What's Microsoft doing about Cryptolocker?

rufford155

New member
Local time
3:18 PM
Messages
53
Why doesn't MS issue a patch or update to prevent Cryptolocker?
Couldn't they provide a permanent solution along the lines of CryptoPrevent?
Is the latter utility safe? - and any good?

Apologies if this is old hat, couldn't find thsi specific query anywhere.
 

My Computer

Computer Manufacturer/Model Number
Acer Aspire 7540
OS
Windows 7 Home Premium x64
Memory
3GB
According to Microsoft, their security software detects and removes this threat.

Trojan:Win32/Crilock.A

Virus:Win32/Crypto.C.dr

Presumably it's easier to update the signatures and heuristics for anti-malware software than to keep issuing patches or updates to an operating system.
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Sony Vaio VPCEB47GM Laptop
OS
Win 7 Pro 64-bit
CPU
Intel i5 2.4 Ghz
Memory
8GB DDR3
Graphics Card(s)
Intel HD 3000
Sound Card
IDT High Definition
Monitor(s) Displays
15.6 WGXA Anti-Glare LED
Screen Resolution
1280x800
Hard Drives
640Gb 7200rpm
Antivirus
MSE
Browser
Opera (primary) with IE9 backup
Detecting and removing the Crypto software after your computer is infected is too little, too late as your files will already have been encrypted. Cryptorevent is an attempt to prevent the infection in the first place which is what rufford18 is asking about.

As far as I know, CryptoPrevent is safe and recommended. I have it installed but can't say how effective it is. The best defense seems to be to have backups on drives that are not kept attached to your network.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built desktop, Dell G15 5511 Gaming laptop,MS Surface Pro 7 tablet
OS
W10 Pro desktop, W11 laptop, W11 Pro tablet (all 64-bit)
CPU
3.7Ghz 8700K i7, i7-11800H, i7-1065G7
Motherboard
ASUS TUF Z370-Pro Gaming in desktop
Memory
16G desktop, 16G laptop, 4G tablet
Graphics Card(s)
AMD Radeon RX580, RTX 3060, Intel Iris Plus
Sound Card
High Definition Audio (Built-in to mobo)
Monitor(s) Displays
Samsung U32J59 32" (2x), 15.6", 12"
Screen Resolution
3840x2160, 3840x2160, 1920x1080, 2160x1440
Hard Drives
500G SSD for OS; 2T, 10T & 15T HDDs for Data on Desktop, 1TB SSD laptop, 128G SSD tablet.
PSU
Corsair CX 750M
Case
Antec 100
Cooling
CM 212+
Keyboard
IBM Model M - used continuously since 1986
Mouse
Microsoft Pro IntelliMouse
Internet Speed
400M down 8M up
Antivirus
Windows Defender
Browser
FireFox
Other Info
Built my first computer (8Mhz 8088cpu, 640K RAM, 20MB HDD, 2 360K floppy drives) in 1985 and have been building them for myself, relatives and friends ever since.
Once it infects your pc though, no software could decrypt your files.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Vostro 400/Dell XPS 8700(Slightly Customized for me by Dell)/Toshiba Satellite T135
OS
Windows 7 Professional 32-bit/Windows 8 64-bit/Win7 Pro64-bit
CPU
Intel Core 2 Quad Q6600/Intel Core i7 4790/Intel Pentium
Memory
2GB/16GB/4GB
Graphics Card(s)
Intel G33/G31 Express(Vostro)/NVIDIA GeForce GTX 745(XPS)
Monitor(s) Displays
HP 2009m(Vostro)/ViewSonic VX2250wm-LED(XPS)
Screen Resolution
1600x900(Vostro)/1920x1080(XPS)
Hard Drives
Seagate ST3160815AS(Vostro)/Western Digital Blue(Satellite)
External:
Western Digital My Passport 0748
Samsung HM121HC
Keyboard
Dell L100)(Vostro)/Dell KB2133p(XPS)
Mouse
Dell M-UAV-DEL8(XPS)
Internet Speed
100 Mbit/s(Only when IPTV is plugged out)
Antivirus
Avast, Malwarebytes PRO
Browser
Internet Explorer 11
Other Info
Note: Names with slashes between two different parts mean that the left is my old desktop and the right is my old laptop and the middle is my new desktop.(Unless specified)
Ping is horrible for servers overseas in US and Europe.
New laptop:LG Gram(Not available in US) Processor:Intel Core i3 4th Gen Ultra Low Power RAM:4GB Hard Drive:SK Hynix OEM MSATA or M.2 Graphics:Intel HD
Detecting and removing the Crypto software after your computer is infected is too little, too late as your files will already have been encrypted. Cryptorevent is an attempt to prevent the infection in the first place which is what rufford18 is asking about.

