#Q3, could not find other than this, Why not this result “Torjan:MSIL/Rozena.KAE!MTB” accepted ???
#Q3 . According to Windows Defender Antivirus, what is the name of the malware record reported for Sample2?
#Q3, could not find other than this, Why not this result “Torjan:MSIL/Rozena.KAE!MTB” accepted ???
#Q3 . According to Windows Defender Antivirus, what is the name of the malware record reported for Sample2?
Microsoft does change the way they designate malware from time to time. It’s possible the answer needs to be updated. I will check and get back to you.
Sample 2 is not Trojan:MSIL/Rozena.KAE!MTB
The answer I got from Defender matches the answer expected in the lab.
This is also what is happening to me.
Just to be clear, I am extracting sample2.zip and windows defender is giving me Trojan:MSIL/Rozena.KAE!MTB. I’ve done it twice just to make sure and it gave me this both times.
I am also having the exact issue and Defender has the name as Trojan:MSIL/Rozena.KAE!MTB. I tried doing the steps again, same result
I will add this as an accepted answer since multiple students are reporting the same thing.
Has anyone been able to find a solution to this?
I have the same problem.
Trojan:MSIL/Rozena.KAE!MTB should be an accepted answer now.
I don’t accept that answer
Try that answer one more time. I may have fat fingered something.
ready, I accept the answer, thank you
When checked with Defender sample 2 on my version is Ransom:Win32/StopCrypt.CRIS!BTB but the answer gets marked as wrong.
Hey there - can you try again in a fresh lab session? I just tested this lab and it seemed to work fine.
Yes I just retried it and it still showing interrupted action unexpected error
Hmmm - okay bear with me. Can you try one more time and do exactly this?
-Open the File Explorer, navigate to C:\Evil.
-Right-click the Sample1.zip file, select 7-Zip > Extract Here, then enter the password (Infected) to decompress the file.
-Right-click the resulting file (beginning 1a1c) and select Copy.
-Return to the C folder, then right-click anywhere and select Paste.
Does that work? If not, does copy/pasting the file to the Desktop work?
It says same thing for both error
Thanks - I’m not sure how this could be the issue, but we did just move this lab to our new backend a few days ago, so I just moving it back to the old one. Can you let me know if you get a different result?
Still showing the error