Jump to content

Exploit.Payload File Block, C:\Windows\sysnative\cmd.exe, is this safe?


xLuckyL

Recommended Posts

Hello, 

This is my first time creating a ticket so im sorry if I do something incorrectly. Here is the problem.

I started my PC up a couple minutes ago and I instantly got a couple warnings from my Malwarebytes Premium 4.6.1. called: Exploit.PayloadProcessBlock

I have no idea what this is and I have no idea if it is safe or if it is a false message. I got this message 4 times in a row. Here is the TXT file:

Malwarebytes
www.malwarebytes.com

-Log Details-
Protection Event Date: 9/12/23
Protection Event Time: 1:47 AM
Log File: 88cd4300-50fd-11ee-a1c9-d45d645172ee.json

-Software Information-
Version: 4.6.1.280
Components Version: 1.0.2117
Update Package Version: 1.0.75165
License: Premium

-System Information-
OS: Windows 10 (Build 19045.3324)
CPU: x64
File System: NTFS
User: System

-Exploit Details-
File: 0
(No malicious items detected)

Exploit: 1
Exploit.PayloadProcessBlock, C:\Windows\sysnative\cmd.exe C:\Windows\sysnative\cmd.exe \c C:\Windows\System32\REG.exe QUERY HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography \v MachineGuid, Blocked, 701, 392684, 0.0.0, , 

-Exploit Data-
Affected Application: cmd
Protection Layer: Application Behavior Protection
Protection Technique: Exploit payload process blocked
File Name: C:\Windows\sysnative\cmd.exe C:\Windows\sysnative\cmd.exe \c C:\Windows\System32\REG.exe QUERY HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography \v MachineGuid
URL: 

(end)

 

Can someone help me and look if it is safe?

Thank you very much and I am looking forwards to your reply.

 

Greetings,

 

Luke

Screenshot_3.png

Link to post
Share on other sites

@xLuckyL

Please do the following so that we may take a closer look at your system.

Please restart the computer and do the following.

WARNING: Do Not click the Repair option under Advanced unless requested by a Malwarebytes support agent or authorized helper

NOTE: The tools and the information obtained are safe and not harmful to your privacy or your computer, please allow the programs to run if blocked by your system.

  • Download the Malwarebytes Support Tool
  • In your Downloads folder, open the mb-support-x.x.x.xxx.exe file
  • In the User Account Control pop-up window, click Yes to continue the installation
  • Run the MBST Support Tool
  • In the left navigation pane of the Malwarebytes Support Tool, click Advanced
  • In the Advanced Options, click Gather Logs. A status diagram displays the tool is Getting logs from your machine
  • A zip file named mbst-grab-results.zip will be saved to the Public desktop (usually C:\Users\Public\Desktop), please upload that file on your next reply

     

Thank you

Link to post
Share on other sites

  • 2 weeks later...

I just got another one of those detections randomly.

 

Malwarebytes
www.malwarebytes.com

-Log Details-
Protection Event Date: 9/29/23
Protection Event Time: 4:58 PM
Log File: ac41ff04-5ed8-11ee-8011-d45d645172ee.json

-Software Information-
Version: 4.6.2.281
Components Version: 1.0.2131
Update Package Version: 1.0.75789
License: Premium

-System Information-
OS: Windows 10 (Build 19045.3448)
CPU: x64
File System: NTFS
User: System

-Exploit Details-
File: 0
(No malicious items detected)

Exploit: 1
Exploit.PayloadProcessBlock, C:\Windows\system32\cmd.exe cmd \c query session, Blocked, 701, 392684, 0.0.0, , 

-Exploit Data-
Affected Application: cmd
Protection Layer: Application Behavior Protection
Protection Technique: Exploit payload process blocked
File Name: C:\Windows\system32\cmd.exe cmd \c query session
URL: 

(end)

 

Is this dangerous?

image.png.14c420d85aead00231b32fc04c817491.png

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.