Jump to content

MalwareBytes Blocks CloudPATIO due to Exploit payload


DavidLamm

Recommended Posts

Malware bytes falsely blocks our software called CloudPATIO at one of our customer's locations. They are Kirby Medical Center. This is used to display sleep study raw data.

Our software is invoked via the web browser. It launches a Batch script called run.bat which will retrieve a study file and pass it to another application called zzzPATViewer

agent version 1.2.0.1054

Windows 10 Enterprise

Version 22H2

OS Build 19045.3086

 

These are files that reported as being blocked. They have been added to exclusion list but still getting blocked.

CMD and batch scripts are not blocked by windows. The Run.bat can be executed manually.

 

image.png.8de2a35a0dda70a569ade15f56f34226.png

Aaron Slabe is IT agent from Kirby Medical Center where this problem is occurring and can provide more details.

image.png.f59ed4d3e27eb2d66c12252da4463fc8.png

image.png.0b376008b3ffab1c1fc08d475b91b19f.png

Edited by Arthi
Removed customer's personal info
Link to post
Share on other sites

  • Staff

Hi DavidLamm,

Thanks for posting. Malwarebytes exploit protection module is blocking the action of a web browser running a batch script command as we consider this an insecure operation.

Workaround for this is to turn off exploit protection for the web browser being used to do this action.

Thanks.

  • Like 1
Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.