Jump to content

RANSOMEWARE ALERT


RODCOL16

Recommended Posts

Got a question, how can we know if this software is scanning something and reports it as ransomeware? I checked the dashboard, the quarantined and exclusions. No settings and no way to tell what has been or not been scanned. ? Don't like the idea of it flagging a false positive and removing something. I just got this computer within the past week. So what could it have flagged? ,

Link to post
Share on other sites

Hello All:

 

Please carefully read the locked and pinned topic in this sub-forum, How to report a False Positive.

 

Then, kindly attach the requested archives to your own topic so possible follow-up with one member is not misconstrued by another..

Thank you for beta testing MBARW and your valuable feedback.

Link to post
Share on other sites

  1. Finish the detection process and reboot if asked by Anti-Ransomware. ?How to do this? There is very little interface, no ability to start or stop a detection process other than turn protection on or off. Was not asked to reboot. The alert pop up faded and I went to the program, checked it top to bottom, nothing. No information on anything. No file listed. No way of telling if it was scanning or what, other than opening task manager to see what memory was being used. 
  2. After reboot disable the Anti-Ransomware protection.
  3. Restore the file from Quarantine and add it to the exclusions. No file in quarantine to restore. Nothing listed anywhere in the program. 
  4. Find the restored EXE file that was quarantined, right-click on it and click "Send To >> Compressed (Zipped) Folder". Attach this ZIP file also to your report.
  5. Create a ZIP of the directory C:\ProgramData\Malwarebytes\Malwarebytes Anti-Ransomware\ and attach it to your post.
  6. Create another ZIP of the directoy C:\ProgramData\Malwarebytes\MBAMService\logs\ and attach it to your post.

 

There was no file in quarantine to restore. The software itself gives no indication where or what it found just that ransomware had been found alert. 

Link to post
Share on other sites

Using Win 7 Pro. Had windows update today. On reboot, Ransomware popup said it had stopped an infection & quarantined it. I looked in quarantine and no file was listed as quarantined - same as others experienced. I missed the filename but a Google search of what I remembered of it, a MS system file had a similar name - DISM.... .EXE.

 

I then ran anti-malware (threat scan), anti-rootkit & anti-junk scans, all reporting negative results.

 

Not sure what happened. I will write down popup msg next time.

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.