# Securing your Microsoft Machine

**URL:** <https://forums.speedlife.net/t/securing-your-microsoft-machine/62335>\
**Category:** NYSpeed Off Topic\
**Created:** [February 2, 2009, 2:44pm UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335 "2009-02-02T14:44:36Z")\
**Posts on this page:** 17\
**Page:** 8

<div class="post-metadata">

**Author:** ![BOBBYGRV](https://avatars.discourse-cdn.com/v4/letter/b/ed8c4c/32.png) [@BOBBYGRV](https://forums.speedlife.net/u/BOBBYGRV)\
**Post date:** [September 11, 2013, 6:27am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/141 "2013-09-11T06:27:33Z")

</div>

Well, I need to have some sort of protection on there for spyware and anti virus. It’s better than having nothing right?

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [September 11, 2013, 6:31am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/142 "2013-09-11T06:31:05Z")

</div>

Just run Microsoft security essentials its free

I was just explaining there isn’t a end all for antivirus/spyware protection.

You’re also much better off not using internet explorer and using chrome 🙂

---

<div class="post-metadata">

**Author:** ![BOBBYGRV](https://avatars.discourse-cdn.com/v4/letter/b/ed8c4c/32.png) [@BOBBYGRV](https://forums.speedlife.net/u/BOBBYGRV)\
**Post date:** [September 11, 2013, 7:00am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/143 "2013-09-11T07:00:47Z")

</div>

I use FF most of the time. Never use IE.

---

<div class="post-metadata">

**Author:** ![boardjnky4](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@boardjnky4](https://forums.speedlife.net/u/boardjnky4)\
**Post date:** [September 11, 2013, 7:33am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/144 "2013-09-11T07:33:44Z")

</div>

Avast is ranking pretty high on detection right now. I think MSE has been slacking off a bit.

---

<div class="post-metadata">

**Author:** ![TradersBASE](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/tradersbase/32/5321_2.png) [@TradersBASE](https://forums.speedlife.net/u/TradersBASE)\
**Post date:** [October 10, 2013, 6:12pm UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/145 "2013-10-10T18:12:12Z")

</div>

> **[r/sysadmin - Proper Care & Feeding of your CryptoLocker Infection: A rundown on...](https://www.reddit.com/r/sysadmin/comments/1mizfx/proper_care_feeding_of_your_cryptolocker/)**
>
> 592 votes and 544 so far on reddit

We just got hit with a phishing attack that contained the above (cryptolocker). Good times ahead. LOL  
Any of you guys see this in the wild? I was warned about it a few weeks back.

---

<div class="post-metadata">

**Author:** ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)\
**Post date:** [October 10, 2013, 7:35pm UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/146 "2013-10-10T19:35:37Z")

</div>

^Damn that looks scary. As LZ said run the EMET tool. Wondering if the DEP portion takes care of this?

If you want to install Avast (which is what I’m using). Download from this link [http://www.avast.com/get/TRKxgoo2](http://www.avast.com/get/TRKxgoo2)

If I get a certain number of installs It bumps up to Avast Internet Security for 1 year. Remember to remove previous versions of your A/V before installing a new one.

---

<div class="post-metadata">

**Author:** ![boardjnky4](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@boardjnky4](https://forums.speedlife.net/u/boardjnky4)\
**Post date:** [October 10, 2013, 7:50pm UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/147 "2013-10-10T19:50:20Z")

</div>

spent all day dealing with cryptolocker. It’s really fun when you have multiple shared network drives mounted to the machine. We are seeing whole directories on shared network resources being completely encrypted and fucked…fml, not getting any sleep anytime soon.

All started with a malicious email attachment. A .zip with a .exe in it, that is masquarading as a PDF (thumbnail shows PDF once extracted) Exactly the same behaviors as above link. Luckily it’s easy to identify on machines but it’s still a brutal mess.

Motherfuckers really need to stop clicking on shit!

