I have XArp installed and the last hour it has come up with 350 alerts:
1. ChangeFilter: MAC Address for IP x.x.x.x changed from x-x-x-x-x.
2. RequestedResponseFilter: no matching request packet was sent out for this reply
3. MacFilter: incoming packet but sender mac set to our own mac address
4. SubnetFilter: source ip address lies not in your subnet
This is the variety of alerts I get. I have changed it to aggressive from default and it gets about the same alert numbers as default.
Avast and Malwarebytes have put many plugins coming from NiceHash (Cryptocurrency mining software) into quarantine, marked as Trojans. These are the only threats found from these two.