Share via

Help with PowerShell Virus!

Anonymous
2023-01-29T18:57:09+00:00

Every time that I open windows, PowerShell pops up. I searched and I found that it's a PowerShell virus.

I followed the steps that are listed here,

How to uninstall PowerShell? Trojan Virus and Help with PowerShell Virus!

but nothing happened.

Autorun scan log

https://drive.google.com/file/d/178BS66D-qUMc6-UuRO-qFF57HfIy5vmX/view?usp=share_link

Bitdefender after every restart:

I really appreciate any help you can provide.

Windows 10 user

Windows for home | Windows 10 | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

Answer accepted by question author

Ramesh 176.5K Reputation points Volunteer Moderator
2023-01-30T09:16:35+00:00

Run:

  • del C:\Windows$sxr-powershell.exe /a

Was this answer helpful?

2 people found this answer helpful.
0 comments No comments

Answer accepted by question author

Ramesh 176.5K Reputation points Volunteer Moderator
2023-01-30T09:07:47+00:00

It might be hidden. From Command Prompt, run:

  • dir C:\Windows$sxr-powershell.exe /a

Was this answer helpful?

2 people found this answer helpful.
0 comments No comments

Answer accepted by question author

Ramesh 176.5K Reputation points Volunteer Moderator
2023-01-30T08:49:05+00:00

Glad to hear that.

Please also delete this file → C:\Windows$sxr-powershell.exe

If you have no further questions regarding the issue, you may close this question by marking useful responses in this thread as answers. How to mark Your question as "Answered". Thanks.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

9 additional answers

Sort by: Most helpful
  1. Anonymous
    2023-01-30T09:20:54+00:00

    Now it's deleted, Thank you for the help <3

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Ramesh 176.5K Reputation points Volunteer Moderator
    2023-01-30T08:26:33+00:00

    Open an elevated Command Prompt window and run:

    • schtasks /delete /TN "$sxr-ZZabTbcJkAxwXiSgJMYP" /F

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments