Prevention and treatment of PowerShell virus (no file extortion)
1. Create an AppLocker Rule
Select computer configuration-> Windows configuration-> Security Settings-> Application Control Policy-> AppLocker
Right-click "executable Rule" and select "create New Rule"
After clicking create New Rule, open the following window, and click next:
Select "reject" for the operation, and select the appropriate user or user group for this rule, where EveryOne is configured and go to the next step.
Select path here, and then click next:
Select the path to the PowerShell program (default address: C:\ Windows\ System32\ WindowsPowerShell\ v1.0\), and then next:
Specify a name for the new rule, and then click create:
Select Yes when prompted as follows:
Right-select AppLocker and click Properties, then under executable rules, select Enforcement rules, and check configured.
Note:
1. Make sure that the Application Identify service starts and is set to boot automatically. If the service does not start properly, Applocker Rule will not run correctly.
2. After adding the policy, execute Gpupdate to update the group policy.