Team OS : Your Only Destination To Custom OS !!

Welcome to TeamOS Community, Register or Login to the Community to Download Torrents, Get Access to Shoutbox, Post Replies, Use Search Engine and many more features. Register Today!

Tips & Tricks Prevent Malwarebytes Corporate from modifying Windows host file [Trick]

juanamm

Uploader
Uploader
Power User
✅ Verified Member
Member
Downloaded
5.7 GB
Uploaded
448.6 GB
Ratio
78.11
Seedbonus
134,973
Upload Count
217 (223)
Member for 5 years
Prevent Malwarebytes Corporate from modifying Windows host file [Trick]

I had trouble running a version of IDM and I started to investigate why.
After looking closely I realized that some lines of the Windows host file were disabled (commented with #).
Those lines referenced the IDM host, so I removed the # to get them active again.
But when restarting PC Malwarebytes Corporate comments them again with #.

malw_ignore0.png


I know MB is doing that because in Avast I have the file excluded.

This specific version of Malwarebytes does not allow to manually add the paths to the files that I want to exclude (ignore list, whitelist).
You have to navigate to be able to include files there, but when I browse, it doesn't show me the "etc" folder, it only allows me to get to:
C:\Windows\System32\drivers\
So I will never be able to tell MB to ignore the host file that is on this path:
C:\Windows\System32\drivers\etc

malw_ignore.png


I thought about modifying access permissions to the host file, but that brings problems, because if I remove the permissions from the administrators when you want to install a program (such as silent IDM or other versions) that modify the file they will not be modified.

Then I thought about programming a .bat file with timers, so that after MB was loaded it would modify the host file again.


The only solution I found to keep MB from modifying the host file was by putting "read only" attributes on it.
It seems like a silly solution, I thought MB would break the attribute, but it worked. :giggle:


If someone comes up with a more ingenious idea so that MB doesn't modify the host file, don't hesitate to share it. :)
 

Don007

Uploader
✅ Verified Member
Member
Downloaded
121.9 GB
Uploaded
2.5 TB
Ratio
20.88
Seedbonus
7,567
Upload Count
6 (8)
Member for 5 years
Nice Trick ! @juanamm
 

Cyler

🤴 Super Admin
⚡OS Master
Downloaded
510.5 GB
Uploaded
24.5 TB
Ratio
49.16
Seedbonus
27,587
Upload Count
1 (1)
Member for 6 years
You could also try to block the System admin account from having access to that specific file.

  • Right-click on hosts file go to properties.
  • Go to the Security tab.
  • Under Groups and users go to the System and edit permissions.
  • Deny write permissions for the System.
  • Press OK and Done.
Some programs might edit the read-only attribute but they can never change the system without you doing it. You can reverse it at any time if you see any issues.
 
Last edited:

verash

Member
Downloaded
140 GB
Uploaded
2.9 TB
Ratio
21.34
Seedbonus
331,354
Upload Count
0 (0)
Member for 6 years
Nice work
 

juanamm

Uploader
Uploader
Power User
✅ Verified Member
Member
Downloaded
5.7 GB
Uploaded
448.6 GB
Ratio
78.11
Seedbonus
134,973
Upload Count
217 (223)
Member for 5 years
You could also try to block the System admin account from having access to that specific file....
I waited until today to answer you waiting for MB's behavior.
So far MB has not broken the read-only attribute, so I think it is a simple solution and it works.
In this specific case I will not change the access permissions of System, but it is a good idea for other programs that can break the attributes of the files.
Thank you very much for your suggestion.
 

