webdandy #1 Posted September 9 Hi, Recently read https://www.bleepingcomputer.com/news/security/fake-paypal-site-spreads-nemty-ransomware/ which details info on a fake Paypal site and the Nemty Ransomware. The article says "Fortunately, the malicious executable is detected by most popular antivirus products on the market. A scan on VirusTotal shows that it is detected by 36 out of 68 antivirus engine." however based on the Virus Total scan it looks like MB doesn't detect the ransomware. Can you advise if this is the case or if MB does in fact detect Nemty? Elaine Share this post Link to post Share on other sites
Malwarebytes #2 Posted September 9 ***This is an automated reply*** Hi, Thanks for posting in the Malwarebytes 3 Help forum. If you are having technical issues with our Windows product, please do the following: Spoiler If you haven’t already done so, please run the Malwarebytes Support Tool and then attach the logs in your next reply: NOTE: The tools and the information obtained is safe and not harmful to your privacy or your computer, please allow the programs to run if blocked by your system. Download Malwarebytes Support Tool Once the file is downloaded, open your Downloads folder/location of the downloaded file Double-click mb-support-X.X.X.XXXX.exe to run the program You may be prompted by User Account Control (UAC) to allow changes to be made to your computer. Click Yes to consent. Place a checkmark next to Accept License Agreement and click Next You will be presented with a page stating, "Get Started!" Click the Advanced tab on the left column Click the Gather Logs button A progress bar will appear and the program will proceed with getting logs from your computer Upon completion, click a file named mbst-grab-results.zip will be saved to your Desktop. Click OK Please attach the file in your next reply. Before submitting your reply, be sure to enable "Notify me of replies" like so: Click "Reveal Hidden Contents" below for details on how to attach a file: Spoiler To save attachments, please click the link as shown below. You can click and drag the files to this bar or you can click the choose files, then browse to where your files are located, select them and click the Open button. One of our experts will be able to assist you shortly. If you are having licensing issues, please do the following: Spoiler For any of these issues: Renewals Refunds (including double billing) Cancellations Update Billing Info Multiple Transactions Consumer Purchases Transaction Receipt Please contact our support team at https://support.malwarebytes.com/community/consumer/pages/contact-us to get help If you need help looking up your license details, please head here: https://support.malwarebytes.com/docs/DOC-1264 Thanks in advance for your patience. -The Malwarebytes Forum Team Share this post Link to post Share on other sites
SPDIF #3 Posted September 9 If the ransomware protection is on in Malwarebytes Premium, it will protect against ransom as it looks for suspicious activity and block it. Hence a real detection is not needed in this case. Also your browser will firstly already warn you that this site is dangerous! So this also means that user behind the keyboard, totally has to be ignore this warning!! Doing so is at your own risk. If you go ahead anyway and even click the download button, Malwarebytes will see suspicious activity and block this ransom. Also keep in mind that Virustotal is not always 100% accurate. Further you posted in the wrong section, here you talk about problems and support with Malwarebytes. Share this post Link to post Share on other sites
webdandy #4 Posted September 9 Apologies if this was the wrong section. For future ref where would this type of query be best to post? Share this post Link to post Share on other sites
SPDIF #5 Posted September 9 In this section there are specialists that can help you further with this. newest-rogue-ransomware-threats/ Share this post Link to post Share on other sites
webdandy #6 Posted September 9 Thanks. I've taken a note of the section. Share this post Link to post Share on other sites