6 ms·
You can work to prevent this by creating a group policy that disallows %AppData%\*.exe and %AppData%\*\*.exe A good discussion of this happened h
by blhack 13y ago
You can work to prevent this by creating a group policy that disallows
%AppData%\*.exe
and
%AppData%\*\*.exe
A good discussion of this happened here: http://www.reddit.com/r/sysadmin/comments/1mizfx/proper_care_feeding_of_your_cryptolocker/ http://www.reddit.com/r/sysadmin/comments/1mizfx/proper_care...
sidenote: this virus actually scares me, and it sounds like it actually scares most people who work in IT. This is the shittiest thing anybody has ever seen, it sounds like.
- mcphilip 13y agoIt actually made my skin crawl reading about it. Never had that reaction to such a story before. Interesting... Edit: It's the BTC aspect that's worrisome. Ransomeware is nothing new -- AIDS Information Trojan did it in 1989, but the (potentially) safe method of payments in crypto currency seem to be a new factor that will attract much more innovation in these type of attacks.
- deleted 13y ago[deleted]
- marcosdumay 13y agoI just though the exact opposite. When I read "Ransomware comes of age with ... anonymous payments." I just thought "Somebody is going for a surprise once he finds out how anonymous Bitcoin really is". Anyway, what really makes me nervous is Microsoft's insistence of executing any data that a their programs touch.
- hobs 13y agoI thought there were numerous laundering services?
- mr_luc 13y agoHere's one: https://blockchain.info/wallet/send-shared https://blockchain.info/wallet/send-shared (Please note, before downvoting, that I'm not saying that's a bad thing)
- james3 13y agothere is no downvoting
- hollerith 13y agoOn the contrary, after accumulating a certain amount of karma (500 points??) a user gains the ability to downvote comments (but not stories).
- elliottcarlson 13y agoAlso, downvoting is only available for a certain comment age. Once the comment is X hours old, you lose the ability to downvote, but can still upvote.
- linc01n 13y agoX should be 24 hours https://github.com/wting/hackernews/blob/master/news.arc#L1038 https://github.com/wting/hackernews/blob/master/news.arc#L10...
- james3 13y agothanks for the neg reps, really shows your attitude towards newcomers
- conductor 13y agoThis type of viruses are nothing new [0]. The only new thing in this case is that it demands BitCoins instead of an SMS to a premium number or something else. [0] - https://www.securelist.com/en/descriptions/old313444 https://www.securelist.com/en/descriptions/old313444
- dmix 13y agoaka "Ransomware" https://en.wikipedia.org/wiki/Ransomware_(malware) https://en.wikipedia.org/wiki/Ransomware_(malware) > The first known ransomware was the 1989 "PC Cyborg" trojan written by Joseph Popp
- shiftpgdn 13y agoWhat makes this special is the fact it uses real encryption instead of just a password protected zip file.
- crb 13y agoDoesn't Google Chrome run under %AppData% in a default (non-MSI) install? (This is how it's able to silently update itself, even when run as a non-administrator.)
- MartinCron 13y agoYes, I was able to install Google Chrome on a PC which the user didn't have administrative rights just yesterday. It delighted me to no end.
- lstamour 13y agoMy understanding is they changed that and by default it wants admin rights. Then if that fails, it asks if you want to continue without. (At least, this was my experience the last time I had to install Chrome on a machine without admin rights.)
- jrabone 13y agoAnd that's just as good an idea as executable data segments in a binary format (ie. not a very good idea). It's taken MS literally YEARS to get to half-decent default filesystem permissions in Windows 7 and this kind of thing just undermines it totally.
