Windows 10: Anti-ransomware protection in Fall Creators Update

Discus and support Anti-ransomware protection in Fall Creators Update in AntiVirus, Firewalls and System Security to solve the problem; I’m a little surprised MS didn’t whitelist their own exes. Kind of stupid TBO. There is always going to be a bit of annoyance when using protection... Discussion in 'AntiVirus, Firewalls and System Security' started by Stevekir, Nov 13, 2017.

  1. vram Win User

    Anti-ransomware protection in Fall Creators Update


    I’m a little surprised MS didn’t whitelist their own exes. Kind of stupid TBO.

    There is always going to be a bit of annoyance when using protection of this type but it’s needlessly intrusive when it’s bugging users to grant access for applications that it should know are safe.

    IMO, they need to tweak this feature with regularly updated app whitelist definitions. Anything not whitelisted is treated as unknown, requiring permission by the user. Not perfect, but would ease a lot of pain.

    Guess it’ll be another couple of years before they get this new feature out of beta. There is no way I’m activating this or recommending it’s use to anyone I help.
     
  2. Bree New Member

    I've been using it for over a month now. The initial rush of apps I've had to whitelist took a couple of weeks before it dropped to zero. Since then it has been completely unobtrusive. I'm leaving it turned on.
     
  3. vram Win User
    That’s good. Unfortunately I don’t have time to deal with that. Not myself, but for the people that will undoubtedly nag me about it.
     
  4. lx07 Win User

    Anti-ransomware protection in Fall Creators Update

    That is why it is turned off by default - for people like you. You would get nagged. Not much but you would. You don't have time and would moan about the change.

    I use the maywarebytes anti-ransomware. It was a bore for about a day to get it working smoothly but now it does.

    If you don't use one (and don't bother making non-connected backups) then all you can do is hope for the best and not complain later.

    If you make backups (and all the people who nag you do) it doesn't matter really either way. You/they can just restore.
     
  5. Superfly Win User
    LOL... Yup...'nuff said

    BTW.. I had a similar issue with BD Free with over-zealous detection based on listing rather than heuristics - made me switch
     
    Superfly, Nov 23, 2017
    #20
  6. Barman58 Win User
    Predesigned whitelists are a serious issue for antiransomware, as any executable can be the bad one, even if it appears to be a totally benign part of the OS or a standard windows "filler" app.

    The problem with ransomware is that it targets file areas where even a standard user has full control access - Spoof a suitable OS tool that is included in a whitelist and you have full access to encrypt all the user files. But if a standard OS tool attempts to access a file area and you as the user has not initiated it then you at least have something that needs checking immediately, ( unless you a click everything you see kind of person, and those are beyond help )
     
    Barman58, Nov 23, 2017
    #21
  7. vram Win User
    I understand what you're saying but if I whitelist explorer.exe, (and I'm going to have to do that) then the protection of this feature for this app is null and void for that exe, anyway.

    Its the same deal with many other apps the user is obviously going to whitelist as time goes on.

    Best you can do is make sure the definitions for whitelisted exes are properly hashed with digital sigs. Incorrect Hash or missing sig triggers user prompt.
     
  8. Superfly Win User

    Anti-ransomware protection in Fall Creators Update

    Yup, but zero-day is still heuristic though..
     
    Superfly, Nov 23, 2017
    #23
  9. Bree New Member
    I'm curious as to why you feel you need to do that. It's never come up as a blocked app for me.

    I've had to whitelist things like soffice.bin (LibreOffice), 7zFM.exe (7-Zip file manager), psp.exe (PaintShop Pro) and from MS, Attib.exe and RoboCopy.exe (because of the way I use them in my backup batch files) - but I've never needed a general 'pass' for explorer.exe.
     
  10. vram Win User
    I've been notified on two different machines that explorer.exe was prevented from making changes. I know those PCs are clean. Could've been glitches as those machines were upgraded and not clean installed. Doesn't matter though. Should've never happened.
     
