Trojan:PowerShell/DownInfo.BA

Anonymous
2025-06-11T15:19:14+00:00

Hi, I was wondering if anyone could help me to fix the issue i am facing? It just happened about 2 hours ago when suddenly i got multiple pop ups from Windows Security.

Does anyone know how to fix this? Trojan:PowerShell/DownInfo.BA

CmdLine: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -NoProfile -EncodedCommand IwAgADcAMAA3ADcAMgBiAGQAOQAtADkANgAzAGMALQA0ADUAOAAzAC0AYQA3AGMANwAtADUAMAA3AGUANQAwADkAMwAwAGEAMAA2AAoAJABQAHIAb

Thank you in advance.

Andy

[command-line truncated ~moderator]

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Ramesh 181.2K Reputation points Volunteer Moderator
2025-06-11T15:34:07+00:00

A scheduled task triggers the command. Please do the following:

  1. Boot into Safe mode. https://support.microsoft.com/en-us/windows/windows-startup-settings-1af6ec8c-4d4a-4b23-adb7-e76eef0b847f

Open admin Command Prompt and run these commands:

  • netsh.exe winhttp reset proxy
  • bitsadmin /util /setieproxy localsystem NO_PROXY RESET
  • rd /s /q C:\Windows\system32\DomainAuthHost

Post the output.

  1. Share your Farbar scan logs for analysis.
  1. Download Farbar Recovery Scan Tool 64-bit (FRST64.exe)

https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/

Note: If Microsoft Edge or Chrome mislabels the Farbar Scanner executable as PUA/malware, choose to keep it by tapping … in the bottom bar, choosing Keep, and then choosing Keep anyway in the dialog that appears.

See this screenshot: https://learn.microsoft.com/en-us/deployedge/media/microsoft-edge-security-download-interruptions/dowload-was-blocked.png. It's a safe tool used in most antimalware forums.

  1. If the OS language is not English, rename FRST64.exe to FRST64English.exe.
  2. Run the program. Don't check or uncheck any options. Click "Scan".
  3. Add the two logs, FRST.txt and Addition.txt, to a Zip archive, share them on OneDrive or GoFile.io and post the link here.

**************************************************************

Additional note:

The Trojan:PowerShell/DownInfo.BA threat detection was added to Defender on 6/10/2025 10:52 PM (in security intelligence version 1.429.460.0). That's the same day the latest cumulative update was released. This makes the users think the LCU caused this 'false-detection'. In reality, their systems were already infected, and the infection came to light after installing security intelligence update version 1.429.460.0 on June 10.

https://www.microsoft.com/en-us/wdsi/definitions/antimalware-definition-release-notes?requestVersion=1.429.460.0

**************************************************************

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

186 additional answers

Sort by: Newest
  1. Anonymous
    2025-06-12T12:43:14+00:00

    Hi

    Thank you very much for your help

    https://gofile.io/d/zGToeC Thi is the Fixlog

    Thanks again

    Alex

    Hi Alex,

    The script ran fine. Do you use the following services?

    • MobaSSH1
    • OpenDHCPServer

    If you need them, please enable them using Services MMC.

    Run the Kaspersky scanner to ensure everything is clean.

    https://www.kaspersky.co.in/downloads/free-virus-removal-tool

    Configure KVRT as in the image below and run a scan. Post the detection report here.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2025-06-12T12:29:52+00:00

    Hi

    Thank you very much for your help

    https://gofile.io/d/zGToeC Thi is the Fixlog

    Thanks again

    Alex

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2025-06-12T12:27:45+00:00

    i have the same problem , much worse this virus does not allow me to connect to internet what should I do ?

    Please start a new thread and post the details there.

    Click Ask a new question

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2025-06-12T12:25:26+00:00

    A scheduled task triggers the command. Please share your Farbar scan logs for analysis.

     

    1. Download Farbar Recovery Scan Tool 64-bit (FRST64.exe)

    https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/

      

    Note: If Microsoft Edge or Chrome mislabels the Farbar Scanner executable as PUA/malware, choose to keep it by tapping … in the bottom bar, choosing Keep, and then choosing Keep anyway in the dialog that appears.

    See this screenshot: https://learn.microsoft.com/en-us/deployedge/media/microsoft-edge-security-download-interruptions/dowload-was-blocked.png. It's a safe tool used in most antimalware forums.

     

    1. If the OS language is not English, rename FRST64.exe to FRST64English.exe.
    2. Run the program. Don't check or uncheck any options. Click "Scan".
    3. Add the two logs, FRST.txt and Addition.txt, to a Zip archive, share them on OneDrive or GoFile.io and post the link here.

    Hi Ramesh, Thank you for assisting. Below is the link to the FRST.txt and Addition.txt zipped.

    https://filego.io/0sjwy9om

    Hi Andy Chan5,

    Please run this fixlist.

    Download fixlist.txt

    Save Fixlist.txt to the same folder as FRST64English.exe.

    Close all programs.

    Launch the Farbar Scanner tool and click "Fix".

    Restart Windows when prompted.

    Upload the output log file (FixLog.txt) to GoFile.io.

    NOTE: The fixlist.txt script was written specifically for this user and for use on that particular machine. It is not recommended to run it on another machine, and don't run the same fixlist.txt more than once.

    Was this answer helpful?

    0 comments No comments