Tuesday, November 3, 2015

Removing "Windows protected your PC" Messages

Many major browsers produce warnings when downloading rarely-seen files. Attempting to run those files results in the appearance of a "Windows protected your PC" message and no execution of the actual program. These messages can be very annoying, especially when it is known that the file is benign yet rare.

The unsafeness of files is remembered in an NTFS Alternate Data Stream. When the Windows ZIP extractor decompresses an archive, it replicates that tag to all the output files. The tag can be removed in one of two ways:
  • Open the Properties sheet of a downloaded file (before decompressing it if it's a ZIP) and press Unblock near the bottom
  • Download the Sysinternals Streams utility and run it with "-d" followed by a wildcard mask of files from which to purge ADS's
Files without the Zone.Identifier tag are much less likely to arouse SmartScreen's suspicion.

No comments:

Post a Comment