Issue
With the ThreatDown Endpoint Agent installed, you may notice a PowerShell script being executed in your environment that is similar to the following:
"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy RemoteSigned -File C:\WINDOWS\SystemTemp\RandomFolder.bgv\restartservice_Year_Month_Day_Time.ps1", "S-1-0-0", "-", "-", "0x0", "C:\Program Files\Malwarebytes Endpoint Agent\MBCloudEA.exe", "S-1-16-16384"}Environment
- Windows installations of the Endpoint Agent
Resolution
This is expected behavior for the ThreatDown Endpoint Agent. The use of this script is to restart the agent for service and engine updates. For security purposes, the script uses a randomized folder name and date stamped filename.
If you have any further questions on this script, please contact ThreatDown support.