  11. Bree New Member
    Odd - It's never happened to me (and my machine's an upgrade, not a clean install). What was your action that triggered this?

    For further investigation it's worth noting that, unlike most other notifications, these Controlled Folder Access events are recorded in the Event Log as Event ID 1123 in...
    Application and Service Logs/Microsoft/Windows/Windows Defender/Operational
     
  12. vram Win User
    I think I was saving a file on both machines that I witnessed it.
     
  13. PromU Win User

    Anti-ransomware protection in Fall Creators Update

    Upgraded from CU and have had no problems with excessive notifications; so far I've only had 3 or 4.
     
    PromU, Nov 24, 2017
    #28
  14. vram Win User
    I have a fresh loaded machine in front of me. May enable it to test. Not getting my hopes up.
     
  15. Jeddie Win User
    Just upgraded to 1709. Had about 3-4 nags already when saving my files back to C drive (eg Notepad file .txt).
    Doesn't let me save it at all? Already turned Protected Folders off. Lasted about an hour.

    Am I missing something?
     
    Jeddie, Nov 24, 2017
    #30
Thema:

Anti-ransomware protection in Fall Creators Update

Loading...
  1. Anti-ransomware protection in Fall Creators Update - Similar Threads - Anti ransomware protection

  2. Fall creators update.

    in Windows 10 Installation and Upgrade
    Fall creators update.: How do i stop or block this virus you call the fall creators update, 3 times this year it's uploaded itself onto my computer and every time i've had to revert to the previous build. Each time it installs itself i loose 3-4 hours of work time because i can't use my computer,...
  3. Fall creators update v1809

    in Windows 10 Installation and Upgrade
    Fall creators update v1809: I have updated to windows 10 fall creators update v1809 and everything runs smooth until I use sleep mode. When I wake my computer from sleep everything lags extremely to the point where I need to restart, then everything is fine, until I use sleep again. Has anyone...
  4. Sandboxie and Fall Creators Update

    in AntiVirus, Firewalls and System Security
    Sandboxie and Fall Creators Update: I don't know how many Sandboxie users we have here but there's got to be a few. If you are, and have upgraded W10 to FCU, you should install beta 5.21.6. It was released today. Sandboxie doesn't officially support FCU yet, but based on my personal case use, the beta is...
  5. Fall creators update not initializing(?)

    in Windows 10 Installation and Upgrade
    Fall creators update not initializing(?): So when i booted my pc this morning, i was greeted with the "hello" screen of the windows update. But then it just stops fading in and giving me black screens amd half-faded in sentences. I decided to give it a while, but after 4 hours it hasn't gotten a step further. The...
  6. Fall Creators Update

    in Windows 10 Support
    Fall Creators Update: Has anyone installed it yet? If so did it break anything for you? Debating If I should update or not. 95662
  7. Fall Creator Update Query

    in Windows 10 Installation and Upgrade
    Fall Creator Update Query: A couple of weeks ago I installed the Fall Creator Update.All installed well,but when I booted up all my Start Menu items were missing,also my about half my Desktop Icons had gone.so I reverted back to build 1703. have Microsoft sorted these things out,i am a bit unsure if I...
  8. fall creator update

    in Windows 10 Installation and Upgrade
    fall creator update: Is there a general chart which might give info on when i would get fcu. I went from 7 to 10 just a couple weeks before free 10 stopped. 97324
  9. Fall Creators Update

    in Windows 10 Installation and Upgrade
    Fall Creators Update: I just bit the bullet and went to Microsoft site and tried to install it. It hung up stuck on 24% and stayed there for an hour so I pulled the plug and it has gone back to the previous version. Now what? 99881
  10. Fall Creators Update

    in Windows 10 Support
    Fall Creators Update: I work for a company that has about 200 desktop and laptop running Windows 10 (most are HP's)on our own domain and after the fall creators update, we have experienced Unauthenticated network messages as well as download issues in all browsers (Edge, IE 11, Chrome, Firefox)....