Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

CryptoPrevent v.9 blocks InSpectre: Meltdown/Spectre? vulnerabilities check tool


  • Please log in to reply
9 replies to this topic

#1 midimusicman79

midimusicman79

    Sec & Web Browser Enthusiast


  •  Avatar image
  • BC Advisor
  • 5,087 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Norway
  • Local time:03:12 PM

Posted 26 February 2018 - 10:00 AM

Hi all!

 

I have MS Win 10 Pro 64-bit and have run several Meltdown/Spectre vulnerabilities check tools, namely SpecuCheck, SpectreMeltdownCheck and InSpectre, of which the last being the most informative. :thumbup2:

 

The two first run successfully, however, the last is being blocked by CryptoPrevent v.9 and its Software Restriction Policies, since it copies an instance of itself called inspect64.exe to the AppData\Local folder. :(

 

Error message: CryptoPrevent Notification Module, SRP Block Detected, Blocked Program: 'C:\Users\User Name\AppData\Local\inspect64.exe', Protection Rule: 'C:\Users\User Name\AppData\Local\*.exe' :exclame:

 

InSpectre is indeed a legitimate program, and should as such be able to run without restrictions of any kind, even if running from the said folder.

 

I have of course already whitelisted InSpectre.exe, but not inspect64.exe, since the latter is being generated at runtime.

 

And hence, my question is as follows;

 

How do I report this bug to Foolish IT, the creator of CryptoPrevent?

 

Thank you very much in advance!

 

Regards,

midimusicman79


Edited by hamluis, 26 February 2018 - 10:59 AM.
Moved from MRL to Ransomware - Hamluis.

Microsoft Windows 10 Professional 64-bit V. 22H2 (19045) Retail Desktop PC, EAMH Paid/EEK, MB 4 Prem., and Unchecky, MDFW, FF with uBO/AG, Grammarly Free, MBBG, and Acronis CPHOE (DI), RuckZuck, PatchMyPC, UpdateHub, WingetUI, UCheck, and Winget. I have 29 Years of PC Experience.

BC AdBot (Login to Remove)

 


#2 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 62,063 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:09:12 AM

Posted 26 February 2018 - 01:34 PM

You can contact and ask the developer, Nick (Foolish Tech CEO) the following ways.


You can also contact... Proctor_Foolish_IT (Matt Proctor) who is Chief Financial Officer and an Authorized Company Representative for CryptoPrevent.  
  • Email: proctor@foolibleep.com


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#3 midimusicman79

midimusicman79

    Sec & Web Browser Enthusiast

  • Topic Starter

  •  Avatar image
  • BC Advisor
  • 5,087 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Norway
  • Local time:03:12 PM

Posted 27 February 2018 - 09:00 AM

Hi, quietman7!
 
Thank you for the prompt and insightful reply! :)
 
I have now signed up and submitted a ticket to Foolish IT Support.
 
I will let you know the outcome. :thumbup2:

Thank you very much for the help! :) The issue is pending! :busy:
 
Regards,
midimusicman79

Edited by midimusicman79, 27 February 2018 - 12:16 PM.

Microsoft Windows 10 Professional 64-bit V. 22H2 (19045) Retail Desktop PC, EAMH Paid/EEK, MB 4 Prem., and Unchecky, MDFW, FF with uBO/AG, Grammarly Free, MBBG, and Acronis CPHOE (DI), RuckZuck, PatchMyPC, UpdateHub, WingetUI, UCheck, and Winget. I have 29 Years of PC Experience.

#4 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 62,063 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:09:12 AM

Posted 27 February 2018 - 11:11 AM

You're welcome and good luck.

.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#5 midimusicman79

midimusicman79

    Sec & Web Browser Enthusiast

  • Topic Starter

  •  Avatar image
  • BC Advisor
  • 5,087 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Norway
  • Local time:03:12 PM

Posted 28 February 2018 - 10:27 AM

Hi again, quietman7!
 
Foolish IT's CFO Matt Proctor answered, and I quote:
 

Cry[p]toPrevent is behaving as intended.  Our recommendation would be to whitelist C:\Users\User Name\AppData\Local\inspect64.exe.

