'R2D2' stops disk-wipe malware before it executes evil commands

This doesn't seem to do much against encrypting malware though - ultimately there's no way to know what counts as "destructive", any write operation destroys _something_. Unless you're prepared to use an infinitely versioning file system that preserves anything and everything ever written (yeah good luck with your storage medium capacity) the only viable solution I see is lots of decoy files, monitored by a watchdog that immediately trips and alerts as soon as any of them is written. It would still be an arms race about obscuring vs. detecting which files are the "trap" ones of course...

