With Office 365 ATP, things get even slower, too, which is not so great on my work device.
Detection rate is one thing. Performance is another. Both are important.
With Office 365 ATP, things get even slower, too, which is not so great on my work device.
Detection rate is one thing. Performance is another. Both are important.
These memory-type debates come up time and time again. Keep in mind I'm a programmer from the DOS days, note my user name on when this was an important issue. We had to cram every byte.
These programs will use idle RAM as they see necessary to be performant. If you aren't using the RAM, why not actually use it for what it's for?
Are you under memory pressure? How many GB of RAM do you currently have and how often are you capping it out? Try seeing what happens when you are at your GB RAM cap.
"I don't think that's appropriate" is highly subjective and it depends on what it does, and what you are currently doing.
If there was one, it would be fine.
How do I tell the system which of them I prefer (or some rank), instead of letting them fight it out, each of them thinking that they are the process entitled to all the perks of the currently unused memory?
Nothing is "fighting it out", there are internal heuristics to understand what applications need that RAM.
This is an internal OS feature of modern operating systems. If you are not capped out on RAM usage, this point is moot. If you are truly running at the RAM cap, to where the OS is paging out memory to disk and you have contention, you need more RAM.
My point was that there isn't one distinguished process, and that thus -- as you described -- it should be left to the OS to decide and not to Windows Defender.
The AV doesn't need to take "free ram" except when it tries to guess what the OS will do with disk cache. But by putting it in the AV cache it then prevents other software from using the cache.
Just use the OS level disk cache.
Unlike linux[1], windows task manager correctly shows "cached" ram as "free" ram. Therefore it's highly unlikely that the memory usage is from the OS caching mechanism.
As for the actual behavior of using free ram, what happens if there are two apps that try to use the same behavior? ie. you have windows defender and a DBMS installed, both of them try to use up all the free ram. In this situation, what makes you think the behavior of "using all the available free RAM" behavior of windows defender wouldn't push out the "using all the available free RAM" behavior of the DMBS", leading to worse performance?
Windows has an infrastructure to prioritize memory availability by process, and to notify processes when there is physical memory pressure so that they can act accordingly. I'm not sure, but as a first-party component I would assume that Windows Defender uses these appropriately.
That said, like most real-time antivirus Defender does feel that it is important to complete real-time protection scans and will sometimes do so at the cost of performance. The logic here is that it is important to complete these scans even under conditions of resource pressure, otherwise malware could just do things like cause high system load before downloading a second stage in order to avoid Defender completing a real-time scan.
Unfortunately this does sometimes cause headaches, for example I saw a situation recently where someone ran a tool that opened a huge number of media files on a NAS in order to read their metadata. This resulted in Defender queuing up a real-time scan of probably over a TB over the network since it saw all of these 10GB+ files being touched, with a definite negative impact on performance. I still wouldn't give "exclude network mounts" as general advice as some people do, but that's an example of sort of a pathological case for real-time scanning where you probably want to exclude it.
Only the kernel should be grabbing "free" ram and allocating it for cache.
That's something I'd expect a database to do. A virus scanner? Not so much.
I think you can exclude certain directories from Defender scanning too.
Where's the explicit code in Defender which ensures it only does its' thing if the system isn't under heavy load?
Also, you do realize that if every program followed this pattern - it would cease to work?
Whenever I see a machine that's slow or sluggish during operation but reports that only 60% of it's resources are used, Windows Defender is usually the culprit. I've nerfed Windows Defender for performance reasons to the point that I wonder why I even bother anymore.
Does yarn use more than a single core? I've seen some analysis articles that a major root cause of the slowdowns here are that the scanning API is hooked into file close and scanning takes time, so if you have a straightforward open file, write to file, close file, repeat single threaded process, your throughput gets really limited. I don't think there's a Windows API for asynchronous close, but if you send the handle to a thread (pool?), that will get you much better results.
None of the resources in task manager (or the resource manager thing) will show anything being capped so it's hard to troubleshoot what system Defender stresses so much.
Yeah, task manger is missing the most useful feature of FreeBSD top, the state column that lets you know what the process was doing at the sample time. If you saw your installer was always in state close handle, you'd have a good guess. But it's a straight forward throughput problem; if it takes 1 ms to scan a file, and there's no concurrency or pipelining, then you're limited to 1000 files per second. If you can thread pool closing, you get a lot more throughput. Unfortunately, everything that runs on windows and expects to close lots of files needs to manage a threadpool to close, but usually developers don't get to pick their platform, their users pick.
I've got Windows Sandbox to try anything shady in and a decent firewall on the edge between me and the rest of the world, I generally don't worry too much.
I checked on 5 different machines, one of which is a corporate laptop, and every one showed Defender using 100-150MB memory. 3 of those machines have 64GB memory. My desktop (which has 48GB memory) has been on for a week, and is currently showing 135MB.
In my experience, Defender's resource usage is actually low by comparison to others. McAfee is the worst, by a long shot - fans spin constantly, it uses up to gigabytes or memory, and is a ludicrous CPU hog.