Cryptowall

We are using SCCM with Forefront to protect our computers, does Microsoft have a fix or defense for this yet???

will this stop crypto?

http://searchsecurity.techtarget.com/definition/Microsoft-Enhanced-Mitigation-Experience-Toolkit-EMET

  • Edited by jamicon 19 hours 7 minutes ago
February 6th, 2015 11:06am

Microsoft security products identify this under the "Crowti" threat family:

http://www.microsoft.com/security/portal/threat/encyclopedia/Entry.aspx?Name=Win32%2fCrowti

"Microsoft security software detects and removes this threat." (Of course, this depends on the definitions being updated with the latest malware traces.)

The only possible "fix" I've seen to decrypt files encrypted by this malware is this

http://blogs.technet.com/b/mmpc/archive/2014/08/12/fireeye-and-fox-it-tool-can-help-recover-crilock-encrypted-files.aspx

but newer versions of the malware are likely to be using different encryption keys.

Here's some more info on Crowti/Cryptowall 3.0. You might want to consider enabling MAPS in endpoint protection if you aren't already using it.

http://blogs.technet.com/b/mmpc/archive/2015/01/13/crowti-update-cryptowall-3-0.aspx


And yes, EMET is a good option for increasing endpoint security and would decrease the risk of systems getting infected in the first place.


Free Windows Admin Tool Kit Click here and download it now
February 6th, 2015 12:00pm

We have systems affected that are windows and forefront up-to-date

it doesn't look like FEP is catching them

February 6th, 2015 12:49pm

We have systems affected that are windows and forefront up-to-date

it doesn't look like FEP is catching them

It shouldn't be like that, if you have sample of these malwares which won't be detected by FEP, then submit them to:

https://www.microsoft.com/security/portal/submission/submit.aspx

Free Windows Admin Tool Kit Click here and download it now
February 6th, 2015 3:32pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics