use that do check or enable Network Protection.

    Thanks.
     
  25. Pirate_fin

    Pirate_fin Guest

    I have Windows 10 Home Edition too and i used Windows Powershell to enable Network Protection.

    Copy this Get-MpPreference into Powershell and from the list that opens check if "EnableNetworkProtection" has number 1 behind it then it's enabled.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.