Jump to content

Can't remove powershell.exe marked as Trojan, HEUR:Trojan-Downloader.BAT.Agent.gen


Recommended Posts

Posted

I'm not using English Kaspersky.
Issue: powershell.exe repetitively marked as trojan, unable to remove completely.
OS: Windows 11
Kaspersky Plus

Context: Seems to be a trojan I got from running a bad .exe


Full process:

First running yesterday (Windows security detected and removed the supposed trojan right away)but haven't started until the first startup of today, powershell ran weird commands, my discord account was the first to get infected. Has already changed password, so far other account hasn't been infected yet. powershell hasn't started up ever since even if I were to try to restart my pc.

 A ScreenImage.png was created in temp folder, seems to be updated regularly, first generated the same time I started up my pc, I haven't restarted the pc since started doing a full scan with kaspersky, not sure whether it's stopped because of the scan or screenshots only taken after startup.

It seems that a registry key was removed related to powershell? I did find a suspicous powershell registry key manually but wasn't sure whether it's geniune, no longer find it, (kaspersky may had removed the very same registry.)
image.thumb.png.73b62b48f6ca14bed7a234dae881d962.png


image.thumb.png.48541a4b429efbb33cdf70ac417b1a0b.png

I'm not sure how should I proceed next, any help would be appreciated, can provide more information if needed.

Posted

More detail on the scans I did, don't know whether it's helpful or not

image.thumb.png.1969cf218ca3a7516bb4a9d2c8a362be.png

 

harlan4096
Posted

Welcome to Kaspersky Community.

 

Please provide the exact version of KPlus 21.x?

 

Also, the captured attached have very low quality, almost impossible to distinguish anything there.

 

Could You also change into English temporally having K. main interface windows -> key combination SHIFT + F12 (to revert SHIFT + F5), and re take the captures with better quality, please?

  • Like 1
Posted (edited)

Exact version: 21.24.8.522(a)
Initially, I gave up on changing the interface into English, can't find the option anywhere, it worked, thanks.
I don't understand why but my screenshots always seems to be quite low resolution, please see whether it's working properly or not.
Screenshot2026-03-14151202.thumb.png.a0d79db22712725b0d12a717e9b9bb02.pngScreenshot2026-03-14152550.thumb.png.bf71e0978ba92a635dde619e3ba5b98f.pngScreenshot2026-03-14151644.thumb.png.0e43ed6b7d777810fdc96145899e75ed.pngScreenshot2026-03-14151732.thumb.png.985fad211cf35084cdd4a5c5d84022d6.png

I'll copy-paste the the content in other scans:


Disinfect scan:

Result description: Disinfected
Type: Trojan
Name: HEUR:Trojan.Multi.Powesta.d
Precision: Exactly
Threat level: High
Object type: File
Object name: Run:Windows PowerShell v1.0
Object path: reg:\HKU\S-1-5-21-1158635976-3454111911-2512903236-1001\Software\Microsoft\Windows\CurrentVersion

Background Scan:

Result description: Detected
Type: Trojan
Name: HEUR:Trojan.Multi.Powesta.d
Precision: Exactly
Threat level: High
Object type: File
Object name: Run:Windows PowerShell v1.0
Object path: reg:\HKU\S-1-5-21-1158635976-3454111911-2512903236-1001\Software\Microsoft\Windows\CurrentVersion
Reason: Expert analysis
Databases release date: Today, 3/14/2026 8:00:00 AM

Result description: Not processed
Type: Trojan
Name: HEUR:Trojan.Multi.Powesta.d
Precision: Exactly
Threat level: High
Object type: File
Object name: System Memory
Reason: Skipped

Edited by QQxR
  • Like 1
Posted

FULL SCAN COMPLETED, 1 OBJECT NOT PROCESSED

I've finished running the full scan, I still don't understand why powershell was marked as malicous, but can't be removed. I'm currently way too anxious, and paranoid to do anything on my pc at all. Why would powershell marked as malicous? Is this common? Any possible ways to check for damages? How should I proceed next or am I fine for now? Is there any extra steps for checking for the remnants, some leftovers? What is this type of attack? How long would it last? Do I have to monitor my PC for a while for any unusual activities or it's not needed? Is an OS reinstall even needed?(I have a lot of files I'm too afraid to lose). I'm not even sure if I can trust kaspersky. I'm clearly clueless on how to read these results kaspersky sending out so any help at all would be appreciated.

Current identified damage: Steam account, EA account, Discord account. I minimized damage by suspending the accounts or changing passwords. Other accounts seems to be fine for now.

I'm horrible with pressure and stuff like this put a heavy toll on my mentality. 

