Windows 10: How do I get rid of this virus that is located in powershell.exe?

Discus and support How do I get rid of this virus that is located in powershell.exe? in AntiVirus, Firewalls and System Security to solve the problem; I really don't know or remember anything I downloaded, one day this just kept spamming... Discussion in 'AntiVirus, Firewalls and System Security' started by Fredeeeeeeeee, Jun 30, 2024.

  1. How do I get rid of this virus that is located in powershell.exe?


    I really don't know or remember anything I downloaded, one day this just kept spamming

    :)
     
    Fredeeeeeeeee, Jun 30, 2024
    #1

  2. Help with PowerShell Virus!

    Every time that I open windows, PowerShell pops up. I searched and I found that it's a PowerShell virus.

    I followed the steps that are listed here,

    How to uninstall PowerShell? *Trojan Virus* and Help with PowerShell Virus!

    but nothing happened.

    Autorun scan log

    https://drive.google.com/file/d/178BS66D-qUMc6-UuRO-qFF57HfIy5vmX/view?usp=share_link


    How do I get rid of this virus that is located in powershell.exe? c5ac3ca4-7e60-425e-9776-7ba4028c29da?upload=true.jpg


    Bitdefender after every restart:


    How do I get rid of this virus that is located in powershell.exe? b062df92-859a-43f0-8cf1-afb8891fc885?upload=true.jpg


    I really appreciate any help you can provide.

    Windows 10 user
     
    Abbas Naser, Jun 30, 2024
    #2
  3. How to remove Gallery.exe (Virus)

    I've been dealing with a virus named "Gallery.exe," and despite my best efforts, it keeps coming back. I've taken several steps to remove it, including formatting my disk, but it still manages to return. I was able to spot this suspicious exe running in my background, I tried my best to find it's location but it kept opening File Explorer with no signs of that exe. When I opened the exe location using Task Manager it opened 'C:\Users\[username]\AppData\Roaming". I could not see the exe in that location, I somehow opened the exe properties and saw the hidden option on it was greyed out. So I used the command "attrib -h -s /s /d" to unhide the file and then I was able to see it. I deleted the file but then, it kept coming back with every restart. Since then, my windows is going insane, the Windows anti-virus keeps deleting genuine files like, AMD Software, Google Chrome, and windows apps itself. My different apps started behaving weird and all.

    What I've Tried So Far:

    • Formatting the disk and performing a clean install of the operating system.
    • Running multiple antivirus and anti-malware scans.
    • Installing all available Windows updates and patches.
    Unfortunately, none of these attempts have been successful in permanently removing this pesky virus.

    System Information:

    • Operating System: Windows 11
    Specific Questions:

    1. Has anyone encountered a similar virus issue and successfully removed it? If so, could you please share your experience and the steps you took?
    2. Are there any known vulnerabilities or software that "Gallery.exe" may exploit to keep reappearing?
    I'm open to any advice, suggestions, or guidance you can provide. My goal is to get my computer back to a virus-free state and ensure it remains that way.

    Thank you in advance for your help and support. Your expertise is greatly appreciated!

    Best regards, Rehan Ramay
     
    Rehan Rashid, Jun 30, 2024
    #3
  4. How do I get rid of this virus that is located in powershell.exe?

    How do I get rid of Trojan Virus located in my Powershell Application?

    Yeah, the whitelist checkboxes need to be enabled. Else, it lists all the entries, including the MSFT entries.

    • Download fixlist.txt
    • Make sure FRST64.exe and FixList.txt are in the same folder.
    • Launch FRST64.exe and click "Fix".
    • Post the contents of the output log file (FixLog.txt) here, or upload it to OneDrive.
     
    Ramesh Srinivasan, Jun 30, 2024
    #4
Thema:

How do I get rid of this virus that is located in powershell.exe?

Loading...
  1. How do I get rid of this virus that is located in powershell.exe? - Similar Threads - rid virus located

  2. How do I get rid of Trojan Virus located in my Powershell Application?

    in Windows 10 Gaming
    How do I get rid of Trojan Virus located in my Powershell Application?: Malwarebytes keeps popping up saying trojan detected website blocked. It says it has to deal with my windows powershell. https://answers.microsoft.com/en-us/windows/forum/all/how-do-i-get-rid-of-trojan-virus-located-in-my/9f937c17-5890-4372-b2ea-ef5977ae5222
  3. How do I get rid of Trojan Virus located in my Powershell Application?

    in Windows 10 Software and Apps
    How do I get rid of Trojan Virus located in my Powershell Application?: Malwarebytes keeps popping up saying trojan detected website blocked. It says it has to deal with my windows powershell. https://answers.microsoft.com/en-us/windows/forum/all/how-do-i-get-rid-of-trojan-virus-located-in-my/9f937c17-5890-4372-b2ea-ef5977ae5222
  4. How do I get rid of Trojan Virus located in my Powershell Application?

    in Windows 10 BSOD Crashes and Debugging
    How do I get rid of Trojan Virus located in my Powershell Application?: Malwarebytes keeps popping up saying trojan detected website blocked. It says it has to deal with my windows powershell. https://answers.microsoft.com/en-us/windows/forum/all/how-do-i-get-rid-of-trojan-virus-located-in-my/9f937c17-5890-4372-b2ea-ef5977ae5222
  5. How do I get rid of this virus that is located in powershell.exe?

    in Windows 10 Gaming
    How do I get rid of this virus that is located in powershell.exe?: I really don't know or remember anything I downloaded, one day this just kept spamming https://answers.microsoft.com/en-us/windows/forum/all/how-do-i-get-rid-of-this-virus-that-is-located-in/b34f1713-34ac-4651-97c1-60989234fe6d
  6. How do I get rid of Trojan Virus located in my Powershell Application?

    in AntiVirus, Firewalls and System Security
    How do I get rid of Trojan Virus located in my Powershell Application?: I downloaded a link through a gofile website that was linked in another website, and it asked me to unzip the file I downloaded and run the .bat file that was left behind.Upon doing so, my laptop was immediately infected with a Trojan virus, and a hacker gained remote access...
  7. How do I get rid of Trojan Virus located in my Powershell Application?

    in Windows 10 Gaming
    How do I get rid of Trojan Virus located in my Powershell Application?: I downloaded a link through a gofile website that was linked in another website, and it asked me to unzip the file I downloaded and run the .bat file that was left behind.Upon doing so, my laptop was immediately infected with a Trojan virus, and a hacker gained remote access...
  8. How do I get rid of Trojan Virus located in my Powershell Application?

    in Windows 10 Software and Apps
    How do I get rid of Trojan Virus located in my Powershell Application?: I downloaded a link through a gofile website that was linked in another website, and it asked me to unzip the file I downloaded and run the .bat file that was left behind.Upon doing so, my laptop was immediately infected with a Trojan virus, and a hacker gained remote access...
  9. How do I get rid of Trojan Virus located in my Powershell Application?

    in Windows 10 Gaming
    How do I get rid of Trojan Virus located in my Powershell Application?: I downloaded a link through a gofile website that was linked in another website, and it asked me to unzip the file I downloaded and run the .bat file that was left behind. Upon doing so, my laptop was immediately infected with a Trojan virus, and a hacker gained remote access...
  10. How do I get rid of Trojan Virus located in my Powershell Application?

    in Windows 10 Software and Apps
    How do I get rid of Trojan Virus located in my Powershell Application?: I downloaded a link through a gofile website that was linked in another website, and it asked me to unzip the file I downloaded and run the .bat file that was left behind. Upon doing so, my laptop was immediately infected with a Trojan virus, and a hacker gained remote access...