As far as I know, CryptoPrevent is safe and recommended. I have it installed but can't say how effective it is. The best defense seems to be to have backups on drives that are not kept attached to your network.

Is this the one you are referring to : Download CryptoPrevent - MajorGeeks
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Lenovo Z710 #59400485
OS
Windows 8.1.1 64bit
CPU
i7-4700MQ
Memory
8.0GB PC3-12800 DDR3L SDRAM 1600 MHz
Graphics Card(s)
Intel® HD Graphics 4600
Sound Card
on-board
Monitor(s) Displays
17.3"
Screen Resolution
1920x1080
Hard Drives
1TB 5400 RPM;(OS,programs)



Hitachi, 1Tb external,(B'up)
PSU
4 Cell 41 Watt Hour Lithium-Ion
Case
Lenovo
Cooling
Air in, Air out.
Keyboard
Logitech - Y-UY95 - Illuminated
Mouse
M$ - Arc Touch
Internet Speed
59 Mb down / 25 Mb up
Antivirus
Defender
Browser
Firefox (newest)
Other Info
MBAM Pro, SAS Pro, Revo Pro.

Ext. HP 2311 Monitor
Microsoft? Don't know.

I don't know what Microsoft is doing about Cryptolocker but whatever they do the guys that created it will probably try to find a way around any solution that's put in place.

As far as I can work out you can create your own Group Policy rules to prevent executable files from running in the locations that Cryptolocker uses as shown in the link below.


Cryptolocker: How to avoid getting infected and what to do if you are.


The problem with that approach and the "Cryptoprevent" approach is that it can also prevent some legitimate apps from running. I suppose that for most users it's better to have protection in place although they'd need to understand how to whitelist apps that get blocked.

I've tried two approaches:

1). Used Bitdefender Anti-Crypto.

2). Used application whitelisting software that detects when an unsigned file attempts to run and can be set to prompt the user for action. Additionally if a signed file's signature is not in the list of trusted certificates a user can be asked to either block or allow execution.

So far method 2). has been the best solution for me.


 

Attachments

  • Application Whitelisting.jpg
    Application Whitelisting.jpg
    15.8 KB · Views: 74

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware
Detecting and removing the Crypto software after your computer is infected is too little, too late as your files will already have been encrypted. Cryptorevent is an attempt to prevent the infection in the first place which is what rufford18 is asking about.

As far as I know, CryptoPrevent is safe and recommended. I have it installed but can't say how effective it is. The best defense seems to be to have backups on drives that are not kept attached to your network.

Is this the one you are referring to : Download CryptoPrevent - MajorGeeks
Yes, that's CryptoPrevent
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built desktop, Dell G15 5511 Gaming laptop,MS Surface Pro 7 tablet
OS
W10 Pro desktop, W11 laptop, W11 Pro tablet (all 64-bit)
CPU
3.7Ghz 8700K i7, i7-11800H, i7-1065G7
Motherboard
ASUS TUF Z370-Pro Gaming in desktop
Memory
16G desktop, 16G laptop, 4G tablet
Graphics Card(s)
AMD Radeon RX580, RTX 3060, Intel Iris Plus
Sound Card
High Definition Audio (Built-in to mobo)
Monitor(s) Displays
Samsung U32J59 32" (2x), 15.6", 12"
Screen Resolution
3840x2160, 3840x2160, 1920x1080, 2160x1440
Hard Drives
500G SSD for OS; 2T, 10T & 15T HDDs for Data on Desktop, 1TB SSD laptop, 128G SSD tablet.
PSU
Corsair CX 750M
Case
Antec 100
Cooling
CM 212+
Keyboard
IBM Model M - used continuously since 1986
Mouse
Microsoft Pro IntelliMouse
Internet Speed
400M down 8M up
Antivirus
Windows Defender
Browser
FireFox
Other Info
Built my first computer (8Mhz 8088cpu, 640K RAM, 20MB HDD, 2 360K floppy drives) in 1985 and have been building them for myself, relatives and friends ever since.
Im not sure what you are asking Microsoft to do. There is no security vulnerability in Windows that is being exploited, no holes to patch. Cryptolocker is merely an application that does something awful. But nothing a patch or update is going to solve. Unless you disable applications running all togeather.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware Aurora ALX R4
OS
Windows 10 Pro (x64)
CPU
Intel Core i7-3930K (3.2GHz - 4.5GHz)
Motherboard
Alienware Aurora-R4 x79
Memory
4x Samsung 4GB PC3-12800 DDR3 (16GB 1600MHz)
Graphics Card(s)
Nvidia Geforce GTX 690
Sound Card
SteelSeries Siberia Elite
Monitor(s) Displays
Dell UltraSharp U3011
Screen Resolution
2560x1600
Hard Drives
Samsung 850 Pro 256 GB, Seagate 1TB Desktop Hybrid HDD, 2x Western Digital 4TB Green HDD
PSU
875W Some Dell PSU <.<
Case
Alienware Aurora ALX
Cooling
Custom Liquid Cooling (EK CPU & GPU blocks) dual EK 480RAD
Keyboard
Logitech G710+ Mechanical
Mouse
Logitech G700s
Internet Speed
Verizon Fios (50 mbps average)
Other Info
Server: Intel NUC D54250WYK: i5-4250U, 16GB, 256 GB mSATA, Windows Server 2012 R2
Thanks

