Elise

Emsisoft Employee
  • Content Count

    8306
  • Joined

  • Last visited

  • Days Won

    119

Elise last won the day on April 28

Elise had the most liked content!

Community Reputation

267 Excellent

About Elise

  • Rank
    Forum Veteran

Profile Information

  • Gender
    Female

Recent Profile Visitors

32715 profile views
  1. hello my pc is infected all the files and folders are encrypted plz help

    WhatsApp Image 2020-07-06 at 08.10.40.jpeg

    WhatsApp Image 2020-07-06 at 18.39.09.jpeg

    WhatsApp Image 2020-07-06 at 08.11.25.jpeg

  2. No idea, probably a slow update connection. You could try to check if the browser is up to date via Help > About Chrome in the menu.
  3. Does this happen after a restart (not standby) before you start the browser at all?
  4. According to their manual you can uninstall it from Apps & Features: http://h10032.www1.hp.com/ctg/Manual/c06379792
  5. This has not changed. The article also states clearly at the start:
  6. RDP attacks are not really new, please see also this article from 2017: https://blog.emsisoft.com/en/28622/rdp-brute-force-attack/ As for software, I would always try out a program to see if it suits your needs, in case of brute force protection its usually the user/administrator, and not the software that makes the difference.
  7. The short answer to that is: no. It can be broken by malware (as in: won't run) or blocked (a replacement is attempted but after a reboot the original bad file is back), but that is about it. That being said, malware doesn't need to manipulate it, if it can just circumvent it. If a system is infected and a replaced system file has sufficient permissions to fool Windows into thinking it is legitimate (this typically is rootkit-level), you can run SFC all you want and Windows will report everything is fine, while in fact you can have one or more infected system files. So running SFC is not a malware scan nor should it be used as such.
  8. I will test this a bit next week, in the mean time you may want to check what the alert was for, because I highly doubt it was for 7zip and rather for the malware file(s).
  9. It depends completely on how this script is executed; in a "normal" malware scenario it will be dropped or downloaded, which will lead it to be blocked.
  10. Unfortunately I can't access that topic. I have checked the files and I suspect the issue is with the powershell script (mal.ps1). A script like that one is usually the result of being dropped by other malware or ending up on the system using exploit code, which will be blocked. To simulate that correctly in a test you would need to find out what malware dropped this script and run that instead.
  11. Can you share the password as well?
  12. Thank you for your feedback. Could you please send us the samples that weren't blocked so we can check out why they were able to encrypt files?
  13. Generally speaking if you see (A) or (B) behind a detection name it is a signature detection. If it is not there and the detection is not from the Surf Protection (URLs), then it usually is a heuristics detection.
  14. Yes, always use only one antivirus with real-time protection on to avoid conflicts. Windows 10 is smart enough to allow only one AV to be turned on though, so if you'd like to try the Emsisoft Anti-Malware trial, you could install it and it would automatically disable Windows Defender. Likewise if your trial were to expire, it would automatically turn on Windows Defender again.
  15. Hello Peter, Good to hear everything went well. That box just is an offer to install the actual Emsisoft Anti-Malware program so the computer will be protected in real time. The emergency kit scanner only will scan a computer for malicious files, it doesn't offer any actual protection.