Jump to content


  • Content Count

  • Joined

  • Last visited

About shadowwar

  • Rank
    Forum Deity

Recent Profile Visitors

63,320 profile views
  1. This shouldn't be detected anymore. IT was fixed a bit ago.
  2. Its not detected locally here. It should of been within 10 mins of my last post. Maybe shutdown Malwarebytes and restart it and see if its still detected. If you do change it it would have to be whitelisted again for now. You can save some time though by uploading it to virustotal.com as our cloud would get a copy and learn whether its malware or not. I cant get into specifics but basically it looks for file anomalies similiar to what malware does. Files not signed. Weird version info. Empty sections or packed. etc. If the file was valid digital signed it goes a long way to preventing fps.
  3. The name should not make a difference. It may have learned its a fp already. Try naming it back and see.
  4. Impossible to say without the file or virustotal Link. Something is not common with the file.
  5. shadowwar

    VLC update

    I made the MBAE team aware and they are looking into it. TY.
  6. This is globeimposter 2.0 ransomware. There is no known decryptor at this time. Going to the site you linked this script is legit. It doesn't do the encryption. Did you download from anywhere else near the same time?
  7. shadowwar

    VLC update

    This was confirmed a fp and should be fixed now.
  8. This may be fixed now but would like the other information i requested. Thanks!
  9. Can you please click save results on that screen and paste he log here. I need the full path of the second file detected.
  10. Please post the virustotal links when they are done processing. Can you also export the reports and copy and paste them here. It shows more information then the screenshot does. Thanks!
  11. The link seems to be dead for the website that you provided.
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.