  1. Hello! I sympathize with you. Are you sure that your Emsisoft antivirus  at the time of the attack was updated and functioned normally? If possible, tell us in more detail, under what circumstances an unauthorized process of encryption occurred? I think this will be interesting to many users.

  GT500 said:

    At least not for the compromised version of CCleaner (there were no other infected files associated with it, only the copy of ccleaner.exe that had the malicious code in it)

    Yes, there were probably no associated infected files. But the changes in the Internet settings Floxif probably produces. In the screenshot, the result of testing by a known scanner after infection by this trojan.



