Hi Pondus,

That added detection is this Trojan-Ransom.Win32.Foreign.fgni?

polonus