CryptoLocker

Discussion in 'malware problems & news' started by DX2, Sep 10, 2013.

  1. TairikuOkami

    TairikuOkami Registered Member

    Joined:
    Oct 10, 2005
    Posts:
    3,440
    Location:
    Slovakia
    I have just found out, that UAC will not protect you against it unless your files are in a protected folder like ProgramFiles. I moved my backups accordingly. :)
     
  2. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    Can't you just change security permissions in folder properties?
     
  3. guest

    guest Guest

    This. :thumb:

    Although UAC still won't do much. Once you elevate a program it can do anything it wants.

    P.S.: There are some default folders which will give you error warnings when changing permissions in ACL, like "My Documents" for example. It's better to create a new folder, messing around with permissions setting, then once it's all set, move your files to that folder.
     
  4. TairikuOkami

    TairikuOkami Registered Member

    Joined:
    Oct 10, 2005
    Posts:
    3,440
    Location:
    Slovakia
    It is not as simple as it sounds. I have had my share of headaches due to changing permissions, never again. Anyway Windows will protect ProgramFiles until the last breath.
     
  5. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,107
    Location:
    UK
  6. aztony

    aztony Registered Member

    Joined:
    Sep 9, 2012
    Posts:
    737
    Location:
    The Valley Arizona
    Really disconcerting, the idea of having your system and data ripped from your control and held for ransom. Just added CryptoPrevent to my systems today. I also need to implement consistent and regular system backups.
     
  7. TheKid7

    TheKid7 Registered Member

    Joined:
    Jul 22, 2006
    Posts:
    3,576
  8. JRViejo

    JRViejo Super Moderator

    Joined:
    Jul 9, 2008
    Posts:
    98,062
    Location:
    U.S.A.
    Merged Threads to Continue Related Topic.
     
  9. TheKid7

    TheKid7 Registered Member

    Joined:
    Jul 22, 2006
    Posts:
    3,576
    There is also ShadowExplorer to aid in repairing damage caused by CryptoLocker:
    http://www.shadowexplorer.com/
     
  10. aztony

    aztony Registered Member

    Joined:
    Sep 9, 2012
    Posts:
    737
    Location:
    The Valley Arizona
  11. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
    Re: CryptoPrevent

    I tried CP but the test only said it was working with AppGuard on. With AG off the test failed..at least that is how i saw it..
     
  12. aztony

    aztony Registered Member

    Joined:
    Sep 9, 2012
    Posts:
    737
    Location:
    The Valley Arizona
    I installed it last Friday. On Monday nite I was about to reinstall Sandboxie, the installer would initialize but failed to open or run. No errors, or error messages showed on screen. However, in event viewer 'application', I saw an error which stated that sandboxie.exe was restricted by administrator because of a policy rule. I am admin of my system(s) and I made no such rule. I checked to determine if my AV, or firewall, had gone behind my back with some admin chores of their own. I found nothing, and disabling each one was no help. So I then tried to update my Firefox browser to v25. No go there either. Long story short, I discovered CryptoPrevent when 'block' is initiated institutes SRP policies that override the administrator's rights, and was blocking the installers for certain programs from running, until I undid the block.
     
  13. fax

    fax Registered Member

    Joined:
    May 30, 2005
    Posts:
    3,898
    Location:
    localhost
    Re: CryptoPrevent

    I would be careful applying this happily as it may break the installation or operation of software needing access to those parts of the system (and judging from the area been locked many security tools will be affected). ;)

    Better to use Brain 2.0 if you can...
     
  14. Reality

    Reality Registered Member

    Joined:
    Aug 25, 2013
    Posts:
    1,198
    When I first read this thread, the info from some of the links gave the file types that were affected and my understanding was that it wasn't system files like OS and programmes. Now it appears from a recent link programs are affected too. So the question is, is this thing morphing into something worse as time goes by?
     
  15. fax

    fax Registered Member

    Joined:
    May 30, 2005
    Posts:
    3,898
    Location:
    localhost
    There must be some confusion, the OS issues or program non functioning correctly are linked to a tool been developed to prevent the infections not the malware itself... :)
     
  16. Blueshoes

    Blueshoes Registered Member

    Joined:
    Feb 13, 2010
    Posts:
    226
    Business back ups won't mean much when they put a 3 week, 1 month, 2 month "timer" into it.
     
  17. tgell

    tgell Registered Member

    Joined:
    Nov 12, 2004
    Posts:
    1,097
    A poster at bleeping computer stated that a new variant erases all shadow copies.
     
  18. Dermot7

    Dermot7 Registered Member

    Joined:
    Dec 20, 2009
    Posts:
    3,430
    Location:
    Surrey, England.
    https://krebsonsecurity.com/2013/11/how-to-avoid-cryptolocker-ransomware/
     
  19. Reality

    Reality Registered Member

    Joined:
    Aug 25, 2013
    Posts:
    1,198
    Im aware that using the CryptoPrevent blocking tool can cause issues with some programmes opening but Im not talking about that, but the conflicting reports between computergeeksonline and other reports, 2 of which Ive listed here which dont list executables. (Bold emphasis mine)

     
  20. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,107
    Location:
    UK
  21. G1111

    G1111 Registered Member

    Joined:
    May 11, 2005
    Posts:
    2,294
    Location:
    USA
    Does Sandboxie or DefenseWall prevent the encryption of files by the Cryptolocker .exe?
     
  22. aztony

    aztony Registered Member

    Joined:
    Sep 9, 2012
    Posts:
    737
    Location:
    The Valley Arizona
    About 15 mins ago I went to foolishit.com to update CryptoPrevent to its latest release. Once on the website, the text on the webpage kept zooming from normal to fill the whole screen (which wreaked havoc with my eyes). When I scolled down to the end of the page and clicked on the link to download I ended up on Hitman Pro site. I closed that webpage and went back on CryptoPrevent page tried the download link again. I was again sent to another website of different utility. I glanced at my system tray and saw the icon for my AV showing it had shut down and I quickly killed IE in the task manager. Once off the site the AV icon returned to normal. I downloaded the update from majorgeeks instead, and I am now running a MBAM scan on the PC. Don't what that was all about but I thought I spread a word of caution.
     
  23. Reality

    Reality Registered Member

    Joined:
    Aug 25, 2013
    Posts:
    1,198
    Thanks Stapp. I couldn't remember what that site was but now Ive bookmarked it.

    Aztony that sounds weird. Wonder what that was all about.
     
  24. guest

    guest Guest

    I believe Sandboxie can be configured to block access to your file folders. Plus it should virtualize the files by default. No idea about DefenseWall. AppGuard seems to be able to block access as well, but I'm not 100% sure on that.
     
  25. TomAZ

    TomAZ Registered Member

    Joined:
    Feb 27, 2010
    Posts:
    1,131
    Location:
    USA
    I assume NVT ERP and AppGuard used together (both in Lockdown mode) would prevent this as well. Right?
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.