Very interesting, thanks for sharing! So the common Cryptos don't touch Virtual Drives, right?
And yes,
@upnorth is right with UAC
To my experience, this UAC (because of deletion of Shadow Copies) popped up again and again if not accepted, just kill the malicious process and you should be fine.