---

<div class="post-metadata">

**Author:** ![TradersBASE](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/tradersbase/32/5321_2.png) [@TradersBASE](https://forums.speedlife.net/u/TradersBASE)\
**Post date:** [October 10, 2013, 7:54pm UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/148 "2013-10-10T19:54:54Z")

</div>

> [@boardjnky4](#):
>
> spent all day dealing with cryptolocker. It’s really fun when you have multiple shared network drives mounted to the machine…fml, not getting any sleep anytime soon

UGGG fuck. It encrypted your mapped drives? I’m not sure whether we got hit there or not at this point. The one user was at home so that should be a no, the other one was an internal tower so…

- 
  - 
    - Updated - - -

> [@ProgRocker](#):
>
> ^Damn that looks scary. As LZ said run the EMET tool. Wondering if the DEP portion takes care of this?
> 
> If you want to install Avast (which is what I’m using). Download from this link [http://www.avast.com/get/TRKxgoo2](http://www.avast.com/get/TRKxgoo2)
> 
> If I get a certain number of installs It bumps up to Avast Internet Security for 1 year. Remember to remove previous versions of your A/V before installing a new one.

AV have been lagging on this gem. Really it comes down to the users being smart enough to not click stupid shit…which is a near impossibility it seems. 8/

---

<div class="post-metadata">

**Author:** ![boardjnky4](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@boardjnky4](https://forums.speedlife.net/u/boardjnky4)\
**Post date:** [October 10, 2013, 8:10pm UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/149 "2013-10-10T20:10:35Z")

</div>

Yep, any drive that is mapped and is writable will be fucked

We’re having to restore from backup and mount read-only until this is under control…

---

<div class="post-metadata">

**Author:** ![TradersBASE](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/tradersbase/32/5321_2.png) [@TradersBASE](https://forums.speedlife.net/u/TradersBASE)\
**Post date:** [October 11, 2013, 10:11pm UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/150 "2013-10-11T22:11:45Z")

</div>

> [@boardjnky4](#):
>
> Yep, any drive that is mapped and is writable will be fucked
> 
> We’re having to restore from backup and mount read-only until this is under control…

Bummer. You don’t have incremental backups on the mapped shares? I’ll update when I hear whether paying the ransom worked or not, I suspect it will.

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [October 11, 2013, 10:14pm UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/151 "2013-10-11T22:14:18Z")

</div>

See other thread :-p

---

<div class="post-metadata">

**Author:** ![TradersBASE](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/tradersbase/32/5321_2.png) [@TradersBASE](https://forums.speedlife.net/u/TradersBASE)\
**Post date:** [October 11, 2013, 10:18pm UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/152 "2013-10-11T22:18:55Z")

</div>

> [@LZ](#):
>
> See other thread :-p

Fucking thanks alot, now I have to update 2 threads. 😛

---

<div class="post-metadata">

**Author:** ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)\
**Post date:** [November 14, 2013, 6:55am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/153 "2013-11-14T06:55:46Z")

</div>

EMET Tool 4.1 out

> **[Enhanced Mitigation Experience Toolkit (EMET) 4.1](https://www.neowin.net/news/enhanced-mitigation-experience-toolkit-emet-41)**
>
> EMET is a utility that helps prevent vulnerabilities in software from being successfully exploited. EMET achieves this goal by using security mitigation technologies.

---

<div class="post-metadata">

**Author:** ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)\
**Post date:** [May 21, 2014, 7:29am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/154 "2014-05-21T07:29:27Z")

</div>

Change your eBay passwords:

> **[EBay customers must reset passwords after major hack](http://money.cnn.com/2014/05/21/technology/security/ebay-passwords/index.html)**
>
> Hackers now have eBay users' names, passwords, emails, physical addresses and more.

---

<div class="post-metadata">

**Author:** ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)\
**Post date:** [June 12, 2014, 6:30am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/155 "2014-06-12T06:30:19Z")

</div>

Looks like Malwarebytes is rolling out their own EMET type tool. Has a free and paid version:

[http://blog.malwarebytes.org/news/2014/06/introducing-malwarebytes-anti-exploit/](http://blog.malwarebytes.org/news/2014/06/introducing-malwarebytes-anti-exploit/)

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [July 19, 2015, 4:43pm UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/156 "2015-07-19T16:43:56Z")

</div>

Any of you enterprise guys using Applocker via GPO?

---

<div class="post-metadata">

**Author:** ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)\
**Post date:** [July 20, 2015, 2:47pm UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/157 "2015-07-20T14:47:00Z")

</div>

Nope, never heard of it honestly. Just deny users from installing software (usually) only to the %programfiles% folder. SCCM for program distribution.

[Previous page](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335.md?page=7)
