Thank you. It’s good to see an important step taken with the development of recognizers. I hope 2017 will be the year of further development of recognizers.
You set an exclusion so that files in “Downloads” folder are not virtualized, so it’s pretty clear why they can be encrypted…
In the video I can’t see it, but I guess your configuration was Internet Security. It would be interested to do the same with Proactive Security Configuration.
The two main competitors of CIS have exactly the same problem. It seems there is an indiscriminate permission of the files of the system, which ends up allowing the success of trojancrypt. Example: svchost-explorer, svchost-dllhost, svchost-rundll32, “wscript” -cmd, System-conhost-cmd, system-text-image files and video … :-TD
It seems that if there are some intensive disk operations (or for example downloading and installing new Unreal Engine 4.14) that new Viruscope plugin can eat up one core (or thread) of CPU with cmdagent.exe process. They only solution is to turn either Viruscope or the module off for the time being
Also I noticed WHEA thread on System module (using Process Hacker 3) which I believe was also connected to this issue (it caused quite a stuttering on i7 4771 CPU). But this happened only once. Cmdagent.exe eating one core/thread happens much more often.
Could you look into that?
I include actual config of CIS, but I discourage any normal user to use that one