Cryptowall loads and executes arbitrary DLLs in its current directory. Therefore, we can hijack a vuln DLL execute our own code, control and terminate the malware pre-encryption. Blocking the ransomwares encryption and killing the process.
www.malvuln.com/advisory/0CFFEE266A8F14103158465E2…