ChantelleCameronFan Posted May 25 ID:1569086 Share Posted May 25 Hi, people. I downloaded days ago the file LibreOffice_7.5.3_Win_x86-64.msi and I have problems as follows: If I open it fresh, i.e. without opening any other created document, it opens OK. But if I open an old file then Malwarebytes says the following: "Exploit payload process blocked". And that happens opening any file created by Libreoffice, Draw, etc. Weird and the first time I see this. I tried to upload the LibreOffice_7.5.3_Win_x86-64.msi but its size does not allow me to do so. I don't know how to check the sum but it is false positive or not? Link to post Share on other sites More sharing options...
Porthos Posted May 25 ID:1569088 Share Posted May 25 Please provide the log for the detection. You can find Scan and Protection logs within the Malwarebytes 4 program in the following location RTP stands for Real-Time Protection and is where automatic protection operations would normally be logged If you click on the View option you should get something similar to the following with other options available. Thank you Link to post Share on other sites More sharing options...
ChantelleCameronFan Posted May 25 Author ID:1569089 Share Posted May 25 7 minutes ago, Porthos said: Please provide the log for the detection. You can find Scan and Protection logs within the Malwarebytes 4 program in the following location RTP stands for Real-Time Protection and is where automatic protection operations would normally be logged If you click on the View option you should get something similar to the following with other options available. Thank you Ok, thank you for the info. I am attaching the screenshots below. Let me know your opinion Link to post Share on other sites More sharing options...
ChantelleCameronFan Posted May 25 Author ID:1569091 Share Posted May 25 Malwarebytes www.malwarebytes.com -Log Details- Protection Event Date: 5/25/23 Protection Event Time: 5:12 AM Log File: 4ce53cb6-fadc-11ed-99f2-8019346d28e1.json -Software Information- Version: 4.5.29.268 Components Version: 1.0.2022 Update Package Version: 1.0.69969 License: Premium -System Information- OS: Windows 10 (Build 19045.3031) CPU: x64 File System: NTFS User: System -Exploit Details- File: 0 (No malicious items detected) Exploit: 1 Exploit.PayloadProcessBlock, C:\Program Files\LibreOffice\program\gpgme-w32spawn.exe C:\Program Files\LibreOffice\program\gpgme-w32spawn.exe C:\Users\pc\AppData\Local\Temp\gpgme-VCxuUM C:\Program Files (x86)\GnuPG\bin\gpgconf.exe --list-dirs, Blocked, 0, 392684, 0.0.0, , -Exploit Data- Affected Application: LibreOffice Protection Layer: Application Behavior Protection Protection Technique: Exploit payload process blocked File Name: C:\Program Files\LibreOffice\program\gpgme-w32spawn.exe C:\Program Files\LibreOffice\program\gpgme-w32spawn.exe C:\Users\pc\AppData\Local\Temp\gpgme-VCxuUM C:\Program Files (x86)\GnuPG\bin\gpgconf.exe --list-dirs URL: (end) Link to post Share on other sites More sharing options...
Porthos Posted May 25 ID:1569094 Share Posted May 25 I will ask @Arthi to assist you. Link to post Share on other sites More sharing options...
ChantelleCameronFan Posted May 26 Author ID:1569181 Share Posted May 26 19 hours ago, Porthos said: I will ask @Arthi to assist you. Thank you, I 'll wait then. Link to post Share on other sites More sharing options...
Staff Arthi Posted Wednesday at 06:08 PM Staff ID:1570068 Share Posted Wednesday at 06:08 PM Hi ChantelleCameronFan, Thanks for reaching out. I will need a couple of log files to analyze this further. 1. Please enable “Event Log Data” under MB4->Settings->General tab 2. Reproduce the block 3. Grab logs- Please get the following two files C:\ProgramData\Malwarebytes\MBAMService\logs\mbae-default.log C:\ProgramData\Malwarebytes\MBAMService\logs\MBAMSERVICE.log Thank you. Link to post Share on other sites More sharing options...
ChantelleCameronFan Posted Wednesday at 09:54 PM Author ID:1570110 Share Posted Wednesday at 09:54 PM 3 hours ago, Arthi said: Hi ChantelleCameronFan, Thanks for reaching out. I will need a couple of log files to analyze this further. 1. Please enable “Event Log Data” under MB4->Settings->General tab I did. 3 hours ago, Arthi said: 2. Reproduce the block 3. Grab logs- and How I do this? Please get the following two files C:\ProgramData\Malwarebytes\MBAMService\logs\mbae-default.log C:\ProgramData\Malwarebytes\MBAMService\logs\MBAMSERVICE.log Thank you. Link to post Share on other sites More sharing options...
