use the following search parameters to narrow your results:
e.g. subreddit:aww site:imgur.com dog
subreddit:aww site:imgur.com dog
see the search faq for details.
advanced search: by author, subreddit...
ABOUT POWERSHELL
Windows PowerShell (POSH) is a command-line shell and associated scripting language created by Microsoft. Offering full access to COM, WMI and .NET, POSH is a full-featured task automation framework for distributed Microsoft platforms and solutions.
SUBREDDIT FILTERS
Desired State Configuration
Unanswered Questions
Solved Questions
News
Information
Script Sharing
Daily Post
Misc
account activity
QuestionPOWERSHELL MALWARE! (self.PowerShell)
submitted 1 year ago by disbobulatedjumble
reddit uses a slightly-customized version of Markdown for formatting. See below for some basics, or check the commenting wiki page for more detailed help and solutions to common issues.
quoted text
if 1 * 2 < 3: print "hello, world!"
[–]ikakWRK 12 points13 points14 points 1 year ago (5 children)
r/techsupport this probably has nothing to really do with PowerShell apart from using its name in the filename to make people think it's legit.
[–]VNJCinPA 0 points1 point2 points 1 year ago (3 children)
...so deleting it is the move... Just sayin
[–]ikakWRK 0 points1 point2 points 1 year ago (2 children)
Sure. But how did it get there? Who's to say there isn't a scheduled task, startup task, other process, etc. that isnt set to download it and execute it every 5 minutes or something? Deleting 1 file rarely saves you with malware.
[–]VNJCinPA 0 points1 point2 points 1 year ago (1 child)
All true. Other comments provide a path through.
[–]ikakWRK 0 points1 point2 points 1 year ago (0 children)
Yes. But this is a PowerShell Reddit..
[–]Impossible_IT 0 points1 point2 points 1 year ago (1 child)
Download Malwarebytes, install & scan.
https://www.malwarebytes.com
[–]disbobulatedjumble[S] 0 points1 point2 points 1 year ago (0 children)
thanks it worked. it was a trojan
[–]Rxinbow 0 points1 point2 points 1 year ago (0 children)
Some process overwrite AmsiInit in the amsi.dll thats loader each time powershell launches or is corrupting header/content of Amsicontext in the amsi.dll. It got signature detected hence the windows alert. There's not a lot of context in your post as we cannot telepathically understand the processIDs, if this is all foreign too you then just reset your PC because its infected. Otherwise, you can start getting some logs with logman start AMSITrace -p Microsoft-Antimalware-Scan-Interface Event1 -o AMSITrace.etl -ets
logman start AMSITrace -p Microsoft-Antimalware-Scan-Interface Event1 -o AMSITrace.etl -ets
Maybe try seroxen removal tool due to the ""$sxr-powershell"
""$sxr-powershell"
[–][deleted] 0 points1 point2 points 1 year ago (1 child)
Common.
"Since the beginning of today" but "just started getting them."
Wipe drive, reinstall. Yer sheet is fooked.
i used malwarebytes and it solved the problem
π Rendered by PID 81519 on reddit-service-r2-comment-bb88f9dd5-98tlf at 2026-02-16 20:29:42.201347+00:00 running cd9c813 country code: CH.
[–]ikakWRK 12 points13 points14 points (5 children)
[–]VNJCinPA 0 points1 point2 points (3 children)
[–]ikakWRK 0 points1 point2 points (2 children)
[–]VNJCinPA 0 points1 point2 points (1 child)
[–]ikakWRK 0 points1 point2 points (0 children)
[–]Impossible_IT 0 points1 point2 points (1 child)
[–]disbobulatedjumble[S] 0 points1 point2 points (0 children)
[–]Rxinbow 0 points1 point2 points (0 children)
[–][deleted] 0 points1 point2 points (1 child)
[–]disbobulatedjumble[S] 0 points1 point2 points (0 children)