Search the Community
Showing results for tags 'psscriptload'.
Addition.txt FRST.txt mbamlog-568.txt Have removed registry entries and quarantined several times. It scans great for 3 days and then they are back. User stated "little black window" flashes on the screen from time to time. I've not witnessed the behavior myself. We have 2 machines with identical issues. Help is sincerely appreciated.
MalwareBytes scan result Been getting these results everyday for a while now. They will always come back. I will sometimes notice a weird blue command prompt appearing for a quick moment before it disappears again. I think it's related to this. I've tried: -Running HitmanPro, Zemana, JRT and adwcleaner along with MalwareBytes. -Resetting Firefox and uninstalling it. -Checked my DNS settings. -Made sure I got the latest MalwareBytes version. I've scanned with Farbar recovery scan tool, files attached below. Thanks. FRST.txt Addition.txt
same problem here Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 6/17/17 Scan Time: 3:22 AM Log File: copy.txt Administrator: Yes -Software Information- Version: 22.214.171.1243 Components Version: 1.0.141 Update Package Version: 1.0.2169 License: Premium -System Information- OS: Windows 10 CPU: x64 File System: NTFS User: System -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 474375 Threats Detected: 5 Threats Quarantined: 5 Time Elapsed: 6 min, 17 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 2 PUP.Optional.PSScriptLoad.EncJob, HKU\S-1-5-21-4156014727-51673578-1275472258-1001\CONSOLE\%SYSTEMROOT%_SYSTEM32_SVCHOST.EXE, Quarantined, , ,1.0.2169 PUP.Optional.PSScriptLoad.EncJob, HKU\S-1-5-21-4156014727-51673578-1275472258-1001\CONSOLE\TASKENG.EXE, Quarantined, , ,1.0.2169 Registry Value: 3 PUP.Optional.PSScriptLoad.EncJob, HKU\S-1-5-21-4156014727-51673578-1275472258-1001\CONSOLE\%SYSTEMROOT%_SYSTEM32_SVCHOST.EXE|WINDOWPOSITION, Quarantined, , ,1.0.2169 PUP.Optional.PSScriptLoad.EncJob, HKU\S-1-5-21-4156014727-51673578-1275472258-1001\CONSOLE\%SYSTEMROOT%_SYSTEM32_WINDOWSPOWERSHELL_V1.0_POWERSHELL.EXE|WINDOWPOSITION, Quarantined, , ,1.0.2169 PUP.Optional.PSScriptLoad.EncJob, HKU\S-1-5-21-4156014727-51673578-1275472258-1001\CONSOLE\TASKENG.EXE|WINDOWPOSITION, Quarantined, , ,1.0.2169 Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 0 (No malicious items detected) File: 0 (No malicious items detected) Physical Sector: 0 (No malicious items detected) (end) Addition.txt FRST.txt