Advice Request Best Antivirus for my Family

Please provide comments and solutions that are helpful to the author of this topic.
Do they provide changelogs at all, Mcafee?

I would love to see change logs, haven't had any luck in finding them, though.
I had to browse Chinese websites to follow up the changes, for example that’s R131 (the user doesn’t seem to be lying).
Looks like they obtain some internal information.


Anyway, there is a new version every month, either towards the end, or next month in the first few days.

I would say all versions before 1.31 and the introduction of TLSH haven’t been that good. From this point (1.31) onwards, multi-dimensional malware analysis through bucketizing, TLSH, the rendering of websites in “invisible” browser for deeper analysis (even deeper seems to be coming soon based on patents) make the product usable and desirable.

If anyone is interested in the McAfee technologies/patents, I can explain in depth.

The architecture is based on just 2 kernel drivers, McAfee uses ELAM for self protection and to block malware from entering kernel mode. Windows and hardware defences like secure boot, patch guard and so on, further deal with kernel malware. Apart from that, there is also the usual suspect, minifilter, that will capture the new files.

Traffic interception is based on WFP entirely (McAfee does not add kernel drivers for this reason).

Real Protect works in user mode only by hooking API calls — before something enters kernel mode, there must be a user mode dropper or loader, it can’t just enter the kernel from the sky.
It needs to drop drivers, register them and potentially create services. At this point (assuming everything else has failed) Real Protect will treat the malware.

McAfee exited (almost) kernel mode even before Microsoft kicks them out.
 
Last edited:
I had to browse Chinese websites to follow up the changes, for example that’s R131 (the user doesn’t seem to be lying).
Is that what you meant? See the screenshot.👇 Well, now I'm going to rest, @Trident, @Studynxx, @harlan4096, @superleeds27, @Parkinsond, @simmerskool and all other members of MT, there are many members, good evening, good morning, good afternoon to all of you and a big hug! I am confident and not paranoid. That is what our friend says. BTW, a hug for you too, my friend @oldschool. I hope I always remember your saying. @KnownStormChaser I apologise for posting so many times on your thread. Sometimes we get a little carried away. I hope you find the AV you are looking for. 🖐
1754247970371.png
 
Eset’s behavioural monitoring is just like Panda TruPrevent — rumoured to exist, but nobody ever saw it in action. That’s why Eset is light.
It’s easy to be light when you are not doing much.
Exactly! Nailed it.

ESET relies only on signature-based detection. Its heuristic capabilities are unimpressive. The HIPS is practically useless. It lacks a behavior blocker entirely. The infinite setting offers no significant impact.
 
Exactly! Nailed it.

ESET relies only on signature-based detection. Its heuristic capabilities are unimpressive. The HIPS is practically useless. It lacks a behavior blocker entirely. The infinite setting offers no significant impact.
The infinite settings are not for the user—they are for Eset. Eset can’t deliver a framework that just works, with *some false positives* and some negatives.

That’s why Eset offers more settings than the entire Windows OS control panel. Users will make their choices. In one case Eset will wash their hands and tell you you didn’t put in aggressive mode.
In the other case when you complain about false positives, Eset will again point the finger at you, they will provide a generic and vague explanation how heuristics work and will say it’s your fault, you ramped the protection up.

It smells a lot of Norton’s beggings for AVC to test them in aggressive modes, but they didn’t dare activate this mode by default.

HIPS is there for the same reason.
 
I am using F-Secure now and looking to replace it as it has become Avira clone. Many people on this forum have discussed this Kaspersky topic in the past, some links on this:

Your post: Advice Request - Kaspersky Internet Security 2021 settings suggestion

This page: App Review - Shadowra's Big Comparative - Episode 1 : Free Antivirus

This whole thread: Question - Kaspersky without HTTPS Scanning - Still safe?
I'm aware of my thread, since this problem used to be a bit of a pain in the butt. But as for now, I haven't had this issue anymore. I suggest you give it a try if you haven't.
 
I started using Bitdefender on an Android Phone (Samsung A56).
RAM usage is very high:500-900MB.
The following app only uses 250MB, but I don't read good things about it:Eset.
I'm thinking about starting to use McAfee.
What is your opinion?
I use this app for phishing protection.
I use NextDNS within the Chrome browser, and special protection is also activated.
I think McAfee gives you extra security.