brainw0rms [they/them]

  • 0 Posts
  • 1 Comment
Joined 2 years ago
cake
Cake day: August 31st, 2023

help-circle
















  • You’re welcome, happy to help. For host file modifications you can either run the .bat in your VM and observe the changes it makes to C:\Windows\system32\drivers\etc\hosts or inspect the .bat and see what hosts its blocking.

    In this case, the .bat seems to do what it claims so it’s safe to run; it re-launches itself as admin, so that it can modify the hosts file. It also changes the ownership, security ACLs, and file attributes of the hosts file to what I believe should be its system defaults actually I guess the file’s owner is changed from the built in SYSTEM account to the Administrators group. Not sure why it does this since admins by default have write access to the file. Maybe their intention was to fix the file in case the user or some other software messed with these previously? Doesn’t seem malicious though.

    It’s also a good practice to block cracked software with your firewall, though not always necessary (or sometimes impossible because an internet connection is necessary to function). Usually this will make hosts file changes unnecessary.