Windows powershell suddenly but often gives this entry in event viewer for the past month.
Windows powershell suddenly but often gives this entry in event viewer for the past month.

As the title says. I tried malwarebytes pro and it started blocking a bunch of websites attempting to connect to my PC. Malwarebytes blocked them and another user on reddit said it was scareware.

Now after that I got very suspicious of my computer for some reason. Adwcleaner, malwarebytes and windows defender didn’t find anything though, never have.

Now three days ago I used cmd to get rid of some razer files that were stubborn and it worked. I didn’t use my computer yesterday and today when I booted it up I got a controlled folder access notification that powershell.exe was blocked trying to acces %system%configsystemprofile and %system%CatRoot just before.

I dove into my powershell event log and noticed that from about a month ago the event viewer is full of this, happening 30 times within 2 minutes after which it stops. All of them being the same hostapplication entry but just state changes or something like: provider “alias” (or environment, filesystem, variable, function, registry) is started.

Before a month ago it was the same thing but the hostApplication would look like this: Powershell.exe -ExecutionPolicy Restricted -Command Write-Host ‘Final result: 1’; It was like that for 2,5 years, up untill a month ago.

Sorry for the text, but should I be worried?

submitted by /u/Background-Soupp
[link] [comments]

Go to Source of this post
Author Of this post: /u/Background-Soupp

By admin