2go2ozz

Member
Downloaded
733.8 MB
Uploaded
4.9 GB
Ratio
6.91
Seedbonus
0
Upload Count
0 (0)
Member for 4 years
What a coincidence.
I was also concerned about how to block the MB Corporate accessing to the hosts file and couldn't manage to see the hosts within the "MB corporate" whereas it was always possible within MB premiere.
I wonder if there's any other way to block access to the hosts file maybe through registry or something else
 

SlavkoPejic

Power User
✅ Verified Member
Member
Downloaded
200.5 GB
Uploaded
80.1 TB
Ratio
409.01
Seedbonus
510,645
Upload Count
0 (0)
Member for 5 years
Thanks
 

Ziggi123

Member
Downloaded
88.9 GB
Uploaded
85.1 GB
Ratio
0.96
Seedbonus
19,876
Upload Count
0 (0)
Member for 5 years
Thanks
 

Mr. Spacely

🤴 Super Admin
Uploader
Downloaded
153.9 GB
Uploaded
44 TB
Ratio
292.65
Seedbonus
12,635,530
Upload Count
11253 (11253)
Member for 8 years
I usually just added hosts file to exceptions in MB corporate or any version and never had problems, you should check to show hidden files and folders
 

2go2ozz

Member
Downloaded
733.8 MB
Uploaded
4.9 GB
Ratio
6.91
Seedbonus
0
Upload Count
0 (0)
Member for 4 years
Iceman96: I am afraid that I cannot find it and it is not possible in Corporate, it seems unless you share the screenshots on finding it.
I could go as far as drivers folder, not the etc and contents via corporate
 

juanamm

Uploader
Uploader
Power User
✅ Verified Member
Member
Downloaded
5.7 GB
Uploaded
448.6 GB
Ratio
78.11
Seedbonus
134,973
Upload Count
217 (223)
Member for 5 years
I usually just added hosts file to exceptions in MB corporate or any version and never had problems, you should check to show hidden files and folders

Iceman96: I am afraid that I cannot find it and it is not possible in Corporate, it seems unless you share the screenshots on finding it.
I could go as far as drivers folder, not the etc and contents via corporate

I would also like to see the screenshot of how you do it @Iceman96. :)
 

Cyler

🤴 Super Admin
⚡OS Master
Downloaded
510.5 GB
Uploaded
24.5 TB
Ratio
49.16
Seedbonus
27,587
Upload Count
1 (1)
Member for 6 years
In the corporate version, the exclusion list is called... allow list as in allowing NOT to scan or allow to skip specific files/folders/sites. In previous versions, it was called exclusion.

Click the Detection History card.
Click the Allow List tab.
To add an item to the Allow List, click Add.
Select the type of exclusion you want to add. (file, folder, website, etc)

I think after that it's simple.

Click Allow a file or folder, click Select a file or Select a folder, choose the file or folder you wish to exclude, then click Open.
Under Exclusion rules, choose how you would like to exclude the file or folder. Exclude from all detections or exclude from detection as malware or potentially unwanted item only or Exclude from detection as ransomware only
Click Done to confirm your changes.

From Malware's site
PUUhXA.png


The exclusion list in older versions.

PUUf8m.png
 
Last edited:

juanamm

Uploader
Uploader
Power User
✅ Verified Member
Member
Downloaded
5.7 GB
Uploaded
448.6 GB
Ratio
78.11
Seedbonus
134,973
Upload Count
217 (223)
Member for 5 years

Up to here we will all agree with you.
But the problem posed in this thread is how to exclude Windows "host" file and this doesn't fix it.
What you mark in the screenshot with number 3 allows you to navigate to the file to be excluded, but the problem is that you will never get to the host file, since MB hides the path to it.
I already shared a screenshot at startup but will be repeating it again just to be clear.
malw_ignore.png

What we ask Iceman for is a screenshot excluding the host file.
If I missed something and you can share that screenshot we will all be grateful to you.
 

Cyler

🤴 Super Admin
⚡OS Master
Downloaded
510.5 GB
Uploaded
24.5 TB
Ratio
49.16
Seedbonus
27,587
Upload Count
1 (1)
Member for 6 years
I think I figured where the problem/misunderstanding is. You were talking specifically and only about the corporate version which does not allow to exclude several files, not just system32/etc. The "normal" versions don't have that issue and that's why the confusion. You can see in the image below that host file from etc is added to the list. To be honest I thought it would be the same for all MBAM products. You learn something every day.

