Advice Request MOTW dilemma

Microsoft Defender
28 Replies 3,388 Views
Share practical recommendations that address the author's needs.

Parkinsond

Level 68
Verified
Top Poster
Well-known
When trying to unblock file downloaded from internet to remove MOTW and allow ISG to act, unblocking fails with the message shown in the picture.

Capture2.PNG
 
Last edited by a moderator:
It seems like you're facing a permissions issue. Try running the unblocking process as an administrator or check the file's properties and permissions. Remember to backup your data before making any changes.
 
It seems like you're facing a permissions issue. Try running the unblocking process as an administrator or check the file's properties and permissions. Remember to backup your data before making any changes.
I am using the admin account, not the standard user.
Properties from context menu has no option as "run as admin"
 
I am using the admin account, not the standard user.
Properties from context menu has no option as "run as admin"
In that case, you might want to try using PowerShell. Open PowerShell as an admin, navigate to the file's directory, and use the command "Unblock-File -Path .\YourFileName.extension". Replace "YourFileName.extension" with your actual file's name and extension.
 
In that case, you might want to try using PowerShell. Open PowerShell as an admin, navigate to the file's directory, and use the command "Unblock-File -Path .\YourFileName.extension". Replace "YourFileName.extension" with your actual file's name and extension.
Worked; thank you
 
When trying to unblock file downloaded from internet to remove MOTW and allow ISG to act, unblocking fails with the message shown in the picture.

View attachment 288682

You probably have SAC enabled, which does not use MotW to check SmartScreen app reputation.
SAC only uses MotW to block shortcuts, scripts, etc. (no SmartScreen backend).
 
Last edited:
A couple of hours ago, I performed full scan with MD.
It came out with a backdoor in Edge cache.

I recalled I was testing fresh samples from URLhaus and some of them triggered download which I have aborted immediately, but seems some code was residing in Edge cache.

I wondered, if MD could detect it by on-demand scan, why it did not detect it once it was downloaded in cache.
Looked for MOTW, it was absent; this explains why BAFS did not work.

Is there any method to make Edge add MOTW to files stored in cache?
Capture.PNG
 
Currently, there's no direct method to force Edge to add MOTW to files in cache. However, you can enhance your security by regularly clearing your cache and enabling SmartScreen Filter in Edge settings. Additionally, always keep your Microsoft Defender updated for the latest threat definitions.
 
Currently, there's no direct method to force Edge to add MOTW to files in cache. However, you can enhance your security by regularly clearing your cache and enabling SmartScreen Filter in Edge settings. Additionally, always keep your Microsoft Defender updated for the latest threat definitions.
SmartScreen was sleeping deeply while testing the sample urls; only McAfee webadivsor and Trafficlight who caught some, and not all, of them.
 
SmartScreen was sleeping deeply while testing the sample urls; only McAfee webadivsor and Trafficlight who caught some, and not all, of them.
That's concerning. While SmartScreen is usually reliable, no tool is 100% foolproof. It's recommended to use a layered security approach. Keep using tools like McAfee WebAdvisor and Trafficlight, and consider adding more layers, such as a reputable antivirus program and a firewall. Stay vigilant with your browsing habits too.
 
That's concerning. While SmartScreen is usually reliable, no tool is 100% foolproof. It's recommended to use a layered security approach. Keep using tools like McAfee WebAdvisor and Trafficlight, and consider adding more layers, such as a reputable antivirus program and a firewall. Stay vigilant with your browsing habits too.
MD is reputable 😜
 
Files in browser's cache can't hurt your system so don't worry much about it.
But with that said, Microsoft Defender does not scan the default cache folders of browsers by its real-time protection. This helps with reducing performance impact I assume. I have only tested Chrome, Edge and Firefox.
But if you store your browser at a different non-standars location like for me a portable Chrome browser in my HDD, then Microsoft Defender will scan the cache and the file that it missed would've been detected (most of the time).
I have verified this multiple times.
 
Files in browser's cache can't hurt your system so don't worry much about it.
But with that said, Microsoft Defender does not scan the default cache folders of browsers by its real-time protection. This helps with reducing performance impact I assume. I have only tested Chrome, Edge and Firefox.
But if you store your browser at a different non-standars location like for me a portable Chrome browser in my HDD, then Microsoft Defender will scan the cache and the file that it missed would've been detected (most of the time).
I have verified this multiple times.
Recently, I have transferred the cache folder from the ssd to the hdd to reduce ssd writes.
It was not the best experience; the browser took ages to launch.
Anyway, Edge is set to clear cache on exit.
 
Recently, I have transferred the cache folder from the ssd to the hdd to reduce ssd writes.
It was not the best experience; the browser took ages to launch.
Anyway, Edge is set to clear cache on exit.
Depends on the HDD speed I guess. I also used like that for a while and didn't notice much of an impact most of the times. But if the HDD was doing something else then surely there was a massive impact. My cache wasn't set to be removed on exit which helped.

Now I store them in RamDisk and it's been a great experience.
 
It came out with a backdoor in Edge cache.
This is normal, especially if you test samples with malware or visit shady websites, even if the tests are superficial. On my browser the other day, there was a trojan in the cache of my Chrome browser. And do you know how it got into my browser cache? As soon as I visited an obviously obscure page, there was nothing unusual at the time, only after K did that automatic scan it does every day, that's when it found this Trojan in the cache and deleted it automatically. Don't play with fire on your physical machine, even if you think there's nothing important on it. Use a VM, or use them in an isolated, virtualized environment or open your browser inside a sandbox, although none of these are guaranteed to prevent you from being infected. The safest and most recommended is to use it in a VM. Ask @Shadowra if he tests malware samples on a physical machine?
 
Depends on the HDD speed I guess. I also used like that for a while and didn't notice much of an impact most of the times. But if the HDD was doing something else then surely there was a massive impact. My cache wasn't set to be removed on exit which helped.

Now I store them in RamDisk and it's been a great experience.

This is normal, especially if you test samples with malware or visit shady websites, even if the tests are superficial. On my browser the other day, there was a trojan in the cache of my Chrome browser. And do you know how it got into my browser cache? As soon as I visited an obviously obscure page, there was nothing unusual at the time, only after K did that automatic scan it does every day, that's when it found this Trojan in the cache and deleted it automatically. Don't play with fire on your physical machine, even if you think there's nothing important on it. Use a VM, or use them in an isolated, virtualized environment or open your browser inside a sandbox, although none of these are guaranteed to prevent you from being infected. The safest and most recommended is to use it in a VM. Ask @Shadowra if he tests malware samples on a physical machine?
Never used VM before; I think it requires ample amount of RAM.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top