Educause Security Discussion mailing list archives

Re: Ransomware


From: "Ashfield, Matt (NBCC)" <Matt.Ashfield () NBCC CA>
Date: Thu, 23 Oct 2014 16:47:37 +0000

Revisiting this thread from a year back....Has anyone seen any downside of the restriction of preventing EXE's from 
running from %APPDATA% ?

Thanks

Matt

From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Kevin 
Moll
Sent: Thursday, November 14, 2013 4:34 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] Ransomware

We had a few users recently get infected with Cryptolocker.  We sent out a college-wide email from our help desk 
reminding users not to open unknown attachments, be cautious of following links, etc.

We also implemented a GPO to prevent EXE's from running from %APPDATA%.  We haven't had any reported infections since 
taking these two measures.

-Kevin

Kevin Moll
Manager, Network/Server Systems
Valencia College
1800 S. Kirkman Rd.
Orlando, FL 32827
________________________________
From: The EDUCAUSE Security Constituent Group Listserv [SECURITY () LISTSERV EDUCAUSE EDU] on behalf of Shahra Meshkaty 
[meshkaty () SANDIEGO EDU]
Sent: Thursday, November 14, 2013 2:29 AM
To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>
Subject: [SECURITY] Ransomware
Is anyone taking any particular steps to inform and communicate the risks or prevalence of Ransomware to your campus?
Did you use this opportunity to caution them to be deligent in general or have provided them with specifics?  Thanks
Shahra


Current thread: