Search the Community
Showing results for tags 'downloadstring'.
Found 1 result
Hi Malwarebytes support, My windows 10 was affected by adware/malware and I have used malwarebytes to remove most of it. However, there' still one malware that can't be removed by malwarebytes. Whenever I startup my windows a powershell cmd appears for a brief second and disappears. I took a screenshot for your reference (refer to attached). It appears to be a powershell command that executes new-object net.webclient.downloadstring(URL). Malwarebyte then detects a malware found at the location c:\windows\winime.exe and quarantines it. Sometimes a myexe.exe malware is also found. Hence i remove it from the quarantine. But that did not fix the problem. Everytime i restart my laptop, the powershell launched again and malwarebytes detected the malware again and quarantine it. Process repeats at every startup. It appears to be that the powershell command that was executed at startup causes this. I have no idea how to remove that powershell cmd or prevent the it from running the command. Please help. Would greatly appreciate your help on this. Malwarebyte did not detect the powershell problem. Regards, Dil