- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
hey,
our ERP System is creating temporary DLL files in users TEMP directory while navigating to an printpreview window of any datasheet.
this DLL file (temporary, name by coincidence) is watched by EFRService. I can see the monitoring through resmon.exe
unfortunately, sometimes the exclusive access during monitoring takes too much time, so the ERP application cant access the file as it wants to. Its not trying it again, so it fails. if the user is retrying the print-process it works usually.
i need to exclude those files from monitoring. But i dont know how. They are not signed by any certificate and do have flexible names while they are saved in users TEMP directory
how could i manage this?
Thanks for any hint
regards
Florian
Generating random DLL files in a temp directory and they’re not signed?
Not sure you can do that without excluding the temp directory (which is probably a bad idea).
yes, thats how microsoft is working, obviously ...
we wont exclude the whole TEMP folder. That behaviour is shown on *all* Office PCs ...
there must be a workaround, right?
TAC might have something, but without a unique way to identify those files, I suspect you're in RFE territory.
Having said that, the behavior of that ERM product seems like a potential security vulnerability that should be reported to the vendor.
Did you try using version 88.62 / 88.70?
i have installed 88.32
but thats more a job at the management engine, right?
I have the same issue with Microsoft Dynamics NAV. Did you find a solution?
Endpoint Version: E88.62
unfortunately not. We still have the same issues
Have you tried doing the exclusions in the forensic blade?
----------------------------------
hy
yes, i tried it like this:
%UserProfile%\AppData\Local\Temp\fileprefix_*
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY