PowerShell GPO Software Restriction Policy Script to apply to OU like "Workstation" or "Desktop" or "Laptop"

Hi

I have a very interesting query that would maybe eliminate this CryptoLocker virus once and for all.

I need a script that i can run on a few servers (different domains) that automatically creates a GPO called "Software Restriction policies", adds a path rule in the policy to block applications running in "%LocalAppData\*\*.exe" , then applies that to any OU in AD resembling "Workstations", "Desktop" or "Laptop"

When this whole thing is done manually per server, it works like a charm. The issue is we are trying to save man hours...
Thought that since i'm paying a monthly fee for Experts Exchange  and rarely use it :) , i could post it here.
jrobbertseAsked:
Who is Participating?
 
David Johnson, CD, MVPOwnerCommented:
that is called by using a wmi filter in group policy editor
Any windows Client OS
select * from Win32_OperatingSystem WHERE (ProductType <> "2") AND (ProductType <> "3") 

Open in new window

I use the wmi filters from http://bit.ly/15OE9TU
0
 
Seth SimmonsSr. Systems AdministratorCommented:
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.