Jump to content

Application License check being blocked


SixtyNine

Recommended Posts

Malwarebytes
www.malwarebytes.com

-Log Details-
Protection Event Date: 9/14/23
Protection Event Time: 10:16 AM
Log File: 61d9edd2-52df-11ee-91eb-20cf3064b32a.json

-Software Information-
Version: 4.6.1.280
Components Version: 1.0.2117
Update Package Version: 1.0.75283
License: Premium

-System Information-
OS: Windows 10 (Build 19045.3448)
CPU: x64
File System: NTFS
User: System

-Exploit Details-
File: 0
(No malicious items detected)

Exploit: 1
Exploit.PayloadProcessBlock, C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -Command echo (Get-WmiObject Win32_ComputerSystemProduct | Select-Object -ExpandProperty UUID), Blocked, 701, 392684, 0.0.0, ,

-Exploit Data-
Affected Application: cmd
Protection Layer: Application Behavior Protection
Protection Technique: Exploit payload process blocked
File Name: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -Command echo (Get-WmiObject Win32_ComputerSystemProduct | Select-Object -ExpandProperty UUID)
URL:

 

(end)

Link to post
Share on other sites

  • 2 weeks later...

Hello, Thank you for responding. The check seemed to occur when the application was first initialised each day.

Since then I have negotiated with the supplier of the application to provide me with an alternative offline check (keyfile) so although the issue itself was not resolved it no longer affects me.

  • Like 1
Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.