What's Microsoft doing about Cryptolocker?

Page 1 of 2 12 LastLast

  1. Posts : 53
    Windows 7 Home Premium x64
       #1

    What's Microsoft doing about Cryptolocker?


    Why doesn't MS issue a patch or update to prevent Cryptolocker?
    Couldn't they provide a permanent solution along the lines of CryptoPrevent?
    Is the latter utility safe? - and any good?

    Apologies if this is old hat, couldn't find thsi specific query anywhere.
      My Computer


  2. Posts : 10,994
    Win 7 Pro 64-bit
       #2

    According to Microsoft, their security software detects and removes this threat.

    Trojan:Win32/Crilock.A

    Virus:Win32/Crypto.C.dr

    Presumably it's easier to update the signatures and heuristics for anti-malware software than to keep issuing patches or updates to an operating system.
      My Computer


  3. Posts : 3,371
    W10 Pro desktop, W11 laptop, W11 Pro tablet (all 64-bit)
       #3

    Detecting and removing the Crypto software after your computer is infected is too little, too late as your files will already have been encrypted. Cryptorevent is an attempt to prevent the infection in the first place which is what rufford18 is asking about.

    As far as I know, CryptoPrevent is safe and recommended. I have it installed but can't say how effective it is. The best defense seems to be to have backups on drives that are not kept attached to your network.
      My Computer


  4. Posts : 2,409
    Windows 7 Professional 32-bit/Windows 8 64-bit/Win7 Pro64-bit
       #4

    Once it infects your pc though, no software could decrypt your files.
      My Computer


  5. Posts : 1,568
    Windows 8.1.1 64bit
       #5

    strollin said:
    Detecting and removing the Crypto software after your computer is infected is too little, too late as your files will already have been encrypted. Cryptorevent is an attempt to prevent the infection in the first place which is what rufford18 is asking about.

    As far as I know, CryptoPrevent is safe and recommended. I have it installed but can't say how effective it is. The best defense seems to be to have backups on drives that are not kept attached to your network.
    Is this the one you are referring to : Download CryptoPrevent - MajorGeeks
      My Computer


  6. Posts : 4,776
    Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
       #6

    Microsoft? Don't know.


    I don't know what Microsoft is doing about Cryptolocker but whatever they do the guys that created it will probably try to find a way around any solution that's put in place.

    As far as I can work out you can create your own Group Policy rules to prevent executable files from running in the locations that Cryptolocker uses as shown in the link below.


    Cryptolocker: How to avoid getting infected and what to do if you are.


    The problem with that approach and the "Cryptoprevent" approach is that it can also prevent some legitimate apps from running. I suppose that for most users it's better to have protection in place although they'd need to understand how to whitelist apps that get blocked.

    I've tried two approaches:

    1). Used Bitdefender Anti-Crypto.

    2). Used application whitelisting software that detects when an unsigned file attempts to run and can be set to prompt the user for action. Additionally if a signed file's signature is not in the list of trusted certificates a user can be asked to either block or allow execution.

    So far method 2). has been the best solution for me.


    Attached Thumbnails Attached Thumbnails What's Microsoft doing about Cryptolocker?-application-whitelisting.jpg  
      My Computer


  7. Posts : 3,371
    W10 Pro desktop, W11 laptop, W11 Pro tablet (all 64-bit)
       #7

    COMPUTIAC said:
    strollin said:
    Detecting and removing the Crypto software after your computer is infected is too little, too late as your files will already have been encrypted. Cryptorevent is an attempt to prevent the infection in the first place which is what rufford18 is asking about.

    As far as I know, CryptoPrevent is safe and recommended. I have it installed but can't say how effective it is. The best defense seems to be to have backups on drives that are not kept attached to your network.
    Is this the one you are referring to : Download CryptoPrevent - MajorGeeks
    Yes, that's CryptoPrevent
      My Computer


  8. Posts : 5,642
    Windows 10 Pro (x64)
       #8

    Im not sure what you are asking Microsoft to do. There is no security vulnerability in Windows that is being exploited, no holes to patch. Cryptolocker is merely an application that does something awful. But nothing a patch or update is going to solve. Unless you disable applications running all togeather.
      My Computer


  9. Posts : 53
    Windows 7 Home Premium x64
    Thread Starter
       #9

    Thanks


    Thanks for all replies.
    Sorry I've been away awhile.
    Found some other useful thread on here too.
      My Computer


  10. Posts : 2,409
    Windows 7 Professional 32-bit/Windows 8 64-bit/Win7 Pro64-bit
       #10

    Microsoft could just block cryptolocker-like files from running.
      My Computer


 
Page 1 of 2 12 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 18:28.
Find Us