www.FoolishIT.com

CryptoPrevent

CryptoPrevent_Large


Current Version:  6.1  released July 13th 2014

CryptoPrevent is a tiny utility to lock down any Windows OS (XP, Vista, 7, 8, and 8.1) to prevent infection by the Cryptolocker malware or ‘ransomware’, which encrypts personal files and then offers decryption for a paid ransom.

Incidentally, due to the way that CryptoPrevent works, it actually protects against a wide variety of malware, not just Cryptolocker!

Click Here for the CryptoPrevent FAQ

Click Here for Technical Information on CryptoPrevent.

Click Here for an important Anti-Virus / Anti-Malware application warning.

Click Here for the portable version which can run from anywhere, even a network share.  Note the portable version does not support the Filter Module, which is only available in the installer version.

Free edition contains:  

  • CryptoLocker and copycat protection (malware that encrypts your files for a ransom.)
  • Protection from fake file extensions and other attacks found in most trojan based malware.
  • Over 250 policy rules created to block malicious executables depending on options selected.
  • Options to disable certain types of protection or rules, and optionally to remove rules individually as necessary.
  • Event viewer for examining the event details and the rule that blocked any application.
  • Manual updating of both the application and definition files.

Premium edition adds:

  • Worry free, hands free, automatic and silent updating of application and definitions on a regular schedule.
  • Email alert option to notify you via email when an application is blocked.  (email setup required.)
  • Enable custom allow and block policies, for powerful customization of your protection!
  • Current protection automatically, for the lifetime of the product!  Malware updates itself!  Shouldn’t you update CryptoPrevent to keep it relevant?

While CryptoPrevent is FREE to download and use, consider CryptoPrevent Premium with automatic updates to the program and definitions, email alerts, and custom policy rules!

Malware gets updates, shouldn’t you be updating CryptoPrevent too?  

Click here to learn more, or purchase below…  

Click here for Bulk/Resale Edition

CryptoPrevent Premium Edition
One purchase covers ALL of your Home PCs
(Commercial usage requires one purchase per PC)

Enable CryptoPrevent Automatic Updates
Enable email alerts on blocked applications!
Enable custom policy rule creation!
Current protection automatically, for the lifetime of the product!


Buy dMaintenance Home Edition with CryptoPrevent and save!!

CryptoPrevent Premium / dMaintenance Home Premium Combo Pack
dMaintenance Home Premium
A comprehensive and automated maintenance application designed to keep your PC running smoothly. The Premium version carries these additional features:

Unlock certain maintenance options
Schedule automated maintenance
Automatic updates to the software
Maintenance reports can be emailed to you

CryptoPrevent Premium
A Malware prevention application designed primarily to block the infamous CryptoLocker infection, and its copycats, this app also works against a ton of trojan based malware! Get Premium to unlock these features:

Enable CryptoPrevent Automatic Updates
Enable email alerts on blocked applications!
Enable custom policy rule creation!
Current protection automatically, for the lifetime of the product!

Currently on SALE! Buy both and SAVE!
One purchase covers ALL of your Home PCs
(Commercial usage requires one purchase per PC)


Background

There already exists a Cryptolocker Prevention Kit as found here, but it only works with domains and OSes that have access to group policy editor (Professional versions of Windows) leaving Home versions without a method of protection.  It also isn’t the most intuitive of installations for the average Joe, either.

The original methodology CryptoPrevent used to lock down a system was presented by Lawrence Abrams of bleepingcomputer.com here, and without that guide CryptoPrevent would not exist.  Unfortunately, like the other Cryptolocker Prevention Kit mentioned, the guide by Lawrence Abrams involves usage of the Group Policy Editor available in Professional versions of Windows, and is a time consuming manual task.

CryptoPrevent seeks to alleviate these issues in allowing protection on ALL Windows OSes, while being easy enough for the average Joe to do, and optionally providing silent automation options for system admins and those who need to immunize a lot of computers automatically.

Further, CryptoPrevent has been improved to include upwards of well over 250 rules instead of just 6.  Also now that CryptoPrevent includes a real-time executable filter module, it is far more valuable than software restriction policies, even if you did create over 250 rules by yourself!

The User Interface

The User Interface allows you to select to apply the prevention tactics selected via the checkboxes above the buttons.  There exists an Undo and a Test Protection feature, an Event Log where you can view any blocked application events, a Whitelist Options dialog allowing you to selectively whitelist individual items, and a feature to automatically check for and apply updates to CryptoPrevent’s new hash based definitions, and application itself.