Full copy paste for Detected and Not processed powershell.exe

Event: Malicious object detected
User: DESKTOP-NPN53GS\Admin
User type: Initiator
Application name: powershell.exe
Application path: C:\Windows\System32\WindowsPowerShell\v1.0
Component: AMSI Protection
Result description: Detected
Type: Trojan
Name: HEUR:Trojan-Downloader.BAT.Agent.gen
Precision: Heuristic analysis
Threat level: High
Object type: File
Object name: amsi_stream_952
Object path: uid://
MD5 of an object: B3127F27D52B5A4B709C5ABD09B52141
Reason: Expert analysis
Databases release date: Today, 3/14/2026 2:30:00 PM

Name: HEUR:Trojan-Downloader.BAT.Agent.gen
Precision: Heuristic analysis
Threat level: High
Object type: File
Object name: amsi_stream_952
Object path: uid://
MD5 of an object: B3127F27D52B5A4B709C5ABD09B52141
Reason: Logged



image.thumb.png.498ce1529c62d8e624e1df2324bc37eb.pngimage.thumb.png.5f889fa431e86e22c2d71dc2198b1752.pngScreenshot2026-03-14175547.thumb.png.38821860fa7e340f8e339fdaa14c31fa.pngimage.thumb.png.cace6228357b012ae7e021cf0d43b9b3.png

Posted

Thank you for your reply.
I'm sorry, I don't quite get what are you trying to have me to do.
So if I understand correctly, 

https://opentip.kaspersky.com/B3127F27D52B5A4B709C5ABD09B52141/results?tab=lookup
Is the type of malware I'm getting infected by, which I can't read nor understand anything from the site.

From this site: https://support.kaspersky.com/kis/2018/en-US/96493.htm
I have to download: https://rufus.ie/en/
Get a USB? or perhaps install on a separate external disk is fine?
I can't find the ISO file anywhere at all
Following this guide: https://support.kaspersky.com/kis/2018/en-US/43538.htm
It seems that it's some sort of software, and I can just set it up like most other software or something?
Then follow the rest of the tutorial? 



I dread my own lack of knowledge...

 

harlan4096
Posted

That tool of Kaspersky (Kaspersky Rescue Disk), allows scanning from a separated Windows system, actually it's in Linux environment... 

 

KRD it's used to scan and disinfect systems.

  • Like 2
harlan4096
Posted

Yes, that warning is common, just click ok.

  • Thanks 1
Posted

I've finished setting up KRD, following this tutorial: https://www.youtube.com/watch?v=r9Wezti9TUU,
I see this warning, do I have to be careful with this?

 

Kaspersky Rescue Disk modifies system files of the operating system. This may make your operating system inoperable. We recommend creating a backup copy of your operating system before using Kaspersky Rescue Disk.

There seems to be a typo of some sorts in: https://support.kaspersky.com/krd/24/272963
Open the system menu icon_krd_system.png and select Administration → Cleanup KRD artefacts. (Considering the difference of the text in the image, I'll just assume it's a typo)

Reading this: https://support.kaspersky.com/krd/24/269992
I'm seeing that there's only 1 infected in C disk, should I do a full scan or just C disk specifically?

The thing I'm most afraid of right now is probably a restart, since getting powershell start on start up, I haven't done a restart aside from installing kaspersky, am I safe doing a restart or shut down?

 

  • Like 1
harlan4096
Posted

Can You post a capture of the infected file?

 

Scan specially these folders:

 

C.\ProgramData\

C:\Users\

C:\Windows\

Posted

I followed the path to the infected file:
C:\Windows\System32\WindowsPowerShell\v1.0
 

image.thumb.png.fee3af31cdcfe449746155fd82929f4b.png

Thanks, so this is what I should be doing:
Shut down my pc, then boot it up using the KRD, scan specifically these folders:
C:\ProgramData\

C:\Users\

C:\Windows\

There should generally be no issues with shutting down or restarting after doing this?

  • Like 1
Schulte
Posted

Hi @QQxR,

One more thing:
“powershell.exe” itself probably isn't the problem.
It looks more like the infected object is a script that requires an active PowerShell session to run.
There are many ways the script could be launched. I would start by checking the Task Scheduler for any unknown entries. Maybe that's where the script (“anyName.ps1”) is being launched?

  • Like 1
harlan4096
Posted

It's weird that VirusTotal system does not know yet the ps1 file detected (B3127F27D52B5A4B709C5ABD09B52141) 

Posted

Hi, @Schulte
image.thumb.png.6fce897e046dea73d4cea6bc069827f3.png

This is my Task Scheduler so far, (Only task scheduler library) I don't see any strange tasks I don't recognize, I may be missing something, is there anything suspicious or locations required further checking?

