I feel I'm doing this correctly. I ran a scan and it lists the MD5 of the file(s) it sees. I choose the MD5 for the file I want to block or allow.
In this case I have 'ninja loader.exe' that kicks on at startup. It also appears to spawn chrome.exe multiple times as elevated.
The scan shows MD5 C57DB0EE407DE704004A48B93B3B58C3 for ninja loader.exe - adding this to the global list as 'bad' does nothing new.
I have now added 110 various files to the global bad list. I 'updated' the configuration on the client (set to a 15 min interval) and ran a full scan.
Same thing.
This is on a test VM, Windows 7 Pro SP1, no update or patches. I went to cnet and just started clicking on the adverts and installing whatever came up.
Thoughts or direction?
thanks,
John
Reply
Login to the community
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.