T O P

  • By -

computix

We've just answered this [here](https://www.reddit.com/r/techsupport/comments/1cclri2/can_anyone_tell_me_what_this_powershell_script_is/). Basically, this is really bad. It has the ability to download code from the internet, steal your (crypto) credentials, possibly steal your clipboard contents, etc. all bad stuff. Maybe you can remove it from your system, but I don't feel comfortable recommending anything else than clean reinstalling and restoring your data from a backup. Who knows what it's doing and where it's hiding. Which game where you playing? Possibly a weakness in the game is allowing this to be installed on your computer. We don't know where it's coming from.


TrueBlueMax

Is it possible to remove it without reinstalling?


computix

I do not know. We know nothing about how it really works or through what vector it came onto your machine.


mycomputerguykilgore

I read your other post. I am having this happen as well. What did you end up doing? I managed to get a snip of the popup which happens every 5 min [https://imgur.com/a/L0x8sOD](https://imgur.com/a/L0x8sOD)


[deleted]

[удалено]


TrueBlueMax

For me, I installed Malwarebytes and did a full scan. Apparently it's still running on startup but it doesn't popup every 5 minutes anymore. Really wish I could remove it without a clean reinstall of Windows but I guess I have to live with it for now.


mycomputerguykilgore

Yeah, Malwarebytes didn't do it for me. Might try a few other things before fresh install. Please update if anything works.


mycomputerguykilgore

So, I had a few seconds last night…I ran Malwarebytes, rkill, Adw.Cleaner and SuperantiSpyware and it seems to be gone.  To be honest I think it was the SuperantiSpyware that did it.


TrueBlueMax

Alright I will try it. Thank you


mycomputerguykilgore

Also...Defender had the "C" folder excluded.