PUUYUq.png


Since the corporate version is part of the endpoint product solution, I suspect that you will also need the endpoint management console to further expand the exclusion lists. I don't use that version tho so I can't be 100% sure.
 
Last edited:

juanamm

Uploader
Uploader
Power User
✅ Verified Member
Member
Downloaded
5.7 GB
Uploaded
448.6 GB
Ratio
78.11
Seedbonus
134,973
Upload Count
217 (223)
Member for 5 years
.....Since the corporate version is part of the endpoint product solution, I suspect that you will also need the endpoint management console to further expand the exclusion lists. I don't use that version tho so I can't be 100% sure.
In the corporate version it does not allow that.
Perhaps it was some agreement with software providers to prevent the host file from being excluded so that it would not be used for piracy.
Or to protect the user in the event that some malware modifies such a file to be able to scan it.
Anyway, this issue is resolved in the way explained at the beginning of thread and since the corporate version is discontinued, engine is not updated, we can rest assured that the read-only attribute will not be broken in the future. :)
 

Mr. Spacely

🤴 Super Admin
Uploader
Downloaded
153.9 GB
Uploaded
44 TB
Ratio
292.65
Seedbonus
12,635,530
Upload Count
11253 (11253)
Member for 8 years
I think I figured where the problem/misunderstanding is. You were talking specifically and only about the corporate version which does not allow to exclude several files, not just system32/etc. The "normal" versions don't have that issue and that's why the confusion. You can see in the image below that host file from etc is added to the list. To be honest I thought it would be the same for all MBAM products. You learn something every day.

PUUYUq.png


Since the corporate version is part of the endpoint product solution, I suspect that you will also need the endpoint management console to further expand the exclusion lists. I don't use that version tho so I can't be 100% sure.

@juanamm that's how I usually do it thanks for showing what I mean @Cyler
 

juanamm

Uploader
Uploader
Power User
✅ Verified Member
Member
Downloaded
5.7 GB
Uploaded
448.6 GB
Ratio
78.11
Seedbonus
134,973
Upload Count
217 (223)
Member for 5 years
@juanamm that's how I usually do it thanks for showing what I mean @Cyler
Unfortunately, that doesn't work for the host file in the corporate version.
Anyway, thanks to you and @Cyler for sharing it.
 

Mr. Spacely

🤴 Super Admin
Uploader
Downloaded
153.9 GB
Uploaded
44 TB
Ratio
292.65
Seedbonus
12,635,530
Upload Count
11253 (11253)
Member for 8 years
Unfortunately, that doesn't work for the host file in the corporate version.
Anyway, thanks to you and @Cyler for sharing it.

I don't know then, it worked for me in that same corporate version, it was detecting changes then I added there and everything was okay, maybe problem is on your side?
 

juanamm

Uploader
Uploader
Power User
✅ Verified Member
Member
Downloaded
5.7 GB
Uploaded
448.6 GB
Ratio
78.11
Seedbonus
134,973
Upload Count
217 (223)
Member for 5 years
I don't know then, it worked for me in that same corporate version, it was detecting changes then I added there and everything was okay, maybe problem is on your side?
No friend, you have already seen that other users have raised the same problem.
So far I have not seen any screenshots of the corporate version where the Windows host file can be added.
If you are so kind to share it, we will thank you, otherwise we leave the subject like that so that it does not become a chit-chat.
 

Mr. Spacely

🤴 Super Admin
Uploader
Downloaded
153.9 GB
Uploaded
44 TB
Ratio
292.65
Seedbonus
12,635,530
Upload Count
11253 (11253)
Member for 8 years
No friend, you have already seen that other users have raised the same problem.
So far I have not seen any screenshots of the corporate version where the Windows host file can be added.
If you are so kind to share it, we will thank you, otherwise we leave the subject like that so that it does not become a chit-chat.

Sure, let me just dig it up somewhere and I will post :)
 
Top