Solved

CryptoLocker Virus

Posted on 2013-11-12
4
488 Views
Last Modified: 2013-12-07
There are some great tools available to help fight .exe's using group policy, according to ThirdTier (thank you) I followed their writeup which .exe's to block in GP to prevent CryptoLocker from taking over data, which are:

Path: %AppData%\*.exe
Path: %AppData%\*\*.exe
Path: %Temp%\Rar*\*.exe
Path: %Temp%\7z*\*.exe
Path: %Temp%\wz*\*.exe
Path: %Temp%\*.zip\*.exe

My question, I have allot of users using 3rd party apps, what is the best way to allow certain .exe's from executing without running risk of CryptoLocker or other .exe's that are hazardous.
0
Comment
Question by:WORKS2011
4 Comments
 
LVL 56

Accepted Solution

by:
Cliff Galiher earned 350 total points
Comment Utility
If you read all the stuff that comes with the Third Tier paper, the idea there is that it blocks all all executables in certain locations. Locations where executables wouldn't normally run anyways, such as from places where mail clients save attachments or web browsers store info.

Legitimate 3rd party programs usually install into the "program files" directory and in ciata/win7/win8, standard users don't have write access to this folder, so it is much more do it is to get socially engineered into launching fake code.

If you follow the third tier guidance, including not letting every user be an administrator, legit programs will work fine because they will exist in a path not listed above. This just blocks the "suspicious" locations where code would never normally run from.
0
 
LVL 14

Assisted Solution

by:Ram Balachandran
Ram Balachandran earned 100 total points
Comment Utility
You can restrict access to application from execution using Software Restriction Policies
You select a path and deny access or select an application and much more

Have a look  - http://technet.microsoft.com/en-us/magazine/2008.06.srp.aspx
0
 
LVL 53

Assisted Solution

by:McKnife
McKnife earned 50 total points
Comment Utility
+1 for cgaliher. In addition: applocker offers logging. When blocking, it produces certain events in its own log. Since we can attach tasks to events (even deploy those tasks using group policy preferences), you can setup mails whenever anything is blocked. Not only interesting for cryptolocker awareness but more for applocker false-positives.
0
 
LVL 17

Author Comment

by:WORKS2011
Comment Utility
Thank you for the great feedback, love EE!!! Specifically Spotify (yeah I know it's not business but I like to keep my clients happy) won't launch on several computers. I don't believe it installs itself in the Program Files folder rather it launches each time connects to the internet then closes out (uninstalls) after closing.
0

Featured Post

Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

Join & Write a Comment

In this article, we will see the basic design consideration while designing a Multi-tenant web application in a simple manner. Though, many frameworks are available in the market to develop a multi - tenant application, but do they provide data, cod…
By this time the large percentage of day-to-day transactions have shifted to mobile banking; here are some overriding areas QAs must investigate while testing mobile banking apps.  
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now