Jump to content

MB Browser Guard v2.3.9 - Possible FP for WhyNotWin11.com


lmacri
Go to solution Solved by gonzo,

Recommended Posts

The URL https://www.whynotwin11.com/ is currently being blocked by Malwarebytes Browser Guard v2.3.9 (both Firefox and Chrome) due to a poor reputation. This site was not blocked when I visited it ~ 1 week ago.

The free WhyNotWin11 utility that is available for download on this site has been recommended on several reputable sites - see Ed Tittle's How to Check If Your PC Can Run Windows 11 on ComputerWorld and Lawrence Abrams' WhyNotWin11 is a Better Replacement for Windows 11's PC Health Check on BleepingComputer for two examples.

 

1134696133_MalwarebytesBrowserGuardforFFv2_3_9BlockingWhyNotWin11_com07Oct2021.png.45b65cb0787e23778ab69c3a73f45b6b.png

The WhyNotWin11 utility is also available on developer Robert Maehl's GitHub page at https://github.com/rcmaehl/WhyNotWin11 (site not  blocked by Malwarebytes).  I have no problem running WhyNotWin11 v2.4.1 (downloaded 28-Sep-2021) but the latest WhyNotWin11 v2.4.2.1 that I downloaded today is currently being blocked by Microsoft Defender's SmartScreen

902091278_WhyNotWin11_exev2_4_2_1BlockedbyMSDefenderSmartScreen06Oct2021.png.c026b30dc49d757edcb3d82500f8e6b4.png

 

The "problem" v2.4.2.1 executable of WhyNotWin11.exe that is blocked by Microsoft Defender's SmartScreen is attached as a .zip file, and scans of the .exe file with both Microsoft Defender and Malwarebytes Premium did not detect any threats.

WhyNotWin11.zip

-----------
64-bit Win 10 Pro v21H1 build 19043.1237 * Firefox v93.0 * Microsoft Defender v4.18.2109.6 * Malwarebytes Premium v4.4.7.134-1.0.1464 * Malwarebytes Browser Guard for FF v2.3.9
Dell Inspiron 15 5584, Intel i5-8265U CPU, 8 GB RAM, Toshiba KBG40ZNS256G 256 GB NVMe SSD, Intel UHD Graphics 620

Edited by lmacri
Link to post
10 hours ago, gonzo said:

...The site has been whitelisted. Please allow 15-30 minutes for changes to take effect. Sorry for the inconvenience.

Hi gonzo:

Thanks for taking care of this.

Just an FYI that the block for https://www.whynotwin11.com/ was removed for Malwarebytes Browser Guard for Firefox v2.3.9 in my default Firefox browser shortly after you posted.

However, Malwarebytes Browser Guard for Chrome v2.3.9 continued to block this site in my MS Edge browser until I cleared the entire browsing history in MS Edge as shown below.  Simply disabling and re-enabling the Malwarebytes Browser Guard for Chrome extension as you suggested <here> in another thread wasn't enough to clear the cache being used by the extension and remove the block.

1286684150_MSEdgev94_0_992_38ClearBrowsingHistory07Oct2021.png.0e27a073fd6f363297125411b1f19a37.png

-----------
64-bit Win 10 Pro v21H1 build 19043.1237 * Microsoft Defender v4.18.2109.6 * Malwarebytes Premium v4.4.7.134-1.0.1464 * Firefox v93.0.0 * MS Edge v94.0.992.38 * Malwarebytes Browser Guard for FF/Chrome v2.3.9
Dell Inspiron 15 5584, Intel i5-8265U CPU, 8 GB RAM, Toshiba KBG40ZNS256G 256 GB NVMe SSD, Intel UHD Graphics 620

Edited by lmacri
Revised image to remove private personal info (PPI)
Link to post
  • Root Admin

They use the same database, but the update mechanism for each browser is different. You many have to manually restart the browser or possibly restart the computer.

I've used that utility before and it seems to work well but not sure of the need at this point. Microsoft offers their own tools for everything one should need.