Thanks for all replies.
Sorry I've been away awhile.
Found some other useful thread on here too.
 

My Computer

Computer Manufacturer/Model Number
Acer Aspire 7540
OS
Windows 7 Home Premium x64
Memory
3GB
Microsoft could just block cryptolocker-like files from running.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Vostro 400/Dell XPS 8700(Slightly Customized for me by Dell)/Toshiba Satellite T135
OS
Windows 7 Professional 32-bit/Windows 8 64-bit/Win7 Pro64-bit
CPU
Intel Core 2 Quad Q6600/Intel Core i7 4790/Intel Pentium
Memory
2GB/16GB/4GB
Graphics Card(s)
Intel G33/G31 Express(Vostro)/NVIDIA GeForce GTX 745(XPS)
Monitor(s) Displays
HP 2009m(Vostro)/ViewSonic VX2250wm-LED(XPS)
Screen Resolution
1600x900(Vostro)/1920x1080(XPS)
Hard Drives
Seagate ST3160815AS(Vostro)/Western Digital Blue(Satellite)
External:
Western Digital My Passport 0748
Samsung HM121HC
Keyboard
Dell L100)(Vostro)/Dell KB2133p(XPS)
Mouse
Dell M-UAV-DEL8(XPS)
Internet Speed
100 Mbit/s(Only when IPTV is plugged out)
Antivirus
Avast, Malwarebytes PRO
Browser
Internet Explorer 11
Other Info
Note: Names with slashes between two different parts mean that the left is my old desktop and the right is my old laptop and the middle is my new desktop.(Unless specified)
Ping is horrible for servers overseas in US and Europe.
New laptop:LG Gram(Not available in US) Processor:Intel Core i3 4th Gen Ultra Low Power RAM:4GB Hard Drive:SK Hynix OEM MSATA or M.2 Graphics:Intel HD

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
They could implement the software previously mentioned into Windows.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Vostro 400/Dell XPS 8700(Slightly Customized for me by Dell)/Toshiba Satellite T135
OS
Windows 7 Professional 32-bit/Windows 8 64-bit/Win7 Pro64-bit
CPU
Intel Core 2 Quad Q6600/Intel Core i7 4790/Intel Pentium
Memory
2GB/16GB/4GB
Graphics Card(s)
Intel G33/G31 Express(Vostro)/NVIDIA GeForce GTX 745(XPS)
Monitor(s) Displays
HP 2009m(Vostro)/ViewSonic VX2250wm-LED(XPS)
Screen Resolution
1600x900(Vostro)/1920x1080(XPS)
Hard Drives
Seagate ST3160815AS(Vostro)/Western Digital Blue(Satellite)
External:
Western Digital My Passport 0748
Samsung HM121HC
Keyboard
Dell L100)(Vostro)/Dell KB2133p(XPS)
Mouse
Dell M-UAV-DEL8(XPS)
Internet Speed
100 Mbit/s(Only when IPTV is plugged out)
Antivirus
Avast, Malwarebytes PRO
Browser
Internet Explorer 11
Other Info
Note: Names with slashes between two different parts mean that the left is my old desktop and the right is my old laptop and the middle is my new desktop.(Unless specified)
Ping is horrible for servers overseas in US and Europe.
New laptop:LG Gram(Not available in US) Processor:Intel Core i3 4th Gen Ultra Low Power RAM:4GB Hard Drive:SK Hynix OEM MSATA or M.2 Graphics:Intel HD

