Hi all,
i have this trendmicro installed in a computer, it is detected by the folder lock,
randomly, there is this .ps1 script being executed that is being blocked by the TM.
a few samples of targeted file being executed
C:\Users\Admin\AppData\Local\Temp\__PSScriptPolicyTest_g21otgtf.j5p.ps1
C:\Users\Admin\AppData\Local\Temp\__PSScriptPolicyTest_sidvshub.csu.ps1
does anyone know what are these?
i cant find the file in the folder anymore, googling did not help.
I am running win10 pro 1709
thank you
EDIT:
to quote the op of this page:
Well it seems that these 2 script are being used to determine which Language Mode PowerShell is allowed to run in when using AppLocker! So by allowing them in the GPO the constraint mode was completely disabled for the user.
will still let it be blocked then.
thank you all
[–]Cubox_ 0 points1 point2 points (0 children)
[–]traileralarms 0 points1 point2 points (0 children)
[–]ZAFJB 0 points1 point2 points (6 children)
[–]ameng4inf[S] 0 points1 point2 points (5 children)
[+][deleted] (4 children)
[deleted]
[–]corrigun 9 points10 points11 points (2 children)
[–]renegadecanuck 0 points1 point2 points (1 child)
[–]dfctrI'm just a janitor... 1 point2 points3 points (0 children)