AlexLeadingEdge Posted July 23, 2020 ID:1396625 Share Posted July 23, 2020 Hi guys, Malwarebytes is quarantining Free File Sync, including the Donation Edition which removes all the ads, so we attempted to add the MD5 Hash to Malwarebytes Cloud / Nebula but it doesn't seem to replicate through and stop Malwarebytes from quarantining our install file. In the new Exclusions window the Exploit Protection option is ticked, but Malware Protection, Ransomware Protection and Website Protection is grayed out as options to select. I'm wondering if this file comes under Malware Protection and therefore doesn't automatically stop the blocking of the file? Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted July 24, 2020 Root Admin ID:1396630 Share Posted July 24, 2020 Hello @AlexLeadingEdge Can you please create a support ticket so that someone can follow up with you on this. Contact Support Once you've created a support ticket if you let me know the ticket number I'll check and let someone on the team know. Thank you Link to post Share on other sites More sharing options...
AlexLeadingEdge Posted July 24, 2020 Author ID:1396633 Share Posted July 24, 2020 Malwarebytes Support Ticket 3125424 Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted July 24, 2020 Root Admin ID:1396634 Share Posted July 24, 2020 Thanks, I will let someone know @AlexLeadingEdge Link to post Share on other sites More sharing options...
AlexLeadingEdge Posted July 24, 2020 Author ID:1396644 Share Posted July 24, 2020 Cheers. Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted July 24, 2020 Root Admin ID:1396667 Share Posted July 24, 2020 Someone should reach out to you by tomorrow Thank you @AlexLeadingEdge Link to post Share on other sites More sharing options...
exile360 Posted July 24, 2020 ID:1396670 Share Posted July 24, 2020 Exclusions by MD5 only apply to Exploit Protection. This is why the item may still be detected by other components of Malwarebytes. If the item is being detected as malware or PUP (Potentially Unwanted Program) then excluding the file itself or the folder where it is installed should prevent it from being detected. Link to post Share on other sites More sharing options...
Solution xristo Posted May 10, 2021 Solution ID:1456050 Share Posted May 10, 2021 On 7/23/2020 at 7:59 PM, AlexLeadingEdge said: Hi guys, Malwarebytes is quarantining Free File Sync, including the Donation Edition which removes all the ads, so we attempted to add the MD5 Hash to Malwarebytes Cloud / Nebula but it doesn't seem to replicate through and stop Malwarebytes from quarantining our install file. In the new Exclusions window the Exploit Protection option is ticked, but Malware Protection, Ransomware Protection and Website Protection is grayed out as options to select. I'm wondering if this file comes under Malware Protection and therefore doesn't automatically stop the blocking of the file? AlexLeadingEdge, where did you obtain the MD5 hash for your exclusion? Did you ever get this method functioning as desired / expected? I don't even know where to find the MD5 hash within our MBAM Cloud console but have been awaiting that functionality since a 2019 feature request. 🤓 Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted May 10, 2021 Root Admin ID:1456054 Share Posted May 10, 2021 Hello @xristo Did you open a Customer Support Ticket for this? That would really be the best way to get further advice and even possibly escalate future enhancement. Link to post Share on other sites More sharing options...
AlexLeadingEdge Posted May 10, 2021 Author ID:1456078 Share Posted May 10, 2021 (edited) 59 minutes ago, xristo said: AlexLeadingEdge, where did you obtain the MD5 hash for your exclusion? Did you ever get this method functioning as desired / expected? I don't even know where to find the MD5 hash within our MBAM Cloud console but have been awaiting that functionality since a 2019 feature request. 🤓 I find I have to release the file out of quarantine and then upload it to VirusTotal.com, which gives me the MD5 hash, which I then can use in the Exclusions section of Malwarebytes OneView. If it is on a domain I can access the computer over the network without annoying the end users. It is long-winded approach but seems to work, but as mentioned above, the MD5 hash only works against Exploit Protection, not all the other components. I have pretty much given up on using MD5 hashes as half the time it will still pick up the file, so I open a forum thread here under False Positives and upload the quarantined file. Edited May 10, 2021 by AlexLeadingEdge Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted May 10, 2021 Root Admin ID:1456093 Share Posted May 10, 2021 On Windows 10 you can get the MD5 from a command prompt certutil -hashfile notepad.exe MD5 Returns the following MD5 hash of notepad.exe:423d3ade2f14572c5bd5f546973eb493 2 Link to post Share on other sites More sharing options...
AlexLeadingEdge Posted May 10, 2021 Author ID:1456095 Share Posted May 10, 2021 13 minutes ago, AdvancedSetup said: On Windows 10 you can get the MD5 from a command prompt Interesting, I didn't know that. Unfortunately it still requires releasing potentially infected files back into the wild just to get the MD5. Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted May 10, 2021 Root Admin ID:1456096 Share Posted May 10, 2021 I don't disagree with you, but in a business normally you'd have dozens or hundreds of systems with the same files. You should be able to check and validate from another computer. I know there is ongoing discussions for improving this in the program. Link to post Share on other sites More sharing options...
AlexLeadingEdge Posted May 11, 2021 Author ID:1456101 Share Posted May 11, 2021 6 minutes ago, AdvancedSetup said: I don't disagree with you, but in a business normally you'd have dozens or hundreds of systems with the same files. You should be able to check and validate from another computer. I know there is ongoing discussions for improving this in the program. Depends on the size of the business and the management software used. Without central management many computers will update themselves at any given day, which may result in dozens of different versions of the same software across a network. Computers that are offline or not on the network cannot be updated, so they have a different version from the majority. We use SolarWinds RMM to control Windows Updates, and PDQ to try and standardise the versions of programs, but there is only so much that you can do. If you look at the likes of Teamviewer, there are literally hundreds (thousands?) of versions, going from version 1 to version 15, with small build changes in each major version, which means different files, different MD5 hashes. Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted May 11, 2021 Root Admin ID:1456107 Share Posted May 11, 2021 Yes, understood. As mentioned the team is aware and have said they are working on improvements. Thank you again for your feedback Link to post Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now