CryptoPrevent_v6

Special Note:  The Whitelist EXEs Option

There are a handful of legitimate executables that developers have decided to put in locations that will be blocked by CryptoPrevent’s policies, and the most popular seems to be ‘Spotify’ though there are also a few remote support applications as well that can run from these locations.  Due to this CryptoPrevent has the ability to automatically whitelist all executables located in these locations while applying the protection policies.

Obviously you never want to enable this option when applying the policies/protections if you are on a potentially infected PC!

There also exists a Policy Editor in the Advanced menu for individual whitelisting, viewing of whitelisted items, and removal of whitelisted items should this become necessary.  Note that manually entered whitelist items may NOT contain wildcards.

Apply

This is simply THE button that applies all protections to your system.  Any protection that is checked above is applied, in addition to hash based protections which are always applied.  Once applied, you will be prompted to restart your PC, to ensure protection is in effect.

Once your PC has restarted, you need to do nothing else; though you may start the program again to use the Test feature if you desire.  Also note that protection does not need to be applied to each user account, as the policies created are system-wide and affect all users, even users created after policies/protections are applied!

Test

When using the test feature, you are first presented with a dialog of simple success or failure.  Do not expect an accurate result without rebooting the PC after making any changes with CryptoPrevent.

What actually happens is a temporary executable is extracted to %appdata% and the test feature attempts to launch it, if the launch fails then the prevention is successful.  If the launch succeeds the temporary application silently returns errorlevel 9 back to CryptoPrevent to alert it that the app was successful in launching and the prevention has failed.

Undo

You may undo the protection at any time by using the Undo button in the main interface.  You will also be given the option to undo the whitelist policies, selecting no will undo the protection only.  Note that upon uninstalling this application, the undo functions are automatically performed during the uninstall process.

Video

Video of v2.x with new whitelisting capabilities:  http://www.youtube.com/watch?v=He4Evv7R2f4

Video of v2.2 protection against an earlier strain of the Cryptolocker malware in both Windows XP and Windows 7 environments.   http://youtu.be/M4dNuZYGgMM

Video of v4.3 protection against the latest strain (as of Feb 6th 2014):  http://youtu.be/O8rXfM2TYNo

 


While CryptoPrevent is FREE to download and use, consider CryptoPrevent Premium with automatic updates to the program and definitions, email alerts, and custom policy rules!

Malware gets updates, shouldn’t you be updating CryptoPrevent too?  

Click here to learn more, or purchase below…  

Click here for Bulk/Resale Edition

CryptoPrevent Premium Edition
One purchase covers ALL of your Home PCs
(Commercial usage requires one purchase per PC)

Enable CryptoPrevent Automatic Updates
Enable email alerts on blocked applications!
Enable custom policy rule creation!
Current protection automatically, for the lifetime of the product!


Buy dMaintenance Home Edition with CryptoPrevent and save!!

CryptoPrevent Premium / dMaintenance Home Premium Combo Pack
dMaintenance Home Premium
A comprehensive and automated maintenance application designed to keep your PC running smoothly. The Premium version carries these additional features:

Unlock certain maintenance options
Schedule automated maintenance
Automatic updates to the software
Maintenance reports can be emailed to you

CryptoPrevent Premium
A Malware prevention application designed primarily to block the infamous CryptoLocker infection, and its copycats, this app also works against a ton of trojan based malware! Get Premium to unlock these features:

Enable CryptoPrevent Automatic Updates
Enable email alerts on blocked applications!
Enable custom policy rule creation!
Current protection automatically, for the lifetime of the product!

Currently on SALE! Buy both and SAVE!
One purchase covers ALL of your Home PCs
(Commercial usage requires one purchase per PC)


License

CryptoPrevent is completely FREE for personal and commercial usage.  If you would like to give a little something for it, consider purchasing the Premium Edition (with Automatic Updates) above.

Download

Download a setup installer with full uninstall support below (recommended for most people, free.)

Download “CryptoPrevent Installer” CryptoPreventSetup.exe – Downloaded 191991 times – 891 kB

NOTE:  The free edition does NOT automatically download definition updates.  

As CryptoPrevent now includes a definition based system of protection, it is strongly recommended to purchase the Premium version which will update these definitions daily!!