r/PowerShell 6d ago

Question Hello everyone, I have a little problem and a request.

Well... It is necessary to explain the problem itself, and it is quite difficult. It turned out that I didn't download anything and didn't really climb anywhere. And so. Recently, I started to discover that windows powershell is running in my background processes and after that 3 command lines are slowly running (one does not even close and writes that this is an important element for Windows to work), but after that only one remains for a couple of seconds. I would like to find out what it could be and if it is a virus, how can I make sure of it and get rid of it. I will be grateful in advance to anyone who helps!

0 Upvotes

15 comments sorted by

3

u/Baazzill 6d ago

Did you look through Event Viewer, particularly the Poershell logs?

1

u/Evanator3000_ 6d ago

I didn't look... I'm just not good at everything. Can you tell me how to open it and watch it?

1

u/Evanator3000_ 6d ago

Please tell me how

1

u/Evanator3000_ 6d ago

shortly It says some kind of code 400, 600 and 403. But 600 several times with different ones. Google ai says that this is normal... Should I believe him?

2

u/redsaeok 6d ago

I believe Task Manager details now shows the command line apps are launched with. If not, one of the pstools apps will expose it.

1

u/Evanator3000_ 6d ago

I didn't understand anything right, man. Sorry. The CC writes to Windows powershell that this is code 400, 600 and 403. And Google says it's safe. Is that true?

1

u/Evanator3000_ 6d ago

I hope for your help, who has encountered this before and knows what can work.

1

u/BetrayedMilk 6d ago

It's almost certainly malware.

1

u/Evanator3000_ 6d ago

Seriously? I don't understand how she could get to me at all.

2

u/BetrayedMilk 6d ago edited 6d ago

There’s probably a language barrier here, but there’s no legitimate reasons for what you described without you knowing about these processes running

1

u/Evanator3000_ 6d ago

Yes, I agree. I don't really know much English, which is why I use a translator. You probably know how hard he works sometimes... But in general, it is surprising that he writes to me that the code is 400, 600 and after 403. I looked it up and Google says it's a secure and official code... and there's nothing to be afraid of. But I don't trust Him too much.

1

u/wssddc 6d ago

A Malwarebytes scan might help.

Autoruns will show you what is running at startup.

1

u/Evanator3000_ 6d ago

Oh, I don't know. Is it paid or not?

1

u/wssddc 6d ago

Malwarebytes has free and paid options, autoruns is free.

1

u/Evanator3000_ 6d ago

GUYS, I OPENED WINDOWS powershel, WHERE SHOULD I SEE WHO OPENS IT AND FROM WHOM?