Jump to content

Node.exe & npm-cli.js [ExploitPayloadFile Blocked]


Icarus34

Recommended Posts

Hi, i bought a computer from a legit store, i installed the same day node, npm, and visual studio code.

I worked for a while coding on visual studio code and i let my computer off for a while.

When i unlocked it again, and reopened visual studio code, alot of exploit warnings appeared, also they blocked node.exe so i could'nt use the terminal anymore.

I formatted the computer, reinstalled all again, worked for two days and the same exploit warning appeared again, when i opened a new visual studio code window.

I will add one log, the one who has location ended on "prefix -g", if you need any more information let me know, im really curious about these warnings.

image.thumb.png.be1f9e82a459ce643b234abda735958f.png

log.txt

Link to post
Share on other sites

@Icarus34 did you do the reset to default?

Please do the following so that we may take a closer look at your system.

Please restart the computer and do the following.

WARNING: Do Not click the Repair option under Advanced unless requested by a Malwarebytes support agent or authorized helper

NOTE: The tools and the information obtained are safe and not harmful to your privacy or your computer, please allow the programs to run if blocked by your system.

  • Download the Malwarebytes Support Tool
  • In your Downloads folder, open the mb-support-x.x.x.xxx.exe file
  • In the User Account Control pop-up window, click Yes to continue the installation
  • Run the MBST Support Tool
  • In the left navigation pane of the Malwarebytes Support Tool, click Advanced
  • In the Advanced Options, click Gather Logs. A status diagram displays the tool is Getting logs from your machine
  • A zip file named mbst-grab-results.zip will be saved to the Public desktop (usually C:\Users\Public\Desktop), please upload that file on your next reply

     

Thank you

Link to post
Share on other sites

  • 2 weeks later...
  • 2 weeks later...

@GeneralMartok

Please download the following installer and run it. Install over the top of your current installation.

https://downloads.malwarebytes.com/file/mb-windows

Then restart the computer and open Malwarebytes and go to Settings by clicking the small gear icon and go to the General tab, scroll down and enable Beta updates 

You may need to wait up to about 5 minutes or so, but then check for updates on that same General tab or the About tab and let it update to the latest Beta version

Once it has updated, RESTART the computer again and let us know if you're still having an exploit block

Link to post
Share on other sites

@Porthos 

 

There is still an issue with MB working with Node.Js.  

Multiple Entries, here are a few.

-Log Details-
Protection Event Date: 10/3/23
Protection Event Time: 3:51 PM
Log File: 32f666f2-6226-11ee-8d85-8cae4cea21b7.json

-Software Information-
Version: 4.6.2.281
Components Version: 1.0.2131
Update Package Version: 1.0.75921
License: Premium

-System Information-
OS: Windows 10 (Build 19045.3448)
CPU: x64
File System: NTFS
User: System

-Exploit Details-
File: 1
Exploit.PayloadFileBlock, C:\Program Files\nodejs\node.exe, Quarantined, 0, 392684, 0.0.0, 1C583CCED5854388CE3BECD1E866602E, 7128B7A6E4EB4D5EFC9EBD62F72BF76EDC4E34EFFDCCFB1C6B399638521495D1

Exploit: 0
(No malicious items detected)


www.malwarebytes.com

-Log Details-
Protection Event Date: 10/3/23
Protection Event Time: 3:51 PM
Log File: 32dce650-6226-11ee-b88f-8cae4cea21b7.json

-Software Information-
Version: 4.6.2.281  (NOTE: In the UI of MB is shows 4.6.4)
Components Version: 1.0.2131
Update Package Version: 1.0.75921
License: Premium

-System Information-
OS: Windows 10 (Build 19045.3448)
CPU: x64
File System: NTFS
User: System

-Exploit Details-
File: 0
(No malicious items detected)

Exploit: 1
Exploit.PayloadFileBlock, C:\Program Files\nodejs\node.exe, Blocked, 601, 392684, 0.0.0, 1C583CCED5854388CE3BECD1E866602E, 7128B7A6E4EB4D5EFC9EBD62F72BF76EDC4E34EFFDCCFB1C6B399638521495D1

-Exploit Data-
Affected Application: cmd
Protection Layer: Application Behavior Protection
Protection Technique: Exploit payload file blocked
File Name: C:\Program Files\nodejs\node.exe
URL: 

(end)

 

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.