 
Which, upon tried, works great, although I discovered that the said file actually gets immediately deleted after being generated, but nevertheless, I was able to whitelist it without having it existing in the first place, as in specifying the file path instead of browsing to it.
 
Thank you very much for the help! :) The issue has been successfully resolved! :thumbup2:
 
Regards,
midimusicman79

Edited by midimusicman79, 28 February 2018 - 10:49 AM.

Microsoft Windows 10 Professional 64-bit V. 22H2 (19045) Retail Desktop PC, EAMH Paid/EEK, MB 4 Prem., and Unchecky, MDFW, FF with uBO/AG, Grammarly Free, MBBG, and Acronis CPHOE (DI), RuckZuck, PatchMyPC, UpdateHub, WingetUI, UCheck, and Winget. I have 29 Years of PC Experience.

#6 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 62,063 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:09:12 AM

Posted 28 February 2018 - 02:46 PM

The AppData\Local folder is one of the known hiding places for malware so that's what I suspected was going on but wanted you to contact Nick for confirmation.

.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#7 arpcpro

arpcpro

  •  Avatar image
  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:03:12 PM

Posted 23 June 2024 - 02:29 PM

In the end did you get any solution for this? I can not whitelist it. Very strange that Crypto Prevent does not allow the whitelisting of a single file.



#8 midimusicman79

midimusicman79

    Sec & Web Browser Enthusiast

  • Topic Starter

  •  Avatar image
  • BC Advisor
  • 5,087 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Norway
  • Local time:03:12 PM

Posted 23 June 2024 - 09:20 PM

:welcome: to BC, arpcpro!

However, if you did not already notice this, you have replied to a six-year-old topic, so please start a new topic for your issue. :exclame:
Microsoft Windows 10 Professional 64-bit V. 22H2 (19045) Retail Desktop PC, EAMH Paid/EEK, MB 4 Prem., and Unchecky, MDFW, FF with uBO/AG, Grammarly Free, MBBG, and Acronis CPHOE (DI), RuckZuck, PatchMyPC, UpdateHub, WingetUI, UCheck, and Winget. I have 29 Years of PC Experience.

#9 arpcpro

arpcpro

  •  Avatar image
  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:03:12 PM

Posted 26 June 2024 - 06:28 AM

I've found a way to whitelist a specific exe file by typing it manually. This is the answer we need, and the warnings stopped.

ZrWl3pX.jpeg

 

 

 

However, if you did not already notice this, you have replied to a six-year-old topic, so please start a new topic for your issue.  :exclame:

 

 

Thanks for the welcome. I did notice it was 6 years ago, but the problem is the same and it was unanswered. I found this post through a google search and I prefer that forums are kept clean with less redundant posts. I hate to click on multiple topics about the same thing until I find a useful one. Like this, the members who subscribed to the topic because they have the same problem might get notified. The search engine results already have this specific post indexed and scored high. This is not a facebook group where the old posts might disappear and people need to keep posting, asking the same things. If it was banned to reply, I guess that the forums would prevent the users from replying to posts after 3 or 4 years.


Edited by arpcpro, 26 June 2024 - 06:33 AM.


#10 midimusicman79

midimusicman79

    Sec & Web Browser Enthusiast

  • Topic Starter

  •  Avatar image
  • BC Advisor
  • 5,087 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Norway
  • Local time:03:12 PM

Posted 26 June 2024 - 08:31 AM

Glad to hear you resolved the issue, arpcpro! :)

You are welcome, Thank you for sharing the solution, and Good luck! :)
Microsoft Windows 10 Professional 64-bit V. 22H2 (19045) Retail Desktop PC, EAMH Paid/EEK, MB 4 Prem., and Unchecky, MDFW, FF with uBO/AG, Grammarly Free, MBBG, and Acronis CPHOE (DI), RuckZuck, PatchMyPC, UpdateHub, WingetUI, UCheck, and Winget. I have 29 Years of PC Experience.




1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users