Jump to content

False positive - Ransom.Filelocker in legit trading software


davidredstone

Recommended Posts

Hi MWB,

 

I work for ANZ Bank in Australia, and our customers have started reporting MWB says our Trading Platform E*TRADE Pro has Ransom.Filelocker

 

Our website is etrade.com.au or invest.etrade.com.au, and the active trader software MSI is downloadable from here:

https://invest.etrade.com.au/pro/msi/proclient6.3.61.msi

 

Please scan for the false detection and update in your next cycle. I have attached a pic of my scan result. Thank you.

 

David R

Techinical Support

E*TRADE Australia

 

Link to post
Share on other sites

Specifically the False Positive is in Nevron.System.DLL
 

https://www.virustotal.com/en/file/be72e9573cd53a6786ff2f8c844588d28990897eccd843cc9d46b02e263fcf30/analysis/1447122533/

 

c:\1\1\Nevron.System.DLL (Ransom.FileLocker) -> No action taken. [d823bebda1eab87e287b7dc5e71d8e72]

 
Nevron.System.zip

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.