Skip to main content
New Participant
September 6, 2023
Question

Malwarebytes detects "Exploit Payload" when Premiere launches

  • September 6, 2023
  • 4 replies
  • 1089 views

Whenever I launch Premiere (Version 24.1.0 BETA Build 2) it triggers Malwarebytes Antivirus to detect an "Exploit Payload"

 

Thought it was worth reporting just in case.

 

Malwarebytes shows this in the log:

 

-Log Details-
Protection Event Date: 06/09/2023
Protection Event Time: 09:11
Log File: f2373992-4c8c-11ee-ae5e-18c04d89f677.json

-Software Information-
Version: 4.6.2.281
Components Version: 1.0.2131
Update Package Version: 1.0.74921
Licence: Premium

-System Information-
OS: Windows 10 (Build 19045.3324)
CPU: x64
File System: NTFS
User: System

-Exploit Details-
File: 0
(No malicious items detected)

Exploit: 1
Exploit.PayloadProcessBlock, C:\WINDOWS\SYSTEM32\WINDOWSPOWERSHELL\V1.0\powershell.exe powershell.exe get-wmiobject win32_computersystem | fl model, Blocked, 701, 392684, 0.0.0, ,

-Exploit Data-
Affected Application: cmd
Protection Layer: Application Behavior Protection
Protection Technique: Exploit payload process blocked
File Name: C:\WINDOWS\SYSTEM32\WINDOWSPOWERSHELL\V1.0\powershell.exe powershell.exe get-wmiobject win32_computersystem | fl model
URL:

 

(end)

This topic has been closed for replies.

4 replies

Ann Bens
Adobe Expert
October 5, 2023

Now I have seen this error message quite often lately.

 

New Participant
September 6, 2023

Thanks for the help!

R Neil Haugen
Brainiac
September 6, 2023

It's a non-issue thing. I've heard comments that the beta builds for many programs run some internal checkers, in order to see that code has executed correctly. (Best I can describe it, no really my wheelhouse.) 

 

And from what I've heard, that can trigger this sort of thing at times in antivirus & maleware reporters.

Ann Bens
Adobe Expert
September 6, 2023

I run malwarebyte: never seen this message.