QNova Client · On the device

Ransomware protection that stops the program before it asks you anything

Ransomware protection in QNova Client is one switch: protect my personal files from ransomware. It locks Documents, Pictures and Desktop against any program the agent does not recognise, plants decoy files in those folders that no legitimate program ever touches, and suspends a suspect process tree before the decision card reaches you.

What it is

One switch, two different things underneath it

The switch is in QNova Client, and it does two jobs most products sell separately.

Two jobs

It locks the folders

Documents, Pictures and Desktop stop accepting writes from any program the agent does not recognise. Reading still works, and only writing is refused.

It plants bait

Decoy files go into those same folders, invisible to the person working there, and no legitimate program has a reason to touch one. Ransomware does not browse a folder and choose. It walks it and takes everything, which is why bait catches it and almost nothing else.

One switch on the device, or the ransomware-shield rule in Company Policy enforced across the fleet. The folders go read only to unrecognised programs, and the decoys are planted in the same pass.

The mechanism

Where the refusal actually happens

Underneath the switch is a file system minifilter: a separate driver, deliberately isolated from the rest of the agent. Untrusted processes can read what is in a protected folder and cannot modify, overwrite, delete or rename anything in it. The denial sits in the file system path, so it does not wait for a scanner and does not depend on recognising the family.

A program Recognised by the agent Company Policy ransomware-shield File system minifilter Shield on Driver not loaded Read Allowed Write Allowed Refused modify, overwrite, delete, rename Protected folders Documents Pictures Desktop Decoy files In the same folders, and invisible Untouched Touched In order Detected on this thread Process tree suspended Decision card drawn Reading still works. Only writing is refused, and it is refused in the file system path.
Shield on. A recognised program writes, and the write goes through.

The diagram shows one program asking the protected folders for two things, reading and writing, with both requests passing through the same file system minifilter. Documents, Pictures and Desktop sit on the right, with the decoy files planted in the same folders. Company Policy reaches the minifilter through its own channel, carrying the ransomware-shield rule across the fleet. Press the recognised program and both requests go through. Press the unrecognised program and the reading path stays live while the writing path stops at the minifilter, refused in the file system path rather than after a scan. Press Touch a decoy and the verdict is already written, so the order underneath lights up in sequence: detected on this thread, process tree suspended, decision card drawn. Press Shield off and the driver is not loaded, the folders accept the write, and the service says so instead of reporting protection it is not giving.

Contain first, ask second is the principle the agent is built on. Suspension happens on the detecting thread: not after a queue, not after the event reaches a console, not after a person picks an option.

Why this exists

Four things that go wrong without it

The Saturday restoring a share from backup

The work that comes afterwards is the part nobody budgets for, and it is the part this removes. A run that gets stopped has no restore behind it.

Ringing round to find which laptop it started on

Without something that stops the run and records what did it, the first hour goes on finding the machine rather than on dealing with it.

A machine rebuilt because nobody could prove it was clean

Rebuilding is what happens when there is no record of what a program touched, which makes it a decision taken in the absence of evidence.

A prompt is a question, and a question stops nothing

During a conventional warning the encryption finishes while the dialog waits for somebody to get back from lunch. The dialog was never going to be the defence.

What you gain

The same switch, read by two different people

If you run the network

The work that comes afterwards stops existing

What this removes is the work that comes afterwards: the Saturday restoring a share from backup, the ringing round to find which laptop it started on, the machine rebuilt because nobody could prove it was clean.

A run that is stopped has none of that behind it. The tree is suspended, what it touched is recorded, and the morning after is a card to read rather than a week to plan.

If you sign for it

A wrong verdict is recoverable

A file judged malicious goes to quarantine, not deletion, so a wrong call is something you restore rather than something you explain.

And turning the shield off is a deliberate, auditable act rather than a click somebody makes to get a printer working, because the driver refuses to unload while a scanner is attached or folders are protected.

How it works

Three steps to a program that is already stopped

You turn it on, and the folders get locked and seeded

One switch on the device, or the ransomware-shield rule in Company Policy enforced across the fleet. The folders go read only to unrecognised programs, and the decoys are planted in the same pass.

Something starts renaming files faster than a person can

The behaviour engine watches for rename storms and bulk write storms, and says what it saw instead of showing a severity colour. Touch a decoy and the verdict is already written: a program tried to alter a decoy file.

You read a card about something that already stopped

The suspect process tree is suspended on the thread that detected it, before the card is drawn. That is an ordering difference, not a feature: during a conventional warning, the encryption finishes while the dialog waits for somebody to get back from lunch.

Before you start

You need QNova Client on the machine and the kernel drivers loaded, which the installer does. The shield itself ships off, so somebody turns the switch on or pushes the rule. Nothing else is installed before the first folder is locked.

