The infection was with Kaspersky disabled, and once system was infected, was enabled, the sample it was already detected by KSN as You can see at the beggining of the video...
Many ransomwares once they attacked the system don't keep active running, others even auto deleted, so You only get the encrypted documents/files and some harmless txt/html files with info to pay/decrypt them...