Share via

Multiple Powershell instances either consuming CPU or RAM and Trojan:BAT/PSRunner.VS!MSR infecting PowerShell

Anonymous
2024-08-26T09:03:12+00:00

Hello, I have a problem with multiple Powershell instances either consuming CPU or RAM. I downloaded and ran Malwarebytes but no success. I saw that to get rid of the probable infection I could use Farbar Recovery Scan Tool. I ran it and have a FRST.txt and Addition.txt, in the files i found multiple "ATTENTION" issues on the frst.txt and the Trojan:BAT/PSRunner.VS!MSR infecting PowerShell on the addition.txt. I could not find instructions detailed enough to construct an fixlist.txt.

I hope someone can help me with this.

https://drive.google.com/file/d/1egjebgkkWiKKYbKgcWMdVPZGTho93f18/view?usp=sharing, https://drive.google.com/file/d/1s4bVpk1ba7pevJm_bZfAVhxV5fQJhtOQ/view?usp=sharing

Thanks a lot in advance.

Kimon

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

Answer accepted by question author

_AW_ 67,926 Reputation points Volunteer Moderator
2024-08-26T09:42:22+00:00
  • Download **** Fixlist.txt **** and save to the folder that FRST64.exe is located in
  • Close any apps with unsaved work
  • Run FRST64.exe and click "Fix"
  • The computer will reboot to complete the procedure

Please upload Fixlog.txt and let me know how things are running.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

3 additional answers

Sort by: Most helpful
  1. _AW_ 67,926 Reputation points Volunteer Moderator
    2024-08-26T11:54:39+00:00

    Thanks. That all looks good in the fixlog. The main infection was a crypto stealer targetting:

    binance, coinbase, blockchain, Voyager, BlockFi, crypto, coindesk, etoro, kucoin, Citi, paxful, paypal, huobi, poloniex, bittrex, kraken, bitfinex, bitstamp

    If there's nothing further, you can delete the Farbar scanner and the C:\FRST folder.

    If you could mark the thread as answered by clicking ‘Yes’ below the post that provided the solution...that'd be much appreciated.

    Good luck :)

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2024-08-26T11:22:39+00:00

    Thank you so much for the instant reply. No powershell instances are active now. Here is the Fixlog.txt

    https://drive.google.com/file/d/132dVirT0dXp3PCSMMlaKUrVoh3KxK0fE/view?usp=sharing

    Was this answer helpful?

    0 comments No comments
  3. Ramesh Srinivasan 81,800 Reputation points Independent Advisor
    2024-08-26T09:44:33+00:00

    Hi Kimon,

    Please run the fixlist below.

    • Download fixlist.txt ([https://1drv.ms/t/s!AjVYLGw0OBWU2jiKPycBsfBMEA3...](https://1drv.ms/t/s!AjVYLGw0OBWU2jiKPycBsfBMEA3F?e=LpebXZ))
    
    • Save Fixlist.txt to the folder where FRST64English.exe is located.
    
    • Close all programs.
    
    • Launch the Farbar Scanner tool and click "Fix".
    
    • Restart Windows when prompted.
    
    • Upload the output log file (FixLog.txt) to your OneDrive.
    

    Was this answer helpful?

    0 comments No comments