Porthos Posted Wednesday at 09:57 PM ID:1570111 Share Posted Wednesday at 09:57 PM 1 minute ago, ChantelleCameronFan said: and How I do this? Zip and attach the following 2 files. You will have to enable hidden files in Windows to see them. C:\ProgramData\Malwarebytes\MBAMService\logs\mbae-default.log C:\ProgramData\Malwarebytes\MBAMService\logs\MBAMSERVICE.log Link to post Share on other sites More sharing options...
Porthos Posted Wednesday at 10:00 PM ID:1570112 Share Posted Wednesday at 10:00 PM Also to get logs you can do the following. Please do the following so that we may take a closer look at your installation for troubleshooting: NOTE: The tools and the information obtained is safe and not harmful to your privacy or your computer, please allow the programs to run if blocked by your system. Download the Malwarebytes Support Tool In your Downloads folder, open the mb-support-x.x.x.xxx.exe file In the User Account Control pop-up window, click Yes to continue the installation Run the MBST Support Tool In the left navigation pane of the Malwarebytes Support Tool, click Advanced In the Advanced Options, click Gather Logs. A status diagram displays the tool is Getting logs from your machine A zip file named mbst-grab-results.zip will be saved to your desktop, please upload that file on your next reply Thanks Link to post Share on other sites More sharing options...
ChantelleCameronFan Posted Wednesday at 10:05 PM Author ID:1570114 Share Posted Wednesday at 10:05 PM 3 hours ago, Arthi said: Please get the following two files C:\ProgramData\Malwarebytes\MBAMService\logs\mbae-default.log C:\ProgramData\Malwarebytes\MBAMService\logs\MBAMSERVICE.log Okay, I have logged into the PC, not into the Malwarebytes application: Thank you Arthi. Here are them as attachments : mbae-default.log MBAMSERVICE.LOG 1 Link to post Share on other sites More sharing options...
ChantelleCameronFan Posted Wednesday at 10:28 PM Author ID:1570119 Share Posted Wednesday at 10:28 PM 27 minutes ago, Porthos said: 27 minutes ago, Porthos said: mbst-grab-results.zip Link to post Share on other sites More sharing options...
ChantelleCameronFan Posted Wednesday at 10:30 PM Author ID:1570120 Share Posted Wednesday at 10:30 PM Dear Portos, I am not sure if I was successful to upload the "mbst-grab-results zip" but I think I did, right?... I was getting errors about wording... Link to post Share on other sites More sharing options...
Staff Arthi Posted Wednesday at 11:12 PM Staff ID:1570133 Share Posted Wednesday at 11:12 PM Hi, Your upload was successful. I am able to see the logs. However, I don't think the block was reproduced the issue after debug log was turned on as I do not see them in the latest log files. Can you please reproduce the block and then grab the logs, please. Thanks. Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted Thursday at 01:25 AM Root Admin ID:1570145 Share Posted Thursday at 01:25 AM I have removed the spam blocking @ChantelleCameronFan You should be able to post now without issue Link to post Share on other sites More sharing options...
ChantelleCameronFan Posted Thursday at 12:38 PM Author ID:1570205 Share Posted Thursday at 12:38 PM 13 hours ago, Arthi said: Hi, Your upload was successful. I am able to see the logs. However, I don't think the block was reproduced the issue after debug log was turned on as I do not see them in the latest log files. Can you please reproduce the block and then grab the logs, please. Thanks. Hi Arthi re-producing the logs using directly Libreoffice and opening files already created or doc files I just created. Every time I open them the same thing happens: the libreoffice application disappears and the Malwarebytes window appears with the same description: "Exploit payload process blocked". Note: if I open Libreoffice again and write something and save it nothing happens; the problem is when I open again the same document (or another already created) and then Malwarebytes closes it with the same payload exploit warning. What I have noticed very strange is (even though the doc was already closed, I can visually see ODT# File (.odt#) with 0 bytes present in the folder where I created/opened the original doc, why? Screenshots are coming in before I send you back everything you and Portos asked for. Please wait for the files you need.. Link to post Share on other sites More sharing options...
