Hello, everyone… I knew that Defense+ can block the attempts to modify MBR of hard disk when using the wildcards such as “\Device\Harddisk0\DR0”. My concern is whether it can still identify or block the attempts to initiate a format process.
So I use the context menu of explorer to initiate the Quick Format, and Defense + does identify the modification attempt of explorer to X:(under VMWARE environment, of course).
However, Defense+ did nothing when I use the context menu of explorer to initiate the Format process to X:, and format process successfully begins!
I think it will be better if Defense+ can monitor such format attempts at the installation mode.