hagezi / dns-blocklists

DNS-Blocklists: For a better internet - keep the internet clean!
GNU General Public License v3.0
4.7k stars 150 forks source link

Windows 10 Defender Removes events.data.microsoft.com From Hosts File #3030

Closed taufikp closed 1 day ago

taufikp commented 2 days ago

Hi,

Not really an issue but just to let you know that Microsoft Windows Defender managed to remove events.data.microsoft.com from hosts file and tagged it as this virus: SettingsModifier:Win32/PossibleHostsFileHijack, few days after I put the anti tracker list in hosts file.

Thank you

hagezi commented 2 days ago

@taufikp

This is a general host file protection, see:

https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=SettingsModifier%3AWin32%2FPossibleHostsFileHijack&threatid=14994

"If you have changed the Hosts file yourself, you need to exclude it from detection by your antivirus software."

https://support.microsoft.com/en-us/windows/add-an-exclusion-to-windows-security-811816c0-4dfd-af4a-47e4-c301afe13b26

Go to Start > Settings > Update & Security > Windows Security > Virus & threat protection. Under Virus & threat protection settings, select Manage settings, and then under Exclusions, select Add or remove exclusions. Select Add an exclusion, and then select from files, folders, file types, or process.

taufikp commented 1 day ago

Thank you, good to know we can exclude hosts file from AV. And when I compared the tampered hosts file with your list here, only events.data.microsoft.com removed by Windows Defender. Interesting.