In detail

What the switch turns on, layer by layer

Layers

What one switch actually turns on

The switch is one control, and underneath it are six things that are set in different places and fail in different ways:

  1. The folder shield. Documents, Pictures and Desktop go read only to unrecognised programs, from the device switch.
  2. The decoy files. Invisible bait in those same folders, planted with the switch, and a touch is the verdict.
  3. The minifilter driver. Blocks modify, overwrite, delete and rename in the file system path, and refuses to unload while it is in use.
  4. The behaviour engine. Rename storms and bulk write storms, reported literally, on with the engines.
  5. Verdict handling. Quarantine rather than deletion, so a wrong call is reversible. Listing what is held needs no privilege, restoring does.
  6. The fleet. The ransomware-shield rule in Company Policy, pushed to everybody at once.

The denial does not depend on recognising the family, which is why a name nobody has seen before gets the same answer as one everybody has.

Order

Contain first, ask second

The suspect process tree is suspended on the thread that detected it, before the decision card is drawn. Not after a queue, not after the event reaches a console, not after a person picks an option.

That ordering is what the rest of the page rests on. A warning that arrives first is a question, and the run continues while the question waits. A suspension that arrives first is a fact, and the card is a report on it.

The shield is a kernel driver, and Microsoft has authorised us to distribute kernel drivers. It is a separate driver from the rest of the agent, deliberately isolated, and it refuses to unload while a scanner is attached or folders are protected.

Ordering

The same program, and the order that decides it

Nothing about the program changes between these two. The only thing that changes is what happens first.

Before

The warning goes first

A program starts at 16:40. It renames, then writes, then renames. An alert is raised, a prompt appears, and the encryption runs through it all, because a prompt is a question and a question stops nothing.

After

The suspension goes first

Same program, same 16:40. It trips the rename storm or touches a decoy, the tree is suspended on the thread that caught it, and the card reaching that desk is about something already frozen. Your Friday ends when it was going to end.

Works better together

The rest of the same agent

Nothing here is a separate purchase. Each one is another part of the agent already on the machine, and each answers a question this page deliberately does not.

01

The agent the switch lives in. One signed agent on the machine, with the shield as one of the things it carries rather than a product of its own.

02

The eleven engines and the second kernel driver. This page tells the story of the folder shield, that one tells the story of everything else the agent watches.

03

Where the ransomware-shield rule is set for the fleet, so the switch is not something each person has to remember to turn on.

04

The whole argument in one place: one signed agent in place of several tools, on every device the company owns.

Every part of the agent is listed in one place, on features.

Proof and scope

What this rests on, and the four things it does not do

The console has a Threat Floor, which tracks organisations named on ransomware leak sites: 4,063 of them across 110 countries, read there on 16 September 2026. It crosses that with the public catalogue of actively exploited vulnerabilities, so you can see which of the ones ransomware groups use are on your own machines. That is context for deciding what to fix first, and it is the last thing on this page that is about anybody but you.

It is not a backup, and it does not decrypt

Files encrypted before the shield went on stay encrypted. It stops a run, it does not reverse one, and anything that claims otherwise is selling you a restore.

The folder shield ships off

Somebody turns it on, or pushes the rule. If the driver is not loaded, the service says so instead of reporting protection it is not giving.

Nobody here is watching your machines

No analyst of ours on a rota, no managed service. The product detects, contains and records, and your people read it.

This is the Windows implementation

Where platform coverage differs we say so by column, not with one tick across a row. The folder shield and the engines behind it are Windows today.

Questions people ask

The ones that come up first

What does the switch actually block?

Any program the agent does not recognise is stopped from modifying, overwriting, deleting or renaming files in Documents, Pictures and Desktop. Reading is still allowed, and the block sits in the file system path, not after a scan.

Will my colleagues see the decoy files?

No. They are invisible, and no legitimate program has a reason to open one, so anything that touches one has identified itself.

Can ransomware turn the shield off?

Not on its own. It has to get past a rule store only administrators can write to, and a driver that refuses to unload while a scanner is attached or folders are protected.

What happens when it gets a file wrong?

The file goes to quarantine and is not deleted, so you restore it. Containing first occasionally freezes something harmless, which costs a minute. The other order hands you an encryption run.

Is this the same thing as endpoint detection and response?

No. This is the folder shield and the decoys, which are one driver and one switch. The eleven engines and the second kernel driver are endpoint detection and response, and they run on the same agent.

See the switch turned on, on your own machines.

An engineer, a machine shaped like yours, and as long as you need. You watch a folder refuse a write, a decoy get touched, and a process tree stop before the card is drawn. It is free and there is nothing to sign.

Scroll to Top