12/15/2015 a False Positive with the new Ransomware Vaccine nuked Office 2013 version 15.0.4875.1001, rendering it inoperable without a full online repair. The victim is the file below:
c:\program files\microsoft office 15\root\vfs\programfilescommonx86\microsoft shared\office15\1033\msointl.dll
The signature that fired was Generic.Ransom.HiddenTear for the paticular DLL. File was last changed 9/20/2016 as installed, and was at version 15.0.4869.1000 which didn’t seem to have moved for a few months.
If you were unlucky enough to have that product combination, you may have had an issue. It’s always good to white list these locations, and check the Quarantine if you suspect an accidental infection. In this case, the configured events on the system did not notify of Malware Outbreak, even with the threshold ticked to 1%.