Live data from Hacker News

MS Windows Defender and DeCSS

arch13.com

31–40 of 211 posts

Re: MS Windows Defender and DeCSS

#31

Do tech aware people like nearly everyone in this forum, need Defender (or another AV) to run at all? How many people here completely or partially stop it from running?

It was really infuriating to disable, FWIW. I spent hours fighting with it one day. The UI doesn't let you fully disable it: you have to use registry keys and the group policy editor. The end result has this hilarious property where it is flagging the fact that I disabled it as tampering that might indicate malware? I don't know if I even can disable that part... and I apparently didn't even succeed fully anyway as I now am getting occasional notifications saying Defender did a scan and I am like "as far as I can tell, Defender us fully off" :/. At least I did--as far as I have so far been able to tell--succeed in disabling the "real-time" thing that kept "quarantining" my files.

Re: MS Windows Defender and DeCSS

#32

To be fair, this does look like a false positive. In general, the desktop antivirus space in 2021 is a mess. Because of the sheer number of malware, and some obfuscation techniques used by some of it, antivirus software has to use very broad regular expressions for describing the malware, counterbalanced by huge whitelists of known mainstream software. If you don't qualify as a "mainstream software vendor", simply bu…

I don't believe they use regular expressions.

Re: MS Windows Defender and DeCSS

#34

To be fair, this does look like a false positive. In general, the desktop antivirus space in 2021 is a mess. Because of the sheer number of malware, and some obfuscation techniques used by some of it, antivirus software has to use very broad regular expressions for describing the malware, counterbalanced by huge whitelists of known mainstream software. If you don't qualify as a "mainstream software vendor", simply bu…

I don't believe they use regular expressions.

Why not? I.e. is that from experience on working on anti malware remediation systems?

Re: MS Windows Defender and DeCSS

#35

Do tech aware people like nearly everyone in this forum, need Defender (or another AV) to run at all? How many people here completely or partially stop it from running?

first thing i do for a fresh windows install: i jump in the group policy editor and disable Defender and other things. been burned way too many times. granted, some of my projects definitely raise a lot of red flags heuristically...being packed and self modifying, etc.

Re: MS Windows Defender and DeCSS

#36
post #7

His comment in /r/sysadmin: "Setting a Windows Defender exception to the folder does not prevent the quarantine from occurring. I re-ran this test three times trying exceptions and even the entire NAS drive as on the excluded list." Windows Defender is overriding the user whitelist?

I wonder if it's related to the tamper protection setting? I know that setting makes it ignore other settings like group policy, though I've never seen it ignore whitelists, but maybe they've changed that?

Re: MS Windows Defender and DeCSS

#37
post #31

Do tech aware people like nearly everyone in this forum, need Defender (or another AV) to run at all? How many people here completely or partially stop it from running?

It was really infuriating to disable, FWIW. I spent hours fighting with it one day. The UI doesn't let you fully disable it: you have to use registry keys and the group policy editor. The end result has this hilarious property where it is flagging the fact that I disabled it as tampering that might indicate malware? I don't know if I even can disable that part... and I apparently didn't even succeed fully anyway as I…

should only take a moment in the group policy editor. you can actually filter settings by name to zero in on things quickly.

the only real cosmetic change i can see is for instance on the virus & threat protection page in windows 10, it says in red at the top of the window:

Your Virus & threat protection is managed by your organization.

Re: MS Windows Defender and DeCSS

#39
post #19
post #3

I wonder when Anti-Virus will start deleting files that express opinions they don't like. Reminds me of the famous Earworm https://www.youtube.com/watch?v=-JlxuQ7tPgQ

I get annoyed with AV when it quarantines "Potentially unwanted software" like ProduKey. While it may be able to be used maliciously, that's not why I have it installed, and I do want it on my machine.

My win10 install recently started deleting my install of qBittorrent, which I very much want installed and use daily, as "potentially unwanted software". Exceptions kept getting ignored so just today I disabled the entire category of potentially unwanted software in win defender. It feels like they're just getting capricious in their scope for flagging things now.

Re: MS Windows Defender and DeCSS

#40
post #31

Do tech aware people like nearly everyone in this forum, need Defender (or another AV) to run at all? How many people here completely or partially stop it from running?

It was really infuriating to disable, FWIW. I spent hours fighting with it one day. The UI doesn't let you fully disable it: you have to use registry keys and the group policy editor. The end result has this hilarious property where it is flagging the fact that I disabled it as tampering that might indicate malware? I don't know if I even can disable that part... and I apparently didn't even succeed fully anyway as I…

Try to uninstall it.
Post reply on HN