App Review McAfee: how bad is the worst antivirus?

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
Content created by
TPSC
thanks (you gave us great info re McAfee (& Checkpoint)) but unclear McAfee Web Advisor needs my specific permission in firefox but NOT in Edge, is this a McAfee thing or browser thing? I decided days ago not to be concerned about McAfee "data collection." Since you asked, I have heard / read Emsisoft is better re privacy, and I asked chatgpt to compare Emsisoft with McAfee re privacy, and it listed several reasons why Emsi is more privacy respecting then M. Assuming chatgpt is correct, it only knows what it reads, I prefer your tests, @Shadowra's tests, cruelsister's tests... & (some) user experiences posted at MT :)
The Emsisift comparison is in the post above. Emsisoft doesn’t offer the same level of service as McAfee or many others. If I am your GP, I need certain set of information (quite large), if I am a first aider, merely applying a band aid, I obviously need less information from you.
The overall job done is not the same.

The prompt is linked to the privacy features Firefox implements.

Emsisoft advertises that data protection is a top priority. With Emsisoft Browser Security, for example, the web address is not transmitted in plain text but as a hash value.
Data encryption in transport (as well as at rest) is a must nowadays. Even cyber criminals nowadays rarely transmit your data in plain text 🙂
 
@Trident
I greatly value your expertise, and it's been very educational for me. I hope you'll continue to share your knowledge with us in the future. I'd hate to miss out on improving my knowledge in the field of cybersecurity.
Don’t worry, I’m not going anywhere for now, I’m difficult to shake off 😆🤪
 
Don’t worry, I’m not going anywhere for now, I’m difficult to shake off 😆🤪
Good, as I also value your knowledge and insights in which I'm now going to be firing up my Cosori Air fryer for lunch, which you turned me on to. It's not always about AV's, but the really important things in life, food 😅😅
 
@Trident (y)
McAfee_Block_backdoor_Moved_Quaratine.gif
 
@Trident (y)
Post in thread 'McAfee: how bad is the worst antivirus?'
App Review - McAfee: how bad is the worst antivirus?

There was another brief test performed by me today, McAfee removed everything. I did modify executables and scripts, but also I test the executables unmodified too (to make sure that it’s not the additional bytes that trigger detection).

Scripts were modified with inclusion of custom functions (subs in VBS as I got nothing to calculate and return).

In essence, the antivirus log does mention TLSH (Trend Micro Locality Sensitive Hash) which allows minor changes to still maintain detection. So the results are as expected. But sometimes it triggers local generic detections.
 
Executables were tested twice, original and hex-edited to append random bytes.
Interesting, I hadn't seen that McAfee blocked everything? Even switching through the Hex editor? Wow, if that's what I understand, nothing gets through, McAfee is catching everything. I hope he's patented it so no one can copy it. I've done everything to infect my machine, I've disabled the extension on purpose and it still downloads any sample, blocks any malicious URL, sometimes it even downloads the infected file but it blocks it and moves it to quarantine, impressive performance McAfee. See with the McAfee WebAdvisor extension deactivated, it still neutralizes. :)
1752619719376.png
 
I hope he's patented it so no one can copy it.
Patent TitlePublication NumberDate (YYYY-MM-DD)Brief Description
--- 2024 ---
Systems and Methods for Providing User Experiences on AR/VR SystemsUS-20240060933-A12024-02-22Manages security and privacy within augmented or virtual reality environments.
Methods and Apparatus for Comprehensive User-Centric ProtectionUS-20240034800-A12024-02-01Creates a personalized security posture based on a user's digital assets and risk profile across devices.
Systems and methods for detecting deepfake artifactsUS-20240012586-A12024-01-11Analyzes media files for subtle inconsistencies and artifacts to identify AI-generated deepfakes.
--- 2023 ---
Visual Detection of Phishing Websites via Headless BrowserUS-20230396013-A12023-12-07Uses a non-graphical browser to analyze the visual components of a webpage to determine if it's a phishing site.
Systems and Methods for Performing Multi-Faceted Security ScanningUS-20230349887-A12023-11-02Implements a multi-layered scanning approach to detect diverse and complex security threats.
Device Reputation Score Based on Device VitalsUS-20230282672-A12023-09-07Calculates a real-time trust score for a device based on its security health, software, and behavior.
In-Place Cloud Instance RestoreUS-20230205562-A12023-06-29Provides a method to restore a compromised cloud computing instance directly, minimizing downtime.
Dynamic Process Criticality ScoringUS-20230185984-A12023-06-15Assigns a real-time risk score to running processes to prioritize security actions.
Visual Identification of MalwareUS-20230089868-A12023-03-23Converts malware code into a visual representation (an image) to use image analysis for faster detection.
Methods and systems for cloud native threat detectionUS-20230070151-A12023-03-02Provides threat detection specifically designed for the architecture of cloud-native applications (containers, etc.).
Icon Based Phishing DetectionUS-20230047306-A12023-02-16Detects phishing attempts by analyzing the favicon or other icons associated with a website.
--- 2022 ---
Method and Apparatus for Hardware Based File/Document Expiry TimerUS-20220399433-A12022-12-15Enforces document access expiry dates using hardware-level security, making it harder to bypass.
Systems and Methods for Utilizing Hardware Assisted ProtectionUS-20220366299-A12022-11-17Leverages specialized hardware security features (like Intel SGX) to protect applications and data.
Threat Hunting Using Natural Language ProcessingUS-11451613-B22022-09-20Enables security analysts to search for threats in datasets using plain English queries instead of complex code.
Multi-Dimensional Malware AnalysisUS-20220261685-A12022-08-18Utilizes machine learning to analyze malware across multiple dimensions (code, behavior, network) for classification.
Systems and methods for mitigating against malicious scriptsUS-11394801-B22022-07-19Detects and neutralizes malicious scripts (e.g., Magecart) designed to steal payment info from web forms.
Detecting Grammatical Artifacts of Machine-Translated Phishing WebsitesUS-20220191398-A12022-06-16Identifies phishing sites by spotting grammatical errors characteristic of automated translation tools.
Systems and Methods for Monitoring IoT Device BaselineUS-11356453-B22022-06-07Establishes a normal behavior baseline for IoT devices and flags anomalous activity as a potential threat.
Methods and Systems for Detecting RansomwareUS-20220078235-A12022-03-10Employs behavioral analysis to detect and block ransomware activity before significant encryption occurs.
 
