Skip to content

Archive

Category: Security

Cryptolocker: How to avoid getting infected and what to do if you are.

 The details are sorrid, but in a nutshell what happens is a crytolocker virus gets onto your computer, locks all your pertinent files and demands a ransom amount so you can get your files back. Those who pay the ones delivering the virus will become more bold and will start demanding more money.

What can you do to protect your company?
Create some Group Policies to lock down likely places for Malware / Spyware / Grayware / Cryptodefense and other likely .exe programs from running:

– Open up Group Policy and create new GPO
– Title this policy Disable .exe from %appdata% and click OK
– Right click on this policy and select Edit
– Navigate to Computer Configuration –> Policies –> Windows Settings –> Security Settings –> Software Restriction Policies
– Right click on Software Restriction Policies and click on ‘New Software Restriction Policies’
– Right click on Additional Rules and click on ‘New Path rule’ and then enter the following
information and then click OK

Path: %localAppData%\*.exe
Security Level: Disallowed
Description: Don’t allow executables from AppData (Win 7)

Path: %localAppData%\*\*.exe
Security Level: Disallowed
Description: Don’t allow executables from AppData subfolders (Win 7)

Path: %localAppData%\Temp\*.zip\*.exe
Security Level: Disallowed
Description: Prevent unarchived executables in email attachments from running in the user space (Win 7)

Path: %localAppData%\Temp\7z*\*.exe
Security Level: Disallowed
Description: Prevent 7zipped executables in email attachments from running in the user space (Win 7)

Path: %localAppData%\Temp\Rar*\*.exe
Security Level: Disallowed
Description: Prevent Rar executables in email attachments from running in the user space (Win 7)

Path: %localAppData%\Temp\wz*\*.exe
Security Level: Disallowed
Description: Prevent Winzip executables in email attachments from running in the user space (Win 7)

The following paths are for Windows XP machines (if you still have them; I put these in just in case with the same disallow security settings)
%AppData%\*.exe
%AppData%*\*\*.exe

Create your new path rules as seen above

 

As per my explore in the Internet it causes because of viruses. When I tried to uninstall this VO Package and end up with  this warning This program is blocked by group policy. I used the  software Revo  uninstaller, it could not finish the job of uninstallation but let me to clean the files and registry entries. That’s good.

http://www.revouninstaller.com/revo_uninstaller_free_download.html

After that I used malwarebyte – http://www.malwarebytes.org/ to clean the computer and got Windows 7 is free from viruses.

STEP1: USE the uninstall tool for Bitdefender 2013 from the link below:

http://www.bitdefender.com/files/KnowledgeBase/file/BD2013_Uninstall_Tool.exe

Step2:  RUN a CCleaner tool to remove all the old registry files, download the CCleaner from the link below:

http://www.filehippo.com/download_ccleaner/

Step3. Restart the PC and re-try to install Bitdefender 2011/2012 once more.