I wish Sophos would do it like Kaspersky does:
blog.kaspersky.com/.../
To help with the zero day aspect it simply just looks for files that are being encrypted. while they are being encrypted it's caching the previous version of the file. At that point it asks if you want this actin to continue, select no, and it returns the files to their previous state:
blog.kaspersky.com/.../
I wish Sophos would do it like Kaspersky does:
blog.kaspersky.com/.../
To help with the zero day aspect it simply just looks for files that are being encrypted. while they are being encrypted it's caching the previous version of the file. At that point it asks if you want this actin to continue, select no, and it returns the files to their previous state:
blog.kaspersky.com/.../