Neo23x0 / Raccine

A Simple Ransomware Vaccine
The Unlicense
942 stars 123 forks source link

Update raccine.cpp #49

Closed JohnLaTwC closed 3 years ago

JohnLaTwC commented 3 years ago

This is a fix for GPO launching powershell. It does a bunch of special casing of powershell that doesn't happen when raccine is injected before powershell. This may require a bit more thought in the future, but handles the case in this thread which is important if raccine will get deployed in any environment with GPO launching powershell scripts.

https://twitter.com/disaster_ita/status/1318947554206359555