Antivirus software comparison - November 2023

These are literally the top 5 out of 5 worst endpoint protection products.

Anything ESET is a paid for... The joke in Cybersecurity is "BOT32, because it installs the botnet for you".

My popular picks for South Africa would be.

Microsoft Defender, crowd strike, sentinel one, sophos (on their way down) and Trend Micro.
 
Kaspersky Internet Security, hands down, the best (imo). Combines the best of safe browsing, and the antivirus part.
I had a malware attack a few years ago, so sophisticated that a students's laptop were infected, even with Defender up to date, and Kaspersky were, like, meh, malware detected and quarantined it. The firewall part also works well.

I heard that ESET is also good, have not seen it for a long time.

How's Sophos doing? I hate that piece of software. It meddled with my Wi-Fi drivers, and messed up my current work laptop's networking stack.
 
Anti-virus software is almost as annoying as talking printing drivers.

Anti-virus should be invisible until there is a virus. But all lean and mean software packages migrate to a circus of themeing and intrusiveness.

I loved Avira.I paid for the proper version. But at some point they decided to bombard me with "warnings" that could only be solved by buying another of their products. So uninstalled it.

I installed BitDefender and it decided that it should install its own root certificate, and mask the certificates of websites INCLUDING ones with invalid certificates. I uninstalled ASAP because you don't want random root certificates in your machine.

I haven't looked at AVG in the while. Does it still make sounds? And do annoying pop-ups to indicate activity?

Truely anti-viruses are almost as bad as viruses themselves.
I tried AVG again but it's a lot worse now. Very hard to set up with a lot of unnecessary and duplicate options. Then when you disable a feature or notification it keeps on telling you it's disabled which defeats the purpose. The final straw was when I had a program that would duplicate file dates but it would block it and there was no way to exit the scanner.

Thinking of trying Trend again which I last used in the days of PCcillin.

While that makes some sense, it sounds like a major PITA for a tiny bit of extra security. Defender really isn’t intrusive enough to warrant that much fuss. I just asked my dad about it and he says to ask you if you miss Vista’s UAC, whatever that is about, lol.

Also chatGPT tells me that antivirus catches only 28% of zero day exploits, which sounds better than zero?
It's quite a major bit of security. If you must use Defender then fine and well but any anti-virus is only as good as its detection but the first priority should be to ensure it doesn't get on your system in the first place. Windows is the very antithesis of security. Instead of relying on things being hidden you should be acquainted with the system so you don't screw it up. The first thing I do is make my system as open and accessible as can be so I can see what's going on with it. People click on a virus not wondering why it's showing a jpg extension when it shouldn't show any extension. Extensions should always show. That way you can't accidentally click it thinking it's a picture.
 
It's quite a major bit of security. If you must use Defender then fine and well but any anti-virus is only as good as its detection but the first priority should be to ensure it doesn't get on your system in the first place. Windows is the very antithesis of security. Instead of relying on things being hidden you should be acquainted with the system so you don't screw it up. The first thing I do is make my system as open and accessible as can be so I can see what's going on with it. People click on a virus not wondering why it's showing a jpg extension when it shouldn't show any extension. Extensions should always show. That way you can't accidentally click it thinking it's a picture.
It can’t be that major if I haven’t ever had a virus in all my years using a computer. Imagine having gone through that daily chore for years and years just to get the same result lol. I just use common sense and a non-intrusive antivirus.
 
Our company use Eset.. haven't failed yet so all good
That's the point of ESETs running joke. You don't have a virus because it can't detect it. POS software

.Only reason it got traction is because a rich Stellenbosch boy got bored and asked daddy for millions to fund his business, which he used to became ESET ZA. Used the rest to market it.
 
These are literally the top 5 out of 5 worst endpoint protection products.

Anything ESET is a paid for... The joke in Cybersecurity is "BOT32, because it installs the botnet for you".

My popular picks for South Africa would be.

Microsoft Defender, crowd strike, sentinel one, sophos (on their way down) and Trend Micro.
Isn’t sentinel one Enterprise software? Cant be downloaded only for one no?
 
That's the point of ESETs running joke. You don't have a virus because it can't detect it. POS software
I'm not sure where you get that from. Eset usually stands up fairly well in all AV benchmarks that I've seen and we've been using it for years with no issues. It's also relatively well priced compared to other offerings.
 
Sheesh......
Guess I'm stuck with them for now, as I paid for a year's subscription, but on the plus side it was during a special and got it super cheap.
You can't trust anyone anymore. But yea not much you can do about it now and considering the fine I'm guessing they plugged that by now.
 
AV is old school.

EDR is the future.
You mean managed AV? , that's been around for decades.

Application signatures and locked down permissions and good security patching is probably still the best way to run a mostly secure setup
 
You mean managed AV? , that's been around for decades.

Application signatures and locked down permissions and good security patching is probably still the best way to run a mostly secure setup
No, endpoint detection and response.
Software like Cloudstrike or SentinalOne uses behaviour analysis with AI. Monitors registry, files, network connections etc to detect threats/anomolies. No more signature based scanning of files which is always one step behind.
 
No, endpoint detection and response.
Software like Cloudstrike or SentinalOne uses behaviour analysis with AI. Monitors registry, files, network connections etc to detect threats/anomolies. No more signature based scanning of files which is always one step behind.
What I actually meant by application signature, was the white listing of applications and blocking the rest.

Registry, file and network connection monitoring has been part of many managed AV suites for quite some time.

Anomaly detection is the way to go, since so many threats are baked into software now. No need to have your own data collection virus, when the Browser, OS or AV suite will do it for you.
 
What I actually meant by application signature, was the white listing of applications and blocking the rest.
This is the way to go but almost impossible to implement in the corporate world unless everything is very tightly controlled. I don't know of a single place that has implemented a default block policy and only allow whitelisted applications.
 
This is the way to go but almost impossible to implement in the corporate world unless everything is very tightly controlled. I don't know of a single place that has implemented a default block policy and only allow whitelisted applications.
I know of a few that have, the problem is that the whitelisted applications get compromised without having the modify the application.

It's the applications you trust that end up hurting you the most.
 
Top
Sign up to the MyBroadband newsletter
X