 

Introducing Windows 11
https://www.microsoft.com/en-us/windows/windows-11

Find Windows 11 specs, features, and computer requirements
https://www.microsoft.com/en-us/windows/windows-11-specifications

Update on Windows 11 minimum system requirements and the PC Health Check app
https://blogs.windows.com/windows-insider/2021/08/27/update-on-windows-11-minimum-system-requirements-and-the-pc-health-check-app/

How to get Windows 11
https://www.microsoft.com/en-us/windows/get-windows-11?icid=mscom_marcom_QL_Windows

Download Windows 11
https://www.microsoft.com/en-us/software-download/windows11

 

image.png

 

Edited by AdvancedSetup
updated information
Link to post
10 hours ago, AdvancedSetup said:

They use the same database, but the update mechanism for each browser is different. You many have to manually restart the browser or possibly restart the computer....

Hi AdvancedSetup:

I didn't go as far as restarting the computer, but restarting my MS Edge browser (with and without Malwarebytes Browser Guard for Chrome v2.3.9 disabled) didn't clear the block.

Quote

... I've used that utility before and it seems to work well but not sure of the need at this point. Microsoft offers their own tools for everything one should need.

I only wanted to report a false positive block of the download page so a discussion about the pros and cons of Robert Maehl's WhyNotWin11 app is a bit off topic, but I've seen several reports from users where the official Windows 11 PC Health Check tool provided by Microsoft failed to run to completion and displayed the message "Your organization manages updates on this PC" because the user had modified advanced Windows Update settings in the Local Group Policy Editor (GPEdit) of their Win 10 Pro machine - see the AskWoody.com thread Win 11 PC Health Check Aborts for one discussion on this topic.  I have modified a few of these advanced Windows Update settings with GPEdit (e.g., like the TargetReleaseVersion setting at Computer Configuration | Administrative Templates | Windows Components| Windows Update | Windows Update for Business | Select the Target Feature Update Version that I use to control when Win 10 version updates like v21H2 will be pushed to my machine) so I don't think the official Windows 11 PC Health Check tool will run correctly on my machine.

I'm also assuming that the official Microsoft app is an installed product (the installer is called WindowsPCHealthCheckSetup.msi) so one added benefit of Robert Maehl's WhyNotWin11 utility is that it does not have to be installed and can be run as a portable app from a removable USB thumb drive.
-----------
64-bit Win 10 Pro v21H1 build 19043.1237 * Microsoft Defender v4.18.2109.6 * Malwarebytes Premium v4.4.7.134-1.0.1464 * Firefox v93.0.0 * MS Edge v94.0.992.38 * MB Browser Guard for FF/Chrome v2.3.9
Dell Inspiron 15 5584, Intel i5-8265U CPU, 8 GB RAM, Toshiba KBG40ZNS256G 256 GB NVMe SSD, Intel UHD Graphics 620

Edited by lmacri
Link to post
3 hours ago, AdvancedSetup said:

Is the block gone now from MS Edge for you?

Hi AdvancedSetup:

Yes, but only after I cleared ALL my browsing data in MS Edge (Settings | Privacy, Search and Services | Clear Browsing Data | Clear Browsing Data Now | Choose What to Clear) as I showed in my image <above>.

When I exit my MS Edge browser I normally clear everything at Settings | Privacy, Search and Services | Clear Browsing Data | Choose What to Clear Every Time You Close The Browser except my Browsing History, which I like to retain for a few weeks at a time to speed up searches from the address bar.

