Antimalware - OUTLOOKE.EXE possible ransomware
Just started getting error message that OUTLOOK.EXE (unknown publisher) is trying to modify 39 files; mainly *.ost and *.pst.
Not sure if this is an error or OUTLOOK.EXE has been tampered with. Checking the files in the relevant directory it looks like a lot of them were installed yesterday. Checking the properties of the file it give Microsoft or the publisher and a certificate date of 25 July (or thereabouts).
Anyone else seeing this?
Ian


- Log in to post comments

Yes-- I just started seeing it as well. It happened yesterday, August 02 2017. I was in Outlook reading emails, and I just had opened a file and clicked "download images". (I have the automatic download of images turned off). I don't remember which option I chose at that point-- I think it was to block but then I thought better of it and didn't have the files recovered. This meant that outlook wouldn't restart and I had to manually rename about 18 files that had ".recovered" appended to them. It just happened again (August 03, 2017) -- same use case where I opened up an email and started to download the images. This time I clicked on "Remember my choice for this process" and Trust, because I think it's just a change in Outlook that's a false positive. This resulted in Outlook.exe being whitelisted. My version of Outlook is based on a subscription to Office 365 and is current.
-Steve
- Log in to post comments

I have also started getting messages from my AV software about Outlook and Excel (on a different system). Says that the certificate is invalid. Looks like a major stuff-up by Microsoft.
Ian
- Log in to post comments