AS in the image Avast was working well until tonight, in the morning, Avast appears turned off, and all the files encrypted by MKP ransomware, avast and protection are fully activated, Windows 10 with the latest backups, and firewall up and running, only me uses the computer, and this computer only has IIS and Sql server. por 80 and 443, 1433 permitted with a public IP
Hello mg444, sorry to see that happens.
I don’t know what happened but my wild guess is, as the directory owner shows “DefaultAppPool”; i.e. IIS, attacks coming through something via your web application. Ransomware shield in smart mode which is default one allows known applications from writing into protected directories.