I suppose if the detection of elevated privileges was disabled in Containment settings, the setup/ransomware would be automatically contained (with a notification saying so) and then get detected/quarantined by VirusScope (which can also be automated in VirusScope settings).

That would be a seamless way of doing it. ;D

Viroscope did not detect it … Viroscope failed t.t

The common people do not occupy the sandbox …