@Trident It's amazing how many patents McAfee has. It's impressive; they have greatly improved the product and its engine. If I had to buy a product license today, even if it were more expensive than other competing products, I wouldn't think twice. I would buy McAfee without a doubt. It's a pleasure to use, it's recognizable, and it's an undisputed, top-of-the-line product. :)
 
@Trident It's amazing how many patents McAfee has. It's impressive; they have greatly improved the product and its engine. If I had to buy a product license today, even if it were more expensive than other competing products, I wouldn't think twice. I would buy McAfee without a doubt. It's a pleasure to use, it's recognizable, and it's an undisputed, top-of-the-line product. :)
I am very interested in reading patents for everyone cuz the deep level of understanding that I wanna have, I’m not gonna get it in blog posts and support articles.
 
I am very interested in reading patents for everyone cuz the deep level of understanding that I wanna have, I’m not gonna get it in blog posts and support articles.
And why did people complain so much about McAfee? I didn't use the product at the time when people were complaining on McAfee forums. Or do they still complain? In fact, most users are never satisfied, even with the products they use on their computers. Sometimes because of the white GUI, I didn't like it lol, there is no such thing as a perfect product. I think effectiveness is more important, and you've been testing products for years. I remember Checkpoint when you did an extensive test, that Checkpoint product had everything it needed to take off, but it didn't happen that time. But it wasn't wasted time, you gained experience and every day you've been gaining more knowledge for decades. I believe you must have used almost every product on the market? So you know how things work in other products as well.
 
They are still complaining and they will always complain, the human nature is, when everything is ok, that’s expected so they won’t write anything.
When there is a small inconvenience, they will all complain.
Some complaints may be justified, a lot of them are on things that users can solve (like auto renewal has been Norton’s No1 complaint and there are at least 5 ways to turn if off quickly).

McAfee overall is a light, efficient and rather quiet product (I haven’t seen any nags myself) and I don’t see why it should be “discarded”. It’s also unique, there aren’t many AVs of this sort. It’s also feature rich and there are cheap licenses so not sure what more someone can ask for.

And yeah, at this point I’ve used everything and I can always use anything without any complaints whatsoever. The only thing I don’t like is lack of proprietary technology and not doing the job well.
 
Last edited:
Check Point and I are still partners, I don’t have partnerships with McAfee. The partnership happened after the tests and my main target are British businesses. Anyway, now I am developing something myself (email security and more).
Okay, I understand that's cool, you'll always have new experiences, this area is very good, it's endless.
 
@Trident Have you tested infostealers?
TBH everything I tested was info stealers, I haven't tested any ransomware.

We should always keep in mind that our tests are slightly unrealistic, McAfee more aggressively scans downloads and detects more malware on downloads as opposed to local files.

We bypass that (as well as the website reputation) by going certain sites to get the malware. Everything is in password protected archives.

McAfee also removes from inboxes emails with suspicious attachments (which as well, we bypass).

But it still does well.
 
But it still does well.
It works really well. I downloaded a sample info stealer. I didn't even get to click on the setup.exe file before it was immediately removed. It's not even fun anymore @Trident to test McAfee, it detects everything.
We should always keep in mind that our tests are slightly unrealistic, McAfee more aggressively scans downloads and detects more malware on downloads as opposed to local files.
Yes, I totally agree with you. These tests are unrealistic. Although many AVs have evolved in recent years, it's still incredible. I like McAfee because it acts quickly to detect threats and neutralizes them just as quickly. It doesn't wait for the user to take action, as happens with MD and K. I think all products should be like this: detect, block, and move to quarantine. But I believe there's something proprietary about them, it's their secret, and they're right, they're not stupid.