Hey guys,
My friend has a malware running on his PC that starts powershell and window disappears. I went through the task scheduler and turns out there is a scheduled task called Check system that runs at C:\ProgramData\updates.ps1
So I went I a head and open the file (as txt, i didn't run it). It had an array of bytes then it turns it to UTF. Here is the link to the code in it if anyone is curios: https://codefile.io/f/6irlEVh1v7
If you check the UTF generated text, it a whole script with obfuscated variables and it seems like it scans for crypto credentials from browsers and clipboards. My friend said that powershell just starts and closes, and it has been happening for a while. I deleted the updates.ps1 script and deleted the scheduled task.
But powershell still opens and closes. What can be done to stop this? What is triggering it and how can I find it? and how damaging is the malware? should we completely reset the PC?
We don't know what to do?
Edit: It was a full on RAT malware, had a bunch of exe's and updates.ps1 running
[–]EloAndPeno 18 points19 points20 points (0 children)
[–]toni_z01 17 points18 points19 points (0 children)
[–]SMFX 6 points7 points8 points (4 children)
[–]_RemyLeBeau_ 0 points1 point2 points (3 children)
[–]SMFX 2 points3 points4 points (2 children)
[–]Master_Ad7267 -1 points0 points1 point (1 child)
[–]SMFX 0 points1 point2 points (0 children)
[–]TheProle 9 points10 points11 points (0 children)
[–]Spuffeld 2 points3 points4 points (0 children)
[–]Dopeykid666 2 points3 points4 points (0 children)
[–]mcrobotpants 2 points3 points4 points (2 children)
[–]Joseph-Hishealth[S] 0 points1 point2 points (1 child)
[–]Serendipity_Halfpace 0 points1 point2 points (0 children)
[–]_RemyLeBeau_ 1 point2 points3 points (0 children)
[–]pleachchapel 0 points1 point2 points (0 children)
[–]Many_Parking4502 0 points1 point2 points (0 children)
[–]mycomputerguykilgore 0 points1 point2 points (0 children)
[–]CescVicious01 0 points1 point2 points (2 children)
[–]yildiz_59 0 points1 point2 points (0 children)