- Local time
- 8:35 AM
- Messages
- 8,138
Brds7t7,
I only checked one test image file. I was able to open it after the ransomware was quarantined. Sometimes, a "non ransom note" file would be created in the same folder as the test image. I could not open or copy that file. It was in use by another program. I don't know if this was the start of the encryption process or not.
I repeated the test 5 or 6 times (deleting the ransom notes between tests). Twice, MBARW did not ask for a reboot to clear the malware. Perhaps MBARW caught the ransomware early on during those two tests.
The number of ransom notes to cleanup varied from a low of about 800 to a high of about 1200. I guess that this means the malware did something worthy of being quarantined at different times.
I only checked one test image file. I was able to open it after the ransomware was quarantined. Sometimes, a "non ransom note" file would be created in the same folder as the test image. I could not open or copy that file. It was in use by another program. I don't know if this was the start of the encryption process or not.
I repeated the test 5 or 6 times (deleting the ransom notes between tests). Twice, MBARW did not ask for a reboot to clear the malware. Perhaps MBARW caught the ransomware early on during those two tests.
The number of ransom notes to cleanup varied from a low of about 800 to a high of about 1200. I guess that this means the malware did something worthy of being quarantined at different times.
My Computer
- Computer type
- Laptop
- Computer Manufacturer/Model Number
- Employer provided Dell Latitude
- OS
- W7 Pro SP1 64bit
- CPU
- i7
- Memory
- 8GB
- Graphics Card(s)
- Intel HD Graphics
- Hard Drives
- crappy SSD
- Antivirus
- Employer mandated Symantec Endpoint Protection
- Browser
- Pale Moon 64bit, IE11 64bit & Chrome 64bit