Windows Vista Forums
Vista Forums Home Join Vista Forums Windows 7 Forum Vista Tutorials Tags
Welcome to Windows Vista Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows Vista. The Vista forum also covers news and updates and has an extensive Windows Vista tutorial section that covers a wide range of tips and tricks.


Go Back   Vista Forums > Vista Forums > System Security

RB

Vista - General Suggestion...

Reply
 
04-02-2009   #1


Windows Vista™ Ultimate x64
 
 

General Suggestion...

Hey guys. I just thought i would post a tip here...

I recently seen a virus which encrypted itself for protection. It took forever to get rid of and i thought it was very smart.

So the following commands will prevent a virus from encrypting itself (hopefully).

1) takeown /f "c:\windows\system32\cipher.exe" (/a)
Putting the /a at the end will give ownership to the Administrator group. Without the /a it will be given to the user who executed the command.

icacls "c:\windows\system32\cipher.exe" /deny everyone:f

As far as i know this should work. It will also prevent a user from encrypting files via a command line and possibly via a GUI too. Im not sure. However if you do not use the EFS i suggest you do this. If you do use it, i suggest renaming the command to something less obvious.

Note
The cipher command is only on advanced versions of XP and Vista. It will not be on home versions.

My System SpecsSystem Spec
04-02-2009   #2


Vista x64 Ultimate SP2, Windows 7 Ultimate x64
 
 

Re: General Suggestion...

Good tip Fmjc001. Not sure, but I believe disabling EFS encryption may prevent this as well.
My System SpecsSystem Spec
04-02-2009   #3


Windows Vista™ Ultimate x64
 
 

Re: General Suggestion...

Quote  Quote: Originally Posted by Brink View Post
Good tip Fmjc001. Not sure, but I believe disabling EFS encryption may prevent this as well.
Yeah probably would have been easier just to explain how to disable it .

Although coping and pasting 2 command lines is quite fast too .

Thanks for the reply Brink
My System SpecsSystem Spec
04-02-2009   #4


Vista x64 Ultimate SP2, Windows 7 Ultimate x64
 
 

Re: General Suggestion...

Your method is fine. It's good to have a few alternatives.
My System SpecsSystem Spec
Reply

RB


Thread Tools


Similar Threads for: General Suggestion...
Thread Forum
suggestion Live Messenger
Suggestion Live Messenger
Suggestion: I submitted a suggestion for a Generic Soap Cmdlet via Connect. Please check it out and vote. PowerShell
Suggestion Vista General
Suggestion: General formatting SwitchParameter NoLabel PowerShell


Vista Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd