Hello Mr. Greg,
It's pleasure to talk to you,
Same issue here exactly:
The computer renames automatically to "Administrator", I am sure it's a virus, even I have the following issues accordingly,
- Windows Search service won't start (keeps trying but fail), means file indexing stopped working which leads to slow file browsing.
- Windows defender won't help, the status of antivirus is green, but once I start scanning computer, its counting to 13 files then stuck and stop immediately,
What I've tried:
1- Tried another antivirus like bitDefender and ESET Node.
2- Stopped all unknown startup programs.
3- Starts the computer on safe mode and scan the computer.
4- Starts Microsoft defender antivirus (offline scan)
all above steps fails,
So, after my private investigation, I found the virus name is "__PSScriptPolicyTest_twoyiqyz.bga.ps1" which is generated in %temp% temporary,
after starting the computer in about 15-20 minutes, starts making some execution and then a PowerShell windows pops up and disappear, after monitoring it, i found it executing the following command:
| "powershell.exe" -WindowStyle Hidden -ExecutionPolicy Bypass -File "C:\Windows\System32\C67C3E38-6391-4014-87CD-3B18A95CBE1E.ps1" |
|---|
The whole execution procedure is captured on the following path:
"Logfile.CSV"
looking forward to your kindest reply,
Kindest regard
Sadiq Aldawas