Skip to main content

Antimalware - OUTLOOKE.EXE possible ransomware

Thread needs solution

Just started getting error message that OUTLOOK.EXE (unknown publisher) is trying to modify 39 files; mainly *.ost and *.pst.

Not sure if this is an error or OUTLOOK.EXE has been tampered with. Checking the files in the relevant directory it looks like a lot of them were installed yesterday. Checking the properties of the file it give Microsoft or the publisher and a certificate date of 25 July (or thereabouts).

Anyone else seeing this?

Ian

0 Users found this helpful

Sorry can't help here Ian as I do not use Outlook and haven't done so for many years.

Yes-- I just started seeing it as well.  It happened yesterday, August 02 2017. I was in Outlook reading emails, and I just had opened a file and clicked "download images". (I have the automatic download of images turned off).    I don't remember which option I chose at that point-- I think it was to block but then I thought better of it and didn't have the files recovered.  This meant that outlook wouldn't restart and I had to manually rename about 18 files that had ".recovered" appended to them.  It just happened again (August 03, 2017) -- same use case where I opened up an email and started to download the images.  This time I clicked  on "Remember my choice for this process" and Trust, because I think it's just a change in Outlook that's a false positive.   This resulted in Outlook.exe being whitelisted.  My version of Outlook is based on a subscription to Office 365 and is current.

 

-Steve

I have also started getting messages from my AV software about Outlook and Excel (on a different system). Says that the certificate is invalid. Looks like a major stuff-up by Microsoft.

 

Ian