Do AV companies check each definition update against windows?


Recommended Posts

oh, so they should just not bother then :facepalm:

seriously, that's your argument ?

and use a quality AV, which pretty much excludes all the free ones and you're pretty damn close to 100%, even on zero day viruses if you keep the heuristics on and at a decent setting

No my point was that you saying they cannot skip Windows files because they cannot guarantee 100% that they are clean, yet they are signed by Microsoft. They cannot guarantee Microsoft files are clean, but they cannot guarantee your computer is 100% clean either (close to 100% is still not 100%, so there is no sticker on the box that says "we guarantee your computer is 100% clean at all times").

Not once did I say they should just not try. These are Microsoft signed files we are talking about. You said they cannot guarantee they are 100% clean, but no AV has 100% detection rate anyway. I did not say they should just give up and go home.

Again, you're missing the context here. We are talking about files signed by Microsoft. Unless there is a disgruntled employee writing Windows, there is a 0% chance a stock Microsoft signed file will be infected with something. I see no reason why Microsoft couldn't be trusted for publishing clean files in their OS. There's no logic in believing this would be a security risk. Scanning these files only adds unnecessary reliability risks.

I think you're missing the point.

it doesn't matter WHO signed the files. The very purpose of security company is to NOT trust anyone elses security.

Also there's only a risk if you use a company with bad Q&A, generally all the free ones and the crappier paid ones. despite it previous bad rep, Norton is actually a very good AV today, with high performance, next to no system impact they actually make sure these things don't happen, and they're one of the best one zero day threats, and web threats that other AV's won't touch because they're not considered "viruses".

so pick one of the better security suites that cover a little more than just AV, and has a good rep and this isn't a problem, stay with the free ones, and expect to have you system files broken at some point.

I think you're missing the point.

it doesn't matter WHO signed the files. The very purpose of security company is to NOT trust anyone elses security.

Actually it does matter because in this context, Microsoft is signing the files... You know, the one who creates the actual OS itself...

Never in the history of Windows has there been a built-in virus created by Microsoft themselves. And I'm sure there never will be.

Even if a core .dll (or such) was infected, the only option would be to delete it which would crash the system anyway. What good does that do for anybody? I'll say it again, there's no reason to scan something that will never be broken as long as checksums line up. All the trust you need is in the checksum. Nothing magical about it.

Actually it does matter because in this context, Microsoft is signing the files... You know, the one who creates the actual OS itself...

Never in the history of Windows has there been a built-in virus created by Microsoft themselves. And I'm sure there never will be.

Even if a core .dll (or such) was infected, the only option would be to delete it which would crash the system anyway. What good does that do for anybody? I'll say it again, there's no reason to scan something that will never be broken as long as checksums line up. All the trust you need is in the checksum. Nothing magical about it.

Sometimes you can disinfect system files or restore the original.

Actually it does matter because in this context, Microsoft is signing the files... You know, the one who creates the actual OS itself...

Never in the history of Windows has there been a built-in virus created by Microsoft themselves. And I'm sure there never will be.

Even if a core .dll (or such) was infected, the only option would be to delete it which would crash the system anyway. What good does that do for anybody? I'll say it again, there's no reason to scan something that will never be broken as long as checksums line up. All the trust you need is in the checksum. Nothing magical about it.

ugh

:facepalm:

I would like to see webroot's take on this. I know we have a rep or two that posts here.... I'd love for them to participate in this thread.

Hello,

Some anti-malware companies check Microsoft Windows Updates. That means applying the update across all combinations of Microsoft Windows in all service pack levels, editions, and languages that they support, in combination with all of their products. This might be one or two thousand different configurations, so it's usually the sort of thing that's done headless in a server lab running all those configurations as VMs, although it could involve native hardware if there were a specific reason to do so (e.g., a strategic partnership between the anti-malware company and a device manufacturer for some kind of turnkey solution).

