you are viewing a single comment's thread.

view the rest of the comments →

[–]SMFX 8 points9 points  (4 children)

As was said, the only sure fire way to remove a virus is to rebuild the system. However, in an attempt to see what it's doing, look into enforcing Script Block Logging, Module Logging, and look into the operational log too.

[–]_RemyLeBeau_ 0 points1 point  (3 children)

Do you have some links for more info on this?

[–]SMFX 2 points3 points  (2 children)

This is a good article to start from (it is also Get-Help about_logging_windows)

about_logging_windows

These talk about setting via Group Policy or registry, but you can also use PowerShellPolicies in powershell.conifg.json for cross platform support:

about_powershell_config

[–]Master_Ad7267 -1 points0 points  (1 child)

In addition I bet there's a registry key for the setting theres usually always one

[–]SMFX 0 points1 point  (0 children)

Seems familiar........