Jump to content

File with hkl estension in temp folder


Recommended Posts

  • Root Admin

Please run GPedit.msc and browse to the following tree level

Local Computer Policy -> Windows Settings -> Security Settings -> Local Policies -> Audit Policy

image.png

Double-click and open the Audit object access entry and enable Success and Failure

image.png

 

Then open My Computer or run Windows File Explorer and browse to the following location.

C:\Windows\System32\WindowsPowerShell\v1.0

In that folder please find the file: powershell.exe

Right-Click on powershell.exe and select Properties and go to the Security tab and click the Advanced button

image.png

Then click on the Auditing tab, then the  image.pngContinue button

image.png

After you click the Continue button the controls will unlock to allow editing

Currently the owner should be TrustedInstaller

Highlight the Everyone entry and click the Edit button

Make sure the Principal is set to Everyone  and the Type is All - then click OK a couple of times to close out the boxes

image.png

 

Then restart your computer and once you do see the PowerShell kick off again let me know and we'll track it down in the Event Viewer.

Write down the exact time you saw it run in case we need to isolate the time in the Event Logs

Cheers

 

Link to post
Share on other sites

  • Replies 65
  • Created
  • Last Reply

Top Posters In This Topic

  • 1 month later...

Hello, yes, sorry for making you wait, I got caught up in school. So, powershell is still running, but with the steps you made me do we could, theoretically, track which program is making it run, right? Let me know how to do it and I'll let you know what I find when it runs tomorrow.

Thank you,

Mattia

Link to post
Share on other sites

  • 2 weeks later...
  • 2 months later...
  • Root Admin

Glad we could help.

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this topic with your request.

This applies only to the originator of this thread. Other members who need assistance please start your own topic in a new thread.

Please review the following to help you better protect your computer and privacy Tips to help protect from infection

Thank you

 

 

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.