  • Like 1
Posted

Actually, am I good to go with a KRD scan now?...

 

Schulte
Posted

Just a quick check:
Could you please take a look at the ‘UpdateHostsFile’ task? Does a script run here?
Unfortunately, I don't have Windows 11 available right now to verify this.
I'm sure @harlan4096 can help with this...

... and then continue with the KRD.

  • Like 2
Posted

You meant the one start at 12:00AM every day? As far as I can remember, it's one I created my own. 

Action: Start a porgram, start the right program I directed it to, I don't see powershell here, conditions, settings, history doesn't show anything strange,...
image.thumb.png.d367da3aec08ea18fcf3e345d966f5cf.png
Thanks, I'll go for a KRD scan now

  • Like 1
Schulte
Posted

The interesting part can be found on the ‘Actions’ tab.
Note: Kaspersky doesn't really like it when the ‘Hosts’ file is modified. It is protected by default.

  • Like 3
Posted

image.thumb.png.1f12c6e7cac38c0e998cbf5fbbe8c559.png
After doing an 80% KRD scan (Yes, for some reason I misclicked and stopped the scan), and restart the pc, I don't see powershell open up on start up anymore.) Both the quarantined objects and Reports didn't show anything in particular. 
There's still a questionable ScreenImage.png (Is this legit? or even common at all to be in temp?)

image.thumb.png.eefcbdc8c99574fd5f6b24e3701c10f1.png

AMSI Protection still sending powershell.exe, though, this is strange... I'm not even sure what is going on anymore...

image.thumb.png.81afa3aef738e89cd4c2008896e4f0ab.png

It's very late right now, and I'm really getting very exhausted of having to deal with this... I may redo the scan tomorrow if needed...
 

  • Like 1
Posted (edited)

Should I wait for tomorrow or am I generally good to go for now? I'm extremely paranoid about the AMSI Protection keep marking powershell.exe. Do I just have to keep monitoring this or anything?
My full timeline:
image.thumb.png.2c817306ae8fe7d609b3dc62a5ea5c68.png
image.thumb.png.ee95bc6762692becfd0de08b7a8a2ab1.png

Edited by QQxR
add images
harlan4096
Posted

Check Windows StartUp Apps:

Quote

Tips for Seeing Startup Programs in Windows 11

  • Use Task Manager: You can also use Task Manager by pressing Ctrl + Shift + Esc, then clicking the Startup tab to manage startup programs.
  • Research Programs: Before disabling, research unknown programs to ensure they’re not crucial to system operations.
  • Consider Impact: Focus on programs with high impact ratings, as these affect startup time the most.
  • Regularly Review: Make it a habit to review startup programs every few months to adapt to new installations or updates.
  • Backup Settings: Create a system restore point before making changes, so you can revert if necessary.
Posted

I actually don't like it when I start up my pc with a tons of softwares so I actually disabled most of them.
This is my start up list: 
image.thumb.png.54be547843973a090c6d9a5a3a06d6bb.png
I think I recognize all of them, is there anything catch your attention?

Posted

Random trojan getting downloaded!

I was browsing kaspersky forum for some related issues and had this thing pop up?
Screenshot2026-03-15001843.thumb.png.6c900ab963cdeb2063226fa535224ff1.png
This is... questionable, so my pc is still infected after all? I'm getting more and more clueless...

 

This is the most recent logs:
Event: Malicious object detected
User: DESKTOP-NPN53GS\Admin
User type: Initiator
Application name: powershell.exe
Application path: C:\Windows\System32\WindowsPowerShell\v1.0
Component: AMSI Protection
Result description: Detected
Type: Trojan
Name: HEUR:Trojan-Downloader.BAT.Agent.gen
Precision: Heuristic analysis
Threat level: High
Object type: File
Object name: amsi_stream_193
Object path: uid://
MD5 of an object: B3127F27D52B5A4B709C5ABD09B52141
Reason: Expert analysis
Databases release date: Yesterday, 3/14/2026 9:42:00 PM

Event: The object scan result has been sent to a third-party application
User: DESKTOP-NPN53GS\Admin
User type: Initiator
Application name: powershell.exe
Application path: C:\Windows\System32\WindowsPowerShell\v1.0
Component: AMSI Protection
Result description: Not processed
Type: Trojan
Name: HEUR:Trojan-Downloader.BAT.Agent.gen
Precision: Heuristic analysis
Threat level: High
Object type: File
Object name: amsi_stream_193
Object path: uid://
MD5 of an object: B3127F27D52B5A4B709C5ABD09B52141
Reason: Logged

  • Like 1

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...