ChantelleCameronFan Posted Thursday at 12:55 PM Author ID:1570210 Share Posted Thursday at 12:55 PM Thanks to AdvancedSetup for removing block. -------------------------------- Again uploading the 3 files for Arthi and Portos: 1- C:\ProgramData\Malwarebytes\MBAMService\logs\mbae-default.log 2- C:\ProgramData\Malwarebytes\MBAMService\logs\MBAMSERVICE.log 3- "mbst-grab-results.zip" LibreOffice continues with the problem in Writer, etc mbst-grab-results.zip MBAMSERVICE.LOG mbae-default.log Link to post Share on other sites More sharing options...
ChantelleCameronFan Posted Thursday at 12:59 PM Author ID:1570213 Share Posted Thursday at 12:59 PM If I need to try again let me know. Or Arthi can enter in my PC. Link to post Share on other sites More sharing options...
Staff Arthi Posted Saturday at 03:04 AM Staff ID:1570531 Share Posted Saturday at 03:04 AM Hi, Can you turn off "Penetration Testing" toggle. You should find it in the Advanced settings. Click on Advanced settings->Turn off Penetration testing toggle and restart Libreoffice. Please let us know if that resolved the issue. Thanks. Link to post Share on other sites More sharing options...
ChantelleCameronFan Posted Saturday at 11:40 AM Author ID:1570544 Share Posted Saturday at 11:40 AM 8 hours ago, Arthi said: Hi, Can you turn off "Penetration Testing" toggle. You should find it in the Advanced settings. Click on Advanced settings->Turn off Penetration testing toggle and restart Libreoffice. Please let us know if that resolved the issue. Thanks. Hi Arthi: I did, but I point out that for months and months (with the toggle on for not allowing penetration testing attacks) Libreoffice and every other program on my PC were running at 100% perfection. The problem only started a week ago when I downloaded the latest version of Libreoffice "LibreOffice_7.5.3_Win_x86-64.msi". Ok, I removed the toggle on and now it is off. Now it opens all docs in (libreoffice) . My question is, what will happen now if at some point someone comes with a genuine 'penetration testing' attempt on my PC? For months and months I am a target of such action and I can explain it to you in a PM here. How can I defend myself from them now? Thanks for your help, Arthi and Porthos. Link to post Share on other sites More sharing options...
Solution Porthos Posted Saturday at 04:15 PM Solution ID:1570568 Share Posted Saturday at 04:15 PM (edited) 4 hours ago, ChantelleCameronFan said: My question is, what will happen now if at some point someone comes with a genuine 'penetration testing' attempt on my PC? For months and months I am a target of such action and I can explain it to you in a PM here. How can I defend myself from them now? That setting is specific to penetration testing (i.e. not actual threats) so enabling won't really do anything unless the system is tested using third-party testing tools/test exploits. It is purely for testing purposes to verify that protection is working properly, however, it is not needed for protecting your system from actual malware which is why it is turned off by default. There is also a warning there to not change those settings. I hope that helps to clarify things and if there is anything else we might help with please let us know. Edited Saturday at 04:20 PM by Porthos Link to post Share on other sites More sharing options...
ChantelleCameronFan Posted Saturday at 11:03 PM Author ID:1570599 Share Posted Saturday at 11:03 PM 6 hours ago, Porthos said: That setting is specific to penetration testing (i.e. not actual threats) so enabling won't really do anything unless the system is tested using third-party testing tools/test exploits. It is purely for testing purposes to verify that protection is working properly, however, it is not needed for protecting your system from actual malware which is why it is turned off by default. There is also a warning there to not change those settings. I hope that helps to clarify things and if there is anything else we might help with please let us know. Hi, Porthos You and Arthi (both) has solved this situation. I thank you both for the help. I will follow your suggestions too. Thank you Link to post Share on other sites More sharing options...
ChantelleCameronFan Posted Saturday at 11:05 PM Author ID:1570600 Share Posted Saturday at 11:05 PM 19 hours ago, Arthi said: Hi, Can you turn off "Penetration Testing" toggle. You should find it in the Advanced settings. Click on Advanced settings->Turn off Penetration testing toggle and restart Libreoffice. Please let us know if that resolved the issue. Thanks. Thank you Arthi for all your awesome help. You and Phortos solved this, 1 1 Link to post Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now