App Review Windows Defender vs Ransomware 2024 (TPSC)

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
Content created by
The PC Security Channel

blackice

Level 38
Verified
Top Poster
Well-known
Apr 1, 2019
2,787
He was just referring to benchmark scores, which for gaming translates to fps. It's just inferior performance, not exactly issues.
I did have issues with one program when I tried it. Something with a low level driver, but I don’t remember what. But yes, ultimately my problem was performance.
 

monkeylove

Level 11
Verified
Top Poster
Well-known
Mar 9, 2014
545
Windows provides choice and control for users to configure their PCs to meet their specific needs, including the ability to turn Windows features like Memory Integrity and VMP on and off. Gamers who want to prioritize performance have the option to turn off these features while gaming and turn them back on when finished playing. However, if turned off, the device may be vulnerable to threats.
 
  • Like
Reactions: simmerskool

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,145
It does not protect well against zero hour malware,

I am afraid that there are no such tests for any AV. In known Real-World tests, there are some 0-day samples (but not zero-hour). The rest are 1-day or even a few days old malware. If I correctly recall, about 2/3 of samples in the wild can be 0-day malware. But when tested in the lab, the ratio can rapidly drop with any hour (many 0-day samples became dead or 1-day samples). If the test is done one time a day, the ratio can drop probably to one 0-day sample per 10 samples.

and fails utterly against banking trojans

That is true, but only if the banking trojan is run in the already infected environment. Such a scenario is probable in Enterprises via lateral movement. At home, the banking trojans are delivered by other malware types that are well-detected. So, the chances of banking trojan infection are very small (combined chances of initial_malware_infection * chances of banking_trojan_infection).

Anything beyond normal attacks and it is more probable that Microsoft Defender will fail to protect a system. This is confirmed by testing by MRG Effitas and AVLab.

That is more or less true for a free version (similarly to other free AVs), but I would not say that it is confirmed by MRG Effitas and AVLab.

MRG Effitas (360° Protection) does test only the business versions. It can confirm that Defender Antivirus Enterprise is an average protection layer against malware simulation on the already infected system (not good in the Banking Simulator Test) and as good as the top solutions in other banking tests (Real Botnet Test and Financial Malware Test). The overall protection against banking malware is better than Trend Micro Security and Avira Antivirus Pro.

The AVLab testing procedure is somewhat flawed for Microsoft Defender, because the "Block at first sight" feature does not work properly. It is rather a custom protection level (different from the real protection) used as a reference for other tested AVs.
Anyway, the results of the last test in January 2024 (2 missed samples) would be probably the same as with a fully functional "Block at first sight. The missed samples are legal PUAs (XMRIG, ReksFN) and Defender was tested with disabled PUA protection. Those PUAs were probably used as payloads and abused by initial malware. It is not clear if AVLab tested also the initial malware, if so then they were detected and Defender might score with 100% protection in the wild.

I can confirm from my experience, that Defender can miss some legal adware and PUAs even when PUA protection is enabled.
 
Last edited:

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,145
Most users are not going to employ a utility to tweak Microsoft Defender so the rationale, at least for Windows Home, is to test Defender at 100% defaults.

"Block at first sight" is a default setting of Microsoft Defender free. It does not work properly in AVLab tests because of a specific testing procedure. This topic was discussed a few times on MT.

Is MD a decent baseline when considering security from a general perspective? Sure it is. Is it good enough? That depends to a large extent upon the person using the system.
I think so. (y)
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top