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Then how does Bit defender Anti-Crypto work?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Vostro 400/Dell XPS 8700(Slightly Customized for me by Dell)/Toshiba Satellite T135
OS
Windows 7 Professional 32-bit/Windows 8 64-bit/Win7 Pro64-bit
CPU
Intel Core 2 Quad Q6600/Intel Core i7 4790/Intel Pentium
Memory
2GB/16GB/4GB
Graphics Card(s)
Intel G33/G31 Express(Vostro)/NVIDIA GeForce GTX 745(XPS)
Monitor(s) Displays
HP 2009m(Vostro)/ViewSonic VX2250wm-LED(XPS)
Screen Resolution
1600x900(Vostro)/1920x1080(XPS)
Hard Drives
Seagate ST3160815AS(Vostro)/Western Digital Blue(Satellite)
External:
Western Digital My Passport 0748
Samsung HM121HC
Keyboard
Dell L100)(Vostro)/Dell KB2133p(XPS)
Mouse
Dell M-UAV-DEL8(XPS)
Internet Speed
100 Mbit/s(Only when IPTV is plugged out)
Antivirus
Avast, Malwarebytes PRO
Browser
Internet Explorer 11
Other Info
Note: Names with slashes between two different parts mean that the left is my old desktop and the right is my old laptop and the middle is my new desktop.(Unless specified)
Ping is horrible for servers overseas in US and Europe.
New laptop:LG Gram(Not available in US) Processor:Intel Core i3 4th Gen Ultra Low Power RAM:4GB Hard Drive:SK Hynix OEM MSATA or M.2 Graphics:Intel HD
Rudolph : Its a 3rd party application. Windows is an operating system. For obvious reasons you can't merge the two.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
How does it work?

Then how does Bit defender Anti-Crypto work?

As far as I can work out it needs to prevent executables from running under the following path:

%AppData%\*.exe

Plus various other paths listed in the article below.

If Microsoft chose to implement the same method to prevent infection the problem is is that there are actually some legitimate applications that might run an executable file from that location and it would require the user to have the knowledge needed to add specific applications to an exclusion list. That's too complicated for many people to understand.

Steps needed to prevent infection:

Cryptolocker: How to avoid getting infected and what to do if you are - Computerworld

As you can see - any unsigned executable needs to be blocked as Cryptolocker file names are randomly generated.
 
Last edited:

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware
Rudolph : Its a 3rd party application. Windows is an operating system. For obvious reasons you can't merge the two.

Well I guess that's true.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Vostro 400/Dell XPS 8700(Slightly Customized for me by Dell)/Toshiba Satellite T135
OS
Windows 7 Professional 32-bit/Windows 8 64-bit/Win7 Pro64-bit
CPU
Intel Core 2 Quad Q6600/Intel Core i7 4790/Intel Pentium
Memory
2GB/16GB/4GB
Graphics Card(s)
Intel G33/G31 Express(Vostro)/NVIDIA GeForce GTX 745(XPS)
Monitor(s) Displays
HP 2009m(Vostro)/ViewSonic VX2250wm-LED(XPS)
Screen Resolution
1600x900(Vostro)/1920x1080(XPS)
Hard Drives
Seagate ST3160815AS(Vostro)/Western Digital Blue(Satellite)
External:
Western Digital My Passport 0748
Samsung HM121HC
Keyboard
Dell L100)(Vostro)/Dell KB2133p(XPS)
Mouse
Dell M-UAV-DEL8(XPS)
Internet Speed
100 Mbit/s(Only when IPTV is plugged out)
Antivirus
Avast, Malwarebytes PRO
Browser
Internet Explorer 11
Other Info
Note: Names with slashes between two different parts mean that the left is my old desktop and the right is my old laptop and the middle is my new desktop.(Unless specified)
Ping is horrible for servers overseas in US and Europe.
New laptop:LG Gram(Not available in US) Processor:Intel Core i3 4th Gen Ultra Low Power RAM:4GB Hard Drive:SK Hynix OEM MSATA or M.2 Graphics:Intel HD
Back
Top