- derefr 13y agoWhat do you suggest instead? People who work at BigCorps and have shitty outdated IE installs are motivated to install alternative web browsers, even when they don't have administrative rights (and they almost never do.) Google is motivated to enable them to do so. The real problem, I think, is that Microsoft thinks requiring admin rights to write to "Program Files" is the be-all and end-all of solving the "application-environment integrity problem." That works for enterprise-wide deploys of sysadmin-supported software, but falls down for user-specific installations. On OSX, "application-environment integrity" can be enforced easily enough, since the OS delineates applications by a line called "the app bundle." OSX can (though I'm not sure it does) just disallow apps from writing into other apps' bundles without a "do you really mean it" prompt. But in Windows, the The Directory Is The Application Bundle[1], and so Windows doesn't know that this directory is special and should be protected from having other apps in other directories tinkering with it. [1] http://blogs.msdn.com/b/oldnewthing/archive/2011/06/20/10176772.aspx http://blogs.msdn.com/b/oldnewthing/archive/2011/06/20/10176...
- fekberg 13y agoHere's a command you can run to find out what executables exist in AppData: dir /S /P "%userprofile%\AppData\*.exe" > %userprofile%\Desktop\FoundFiles.txt
- m_myers 13y agoOr for PowerShell: dir -Path "$env:userprofile\AppData" -Filter *.exe -Recurse > "$env:userprofile\Desktop\FoundFiles.txt" Useful if your corporate security policy, like mine, has disabled the command prompt but left PowerShell intact.
- pjmlp 13y agoIt still wonders me the amount of IT folks unaware of Powershell.
- Silhouette 13y agoIt's helpful to add /A (shows .exe files even if they have hidden/system attributes set) and maybe /B (bare format, just the path/filenames without all the header/footer information).
- sfont 13y agoI tried implementing this solution and it has a lot of difficult side effects. Shortcuts on the task bar could not run (with the exception of Chrome oddly enough). If you select run in IE it fails because it saves to temp and some installers failed as well, again because of the use of temp. Unless the end user is very saavy or has an onsite IT this seems that the better solution is rotating backups. Alternating days to external hard drives that are then disconnected is the best mitigation. And having already had one client effected by this is does scare me. Interesting enough he paid and had his files decrypted in about 48 hours.
- shanselman 13y agoUnfortunately lots of stuff runs under there including, but not limited to: GitHub for Windows and dozens of apps it installs in there F.lux Anything installed with ClickOnce Chrome GMVault Xamarin's Android Support Markdownpad SkyDrive Join.me Assuming that everything in there is a virus is too much, I think.
- tracker1 13y agoI would think that .Net portable apps are likely also per user executables.. not to mention that there are usually at least one scripting environment even on windows cscript/jscript/vbscript/powershell for example, not to mention Java, Python, Ruby and/or node may be installed.
- FedRegister 13y agoClickOnce apps are as well. We get bit with this every day because our main desktop app is distributed through ClickOnce.
- sfont 13y agoI tried implementing this solution and it has a lot of difficult side effects. Shortcuts on the task bar could not run (with the exception of Chrome oddly enough). If you select run in IE it fails because it saves to temp and some installers failed as well, again because of the use of temp. Unless the end user is very saavy or has an onsite IT this seems that the better solution is rotating backups. Alternating days to external hard drives that are then disconnected is the best mitigation.
- bcoates 13y agoDon't do that, that's crazy. If you don't want your users running random binaries turn on applocker: http://technet.microsoft.com/en-us/library/dd723683(v=ws.10).aspx http://technet.microsoft.com/en-us/library/dd723683(v=ws.10)... If the "1002.exe" sample on Reddit is accurate the installer is unsigned, so forbidding unsigned binaries should be sufficient. The number of legitimate unsigned Windows binaries is small enough that you should be able to whitelist them by hand.
- ary 13y agoAppLocker can't be enforced on Windows 7 Professional (or lower). In my case that was a deal breaker. http://technet.microsoft.com/en-us/library/ee424382.aspx http://technet.microsoft.com/en-us/library/ee424382.aspx That being said a very restrictive Software Restriction Policy as linked below would mitigate CryptoLocker as it exists today. It has worked well for me so far. http://www.mechbgon.com/srp/ http://www.mechbgon.com/srp/