Toad Posted May 6, 2017 Share Posted May 6, 2017 When I run my PC for a few hours, I notice the powershell.exe icon pops up on my taskbar for a few seconds then goes away. Shortly after, I get this: http://imgur.com/a/LxnDM I have Avast, Malwarebytes, and Spybot, none of which are detecting it, but Avast keeps marking it when it runs. I read online it's a needed microsoft thing, and no one else is having this type of issue, which is strange. It's been persisting for a few months now. What do I do? Link to comment Share on other sites More sharing options...
fluffyy Posted May 6, 2017 Share Posted May 6, 2017 Add it to your exceptions and hope your sources are correct Link to comment Share on other sites More sharing options...
xxBonsai99xx Posted May 6, 2017 Share Posted May 6, 2017 Looks like you may have malware on your computer trying to download this file... https://www.virustotal.com/en/file/74f7dc47a374a3b8e3760ba30c7718002b8f2e3d954f35bbd0dbd27959e6369e/analysis/1494090695/ Give HitmanPro a try: https://www.hitmanpro.com/en-us/hmp.aspx Link to comment Share on other sites More sharing options...
iStruggle to Run it on Mac Posted May 6, 2017 Share Posted May 6, 2017 Comodo has some instructions on how to get rid of it and what it is : https://file-intelligence.comodo.com/windows-process-virus-malware/exe/powershell Link to comment Share on other sites More sharing options...
Toad Posted May 7, 2017 Author Share Posted May 7, 2017 Ran the Comodo scan as instructed, it found nothing. Link to comment Share on other sites More sharing options...
iStruggle to Run it on Mac Posted May 8, 2017 Share Posted May 8, 2017 Have you ever tried killing the process and deleting the malicious power shell file which should be the one with the most recent date on the Date modified tab? Link to comment Share on other sites More sharing options...
K1ng Posted May 9, 2017 Share Posted May 9, 2017 Try following this guide: https://www.reddit.com/r/techsupport/comments/33evdi/suggested_reading_official_malware_removal_guide/?st=j2gw1zky&sh=c3d9b712 You probably have gone through some of the steps shown there already, but it's worth checking the others. Link to comment Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now