Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
dox
Mar 4, 2006
We have a client get hit by Cryptowall every week when a new variation rolls around.

I'd love for someone to correct me but as far as we can tell, there is no PERFECT solution to block Cryptowall or any future variants. Sure, GPO restrictions may help but then they will just avoid the folders like %AppData%. OpenDNS is great but every client that has been hit is using them... they just changed the variant to encrypt before sending to C&C so even if it can't contact the C&C you're still hosed.

If anyone wants to enlighten me with a perfect solution for MSPs I'd be flabbergasted-- we can't come up with one.

Adbot
ADBOT LOVES YOU

  • Locked thread