Trojan:PowerShell/DownInfo.BA

Anonymous
2025-06-11T15:19:14+00:00

Hi, I was wondering if anyone could help me to fix the issue i am facing? It just happened about 2 hours ago when suddenly i got multiple pop ups from Windows Security.

Does anyone know how to fix this? Trojan:PowerShell/DownInfo.BA

CmdLine: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -NoProfile -EncodedCommand IwAgADcAMAA3ADcAMgBiAGQAOQAtADkANgAzAGMALQA0ADUAOAAzAC0AYQA3AGMANwAtADUAMAA3AGUANQAwADkAMwAwAGEAMAA2AAoAJABQAHIAb

Thank you in advance.

Andy

[command-line truncated ~moderator]

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Ramesh 181.2K Reputation points Volunteer Moderator
2025-06-11T15:34:07+00:00

A scheduled task triggers the command. Please do the following:

  1. Boot into Safe mode. https://support.microsoft.com/en-us/windows/windows-startup-settings-1af6ec8c-4d4a-4b23-adb7-e76eef0b847f

Open admin Command Prompt and run these commands:

  • netsh.exe winhttp reset proxy
  • bitsadmin /util /setieproxy localsystem NO_PROXY RESET
  • rd /s /q C:\Windows\system32\DomainAuthHost

Post the output.

  1. Share your Farbar scan logs for analysis.
  1. Download Farbar Recovery Scan Tool 64-bit (FRST64.exe)

https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/

Note: If Microsoft Edge or Chrome mislabels the Farbar Scanner executable as PUA/malware, choose to keep it by tapping … in the bottom bar, choosing Keep, and then choosing Keep anyway in the dialog that appears.

See this screenshot: https://learn.microsoft.com/en-us/deployedge/media/microsoft-edge-security-download-interruptions/dowload-was-blocked.png. It's a safe tool used in most antimalware forums.

  1. If the OS language is not English, rename FRST64.exe to FRST64English.exe.
  2. Run the program. Don't check or uncheck any options. Click "Scan".
  3. Add the two logs, FRST.txt and Addition.txt, to a Zip archive, share them on OneDrive or GoFile.io and post the link here.

**************************************************************

Additional note:

The Trojan:PowerShell/DownInfo.BA threat detection was added to Defender on 6/10/2025 10:52 PM (in security intelligence version 1.429.460.0). That's the same day the latest cumulative update was released. This makes the users think the LCU caused this 'false-detection'. In reality, their systems were already infected, and the infection came to light after installing security intelligence update version 1.429.460.0 on June 10.

https://www.microsoft.com/en-us/wdsi/definitions/antimalware-definition-release-notes?requestVersion=1.429.460.0

**************************************************************

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

186 additional answers

Sort by: Most helpful
  1. Anonymous
    2025-06-29T15:03:58+00:00

    Gracias!! Con tu ayuda y un poco de Chat GPT pude lograr quitar el Troyano. Las instrucciones que seguí por si a alguien le sirven:

    🛠️ RESUMEN: Cómo solucioné el problema de conexión causado por un troyano (PowerShell/DownInfo.BA) 🧩 1. Detección del problema

    • WhatsApp Desktop, Microsoft Store y descarga de imágenes/audios dejaron de funcionar.
    • El navegador funcionaba, pero algunas apps no.
    • El solucionador de problemas de red mencionaba:

    “El servidor proxy no responde”

    • Microsoft Defender detectó:
      👉 Troyano: PowerShell/DownInfo.BA

    🔎 2. Revisión de tareas programadas

    • Abrí el Programador de tareas (Win + R > taskschd.msc)
    • Detecté una tarea sospechosa:
      MicrosoftPathHealthChecker
    • Ejecutaba comandos PowerShell ocultos (codificados en Base64)

    3. Eliminación de la tarea maliciosa

    • Abrí CMD como administradora
    • Ejecuté:
        bashCopiarEditarschtasks /delete /f /tn MicrosoftPathHealthChecker
      

    🚫 4. Después del reinicio: sin conexión

    • No había internet, ni siquiera con red móvil
    • El diagnóstico de Windows detectó:

    “El servidor proxy configurado no responde”


    🔧 5. Desactivación manual del proxy

    1. Abrí Opciones de Internet (Win + R > inetcpl.cpl)
    2. Fui a la pestaña Conexiones > Configuración de LAN
    3. Destildé “Usar un servidor proxy para su LAN”
    4. Activé “Detectar configuración automáticamente”
    5. Guardé cambios y reinicié

    🎉 6. Resultado

    • ¡La conexión volvió!
    • WhatsApp Desktop y Microsoft Store funcionaban nuevamente
    • La PC dejó de detectar el troyano

    ✅ Recomendaciones finales

    • Hacer un escaneo profundo con Malwarebytes Free
    • Revisar periódicamente el Programador de tareas
    • No ejecutar archivos raros ni hacer clic en enlaces dudosos
    • Guardar este resumen 😉

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2025-06-28T02:50:17+00:00

    Hello, friend.

    Please help!

    Follow the zip

    https://gofile.io/d/8R4HtV

    @Natanael Sakuno:

    1. Open admin Command Prompt and run this command:
    • schtasks /delete /f /tn OneDriveSoftwareHealthCheckerTask

    Post the output.

    1. Run this fixlist.txt.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2025-06-28T01:17:50+00:00

    Hello, friend.

    Please help!

    Follow the zip

    https://gofile.io/d/8R4HtV

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2025-06-27T09:51:50+00:00

    Hello Ramesh,

    J recently ran into the same problem.

    Here's the link to the logs

    https://gofile.io/d/tDYVBf

    Thanks,

    Regards,

    Mugambi,

    @Mugambi:

    There is an illegal KMS software running on your system. Such software is unlawful to use on home systems. The use of such software is prohibited in this forum. We can help you after you get a genuine Windows license.

    Was this answer helpful?

    0 comments No comments