4 ms·
Don't do that, that's crazy. If you don't want your users running random binaries turn on applocker: http://technet.microsoft.com/en-us/library/dd723683(v=ws.10
by bcoates 13y ago
Don't do that, that's crazy. If you don't want your users running random binaries turn on applocker: http://technet.microsoft.com/en-us/library/dd723683(v=ws.10).aspx http://technet.microsoft.com/en-us/library/dd723683(v=ws.10)...
If the "1002.exe" sample on Reddit is accurate the installer is unsigned, so forbidding unsigned binaries should be sufficient. The number of legitimate unsigned Windows binaries is small enough that you should be able to whitelist them by hand.
- ary 13y agoAppLocker can't be enforced on Windows 7 Professional (or lower). In my case that was a deal breaker. http://technet.microsoft.com/en-us/library/ee424382.aspx http://technet.microsoft.com/en-us/library/ee424382.aspx That being said a very restrictive Software Restriction Policy as linked below would mitigate CryptoLocker as it exists today. It has worked well for me so far. http://www.mechbgon.com/srp/ http://www.mechbgon.com/srp/