Regards,

Aryeh Goretsky

Hello,

Some anti-malware companies check Microsoft Windows Updates. That means applying the update across all combinations of Microsoft Windows in all service pack levels, editions, and languages that they support, in combination with all of their products. This might be one or two thousand different configurations, so it's usually the sort of thing that's done headless in a server lab running all those configurations as VMs, although it could involve native hardware if there were a specific reason to do so (e.g., a strategic partnership between the anti-malware company and a device manufacturer for some kind of turnkey solution).

Regards,

Aryeh Goretsky

many people are allergic to hypervizors....

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Those people that come over here on boats are already in a safe country, if they want to come over here then do so correctly though the right channels. I was born in the U.K, my family that came over here came so via the proper means. My partner came here via the correct channels, she also became a British citizen, she knows more about this country than most of them that was born here, including myself, she worked hard to do what she does. She will stick up for this country and have done a few times, when people from her own part of world have put the U.K down. We are not going to agree, all I said to start with is that maybe Trump has the right idea with this America first thing and maybe we should start doing the same. Maybe not as drastic as what he is doing, but we do need to sort this country out, we need to sort out tech instead of relying on the U.S and others. Again you have not shown why you are so annoyed that we have left the E.U and this is what it is all about? If you don't live in the U.K and live in the E.U are you annoyed that we left your little club? If you live in the U.K and is pro-E.U, then fair enough then I can see how it annoys you. Are you one of these people who lives in the U.K and have a holiday chalet in the E.U and can now only stay there for so long? If so, then that is bad luck. As I have posted before, I have no problem with people coming here to work, as long as they do if via the proper channels. We are out of the E.U, people voted out, and maybe if more people had voted instead of sitting on their backsides the results would have been different. But they like the E.U and our government thought no we would not vote to leave. How wrong they were, surprised me. I expected to wake up in the morning and hear on the radio that we voted to stay. As I said, we are out and have been for 10 years, we are not going to go back in anytime soon if we ever do, so we all need to make the best of how things are. Anyway, this is supposed to be a tech site.
    • Tim Cook: "The US over time began to stop having as many vocational kinds of skills." What's the point of wasting time getting those skills if you can't get a job with them? Good Lord, maybe he and his cohort of CEO's who exported all these jobs to China should just shut the f**k up :D
    • I made a new Cinematic/Trailer for the game, this will be the intro, still a work in progress!  I also updated the Steam page with a ton of new screenshots! 👀 https://store.steampowered.com/app/3925340/Incoherence_Dark_Rooms/  
    • Closed-loop cooling and a custom 800G network protocol let the $7.3B campus run as one AI training machine. Microsoft confirmed June 23, 2026, that its Fairwater campus in Mount Pleasant, Wisconsin, is fully operational — and the engineering behind it makes the facility something fundamentally different from every data center that came before it. Where conventional cloud infrastructure racks up general-purpose servers and parcels out workloads to each one independently, Fairwater links hundreds of thousands of NVIDIA GB200 Blackwell GPUs into a single, coherent cluster using a two-story building design, 800-gigabit-per-second Ethernet fabric, and a proprietary networking protocol co-developed with OpenAI and NVIDIA. The result, according to Microsoft, is the closest thing to a purpose-built AI supercomputer that any company has ever placed in commercial operation. https://www.techtimes.com/articles/319205/20260627/microsoft-opens-fairwater-wisconsin-ai-campus-runs-one-supercomputer-via-800g-ethernet.htm  
  • Recent Achievements

    • Conversation Starter
      jessse3334 earned a badge
      Conversation Starter
    • Reacting Well
      JuvenileDelinquent earned a badge
      Reacting Well
    • One Month Later
      Excellence2025 earned a badge
      One Month Later
    • Week One Done
      Excellence2025 earned a badge
      Week One Done
    • Week One Done
      flexorcist earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      501
    2. 2
      +Edouard
      211
    3. 3
      PsYcHoKiLLa
      150
    4. 4
      Steven P.
      73
    5. 5
      macoman
      62
  • Tell a friend

    Love Neowin? Tell a friend!