1960097651_MSEdgev94_0_992_38ClearBrowsingDataonExit08Oct2021.png.3d5379d1ea5fe34c1d71da6f1df00286.png

-----------
64-bit Win 10 Pro v21H1 build 19043.1237 * Microsoft Defender v4.18.2109.6 * Malwarebytes Premium v4.4.8.137-1.0.1474 * Firefox v93.0.0 * MS Edge v94.0.992.38 * MB Browser Guard for FF/Chrome v2.3.9
Dell Inspiron 15 5584, Intel i5-8265U CPU, 8 GB RAM, Toshiba KBG40ZNS256G 256 GB NVMe SSD, Intel UHD Graphics 620

Link to post
27 minutes ago, lmacri said:

... Yes, but only after I cleared ALL my browsing data in MS Edge (Settings | Privacy, Search and Services | Clear Browsing Data | Clear Browsing Data Now | Choose What to Clear) as I showed in my image <above>.

When I exit my MS Edge browser I normally clear everything at Settings | Privacy, Search and Services | Clear Browsing Data | Choose What to Clear Every Time You Close The Browser except my Browsing History, which I like to retain for a few weeks at a time to speed up searches from the address bar.

Hi AdvancedSetup:

I should add that I also don't clear my Browsing History when I exit my Firefox browser, but this didn't seem to cause an issue with my Malwarebytes Browser Guard for Firefox extension.  The block for https://www.whynotwin11.com/ cleared on its own in my default Firefox browser without any intervention on my part as soon as Malwarebytes revised the Web Protection block list on their end.

1432869162_Firefoxv93_0_0ClearHistoryonExit08-Oct-2021.png.3966a1712cd074002f7f356d77b3beba.png

-----------
64-bit Win 10 Pro v21H1 build 19043.1237 * Microsoft Defender v4.18.2109.6 * Malwarebytes Premium v4.4.8.137-1.0.1474 * Firefox v93.0.0 * MS Edge v94.0.992.38 * MB Browser Guard for FF/Chrome v2.3.9
Dell Inspiron 15 5584, Intel i5-8265U CPU, 8 GB RAM, Toshiba KBG40ZNS256G 256 GB NVMe SSD, Intel UHD Graphics 620

Edited by lmacri
Link to post

Hi AdvancedSetup:

I understood from staffer gonzo's 23-Sep-2021 post in MWB Browser Guard- False +ve or Hidden Malware?! that there is a known issue with the way that the Malwarebytes Browser Guard extension employs cache and that a modification request has been submitted to the developers. Hopefully the feedback I posted <above> about the problem I had removing the web block for https://www.whynotwin11.com/ in MS Edge (but not Firefox) will be helpful to the person who is assigned this bug fix.

Reading gonzo's 23-Sep-2021 post about this issue with cached data was the reason I tried clearing my MS Edge browsing history in the first place, and I just wanted him to know that this finally removed the web block after everything else I tried had failed.
-----------
64-bit Win 10 Pro v21H1 build 19043.1237 * Microsoft Defender v4.18.2109.6 * Malwarebytes Premium v4.4.8.137-1.0.1474 * Firefox v93.0.0 * MS Edge v94.0.992.38 * MB Browser Guard for FF/Chrome v2.3.9
Dell Inspiron 15 5584, Intel i5-8265U CPU, 8 GB RAM, Toshiba KBG40ZNS256G 256 GB NVMe SSD, Intel UHD Graphics 620

  • Like 1
Link to post

I'm not sure that it is a known issue with Browser Guard.  Having worked for a browser vendor in the past, I know that they make sure their releases are compliant with standards.  Once they hit that bar, they have a tendency to go in various directions that suit their efforts toward creation of new IETF standards and/or lobbying for new directions.  That has a tendency to make something simple turn into a technical monster when (potentially) each browser manufacturer has their own special tweaks.

As an example, I was on imdb.com, looking at the cast of a movie.  I decided to use my text editor to copy and paste the table (actor and role) since the list was long.  Chrome had the information stored with role (column B) before actor (column A).  Firefox had column A before column B.  I know one allocates memory for table rendering as they go, while the other determines how much memory is needed for the full table before they render anything.  In neither case are standards involved, only preferences of browser vendors.  I had my preference for a secondary usage, but both satisfied the primary usage (the standards).

Profoundly irrelevant story aside, I am passing this thread to the developer should he take interest in your findings.  Thanks for the input.

Link to post

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.