Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
“PowerShell Trojan” is not a precise malware diagnosis. PowerShell is a legitimate Windows tool that malware can abuse, but the actual problem may be a malicious script, scheduled task, startup entry, browser extension, downloaded executable, or even a browser scam alert. Disconnect the affected PC, record the detection details, update Microsoft Defender, and run a Microsoft Defender Offline scan before deleting anything manually.
What “PowerShell Trojan” can mean
The phrase describes how a threat was detected or launched—not a unique malware family. Possible explanations include:
- A Trojan stored inside a
.ps1PowerShell script. - Malware launched by the legitimate
powershell.exeprogram. - A scheduled task, shortcut, registry startup entry, or startup app that invokes PowerShell.
- A downloaded executable or second-stage payload delivered by a PowerShell command.
- A legitimate administrative script incorrectly flagged by security software.
- A fake file named
powershell.exein an unusual folder. - A browser notification, malicious advertisement, or scam page displaying a fake PowerShell warning.
Suspicious commands can include -EncodedCommand, -WindowStyle Hidden, -ExecutionPolicy Bypass, -NoProfile, -NonInteractive, Invoke-WebRequest, Start-BitsTransfer, or IEX/Invoke-Expression. None proves an infection by itself. The file path, digital signature, parent process, timing, and persistence mechanism matter.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchThe Malwarebytes forum title “I have a powershell trojan that i cant get rid of, please help!” should be treated as a historical troubleshooting example. Without the original logs, detection name, Windows version, and final remediation details, it cannot establish what that particular computer actually had—or what every similar alert means today.
#1 Best Overall
- ONGOING PROTECTION Download instantly & install protection for 3 PCs, Macs, iOS or Android devices in minutes!
- TOP-PERFORMING VPN Faster speeds, more server locations, and greater connection control to protect your privacy across all your devices, including Smart TVs.
- ADVANCED SCAM PROTECTION Help spot hidden scams online. With the built-in Genie AI assistant, you’ll never wonder if a message or email is suspicious again.
- REAL-TIME PROTECTION Advanced security protects against existing and emerging malware threats, including ransomware and viruses, and it won’t slow down your device performance.
- DARK WEB MONITORING Identity thieves can buy or sell your information on websites and forums. We search the dark web and notify you should your information be found.
Before removing anything: contain the computer and preserve evidence
- Save your work and disconnect Wi-Fi or unplug Ethernet if active compromise is suspected.
- Do not use the affected computer to access banking, email, password managers, social accounts, or other sensitive services.
- From a known-clean device, change important passwords and enable multifactor authentication. Prioritize email, financial accounts, Microsoft accounts, password managers, and any account used on the suspect PC.
- If the computer belongs to an employer or school, contact IT before deleting files or tasks. Local cleanup can destroy useful evidence.
- Avoid repeatedly rebooting if a professional needs to preserve evidence.
Before quarantine history disappears, record the exact detection name, full file path, detection time, parent process, command line, and whether the item was quarantined, blocked, removed, or merely detected. Also note recurring pop-ups, the time they appear, recent installations, and whether the alert returns after login or reboot.
Do not publish complete logs without removing usernames, email addresses, IP addresses, product keys, browser-session data, and personal file paths.
Run Microsoft Defender in stages
Reconnect only when necessary to update security intelligence, then disconnect again if the machine appears actively compromised. On a stable Windows installation, start with the built-in antivirus:
Free tools Windows power users keep installed
One-click scans. No signup required.
- Open Start → Settings → Windows Security → Virus & threat protection.
- Update the security intelligence if an update option is available.
- Run a Quick scan.
- If the alert is persistent or the affected locations are unknown, open Scan options and run a Full scan.
Microsoft describes quick scans as focusing on common malware-start locations while noting that malicious files can exist elsewhere. Real-time and cloud protection complement scans; a clean quick scan is not proof that the entire system has been examined.
If the same detection returns, security tools are being disabled, or PowerShell relaunches during normal Windows operation, run Microsoft Defender Offline:
- Open Start → Settings → Windows Security → Virus & threat protection → Scan options.
- Select Microsoft Defender Offline scan.
- Choose Scan now.
The computer restarts before the offline scan begins and examines the system outside the normal Windows environment. Menu wording can differ between Windows 10, Windows 11, editions, and managed devices. Microsoft specifically recommends Offline scanning when the same malware keeps returning. See Microsoft’s malware detection and removal guidance.
Advanced option: Defender from Command Prompt
Advanced users can use Microsoft’s elevated Defender command-line utility, MpCmdRun.exe. Its location may be:
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #2
- DEVICE SECURITY - Award-winning McAfee antivirus, real-time threat protection, protects your data, phones, laptops, and tablets
- SCAM DETECTOR - We'll automatically identify risky texts, emails, and videos that attempt to steal your personal or financial information. You can even use our mobile app to check social messages and QR codes for scams on-demand, without missing a beat.
- SECURE VPN – Secure and private browsing, unlimited VPN, privacy on public Wi-Fi, protects your personal info, fast and reliable connections
- IDENTITY MONITORING – 24/7 monitoring and alerts, monitors the dark web, scans up to 60 types of personal and financial info
- SAFE BROWSING – Guides you away from risky links, blocks phishing and risky sites, protects your devices from malware
C:Program FilesWindows Defender
or a versioned platform directory such as:
C:ProgramDataMicrosoftWindows DefenderPlatform<antimalware platform version>
After verifying the actual location, open Command Prompt as administrator and use:
cd /d "%ProgramFiles%Windows Defender"
MpCmdRun.exe -Scan -ScanType 2
-ScanType 2 is commonly used for a full scan, but command availability and installed paths can vary. Confirm the syntax in Microsoft’s current MpCmdRun documentation. Do not disable Defender or add broad exclusions to make a scan complete.
Find what is relaunching PowerShell
When a detection returns at every login, the payload may be gone while its launcher remains—or a downloader may be recreating it. Inspect persistence only after scanning and recording the evidence.
Scheduled Tasks
Open Task Scheduler → Task Scheduler Library. Review recently created or suspicious tasks and inspect:
- Author and description.
- Triggers, such as logon, startup, idle, time-based, or event-based execution.
- The complete action and command line.
- The script or executable path.
- Whether it runs as SYSTEM or with elevated privileges.
Do not delete a task merely because it uses PowerShell. Windows and legitimate applications use scheduled PowerShell tasks. A task is more suspicious when its action points to a user-writable temporary folder, an oddly named script, an unsigned executable, or a location unrelated to its stated author.
For a clearly malicious task, record its details, disable it first, and rescan. Permanently delete it only after confirming that it is not required by Windows or trusted software.
Startup apps and Run entries
Check Settings → Apps → Startup and Task Manager → Startup apps. Also review the user and system Startup folders and registry Run and RunOnce entries.
Rank #3
- ONGOING PROTECTION Download instantly & install protection for 5 PCs, Macs, iOS or Android devices in minutes!
- TOP-PERFORMING VPN Faster speeds, more server locations, and greater connection control to protect your privacy across all your devices, including Smart TVs.
- ADVANCED SCAM PROTECTION Help spot hidden scams online. With the built-in Genie AI assistant, you’ll never wonder if a message or email is suspicious again.
- REAL-TIME PROTECTION Advanced security protects against existing and emerging malware threats, including ransomware and viruses, and it won’t slow down your device performance.
- DARK WEB MONITORING Identity thieves can buy or sell your information on websites and forums. We search the dark web and notify you should your information be found.
Disable a clearly suspicious startup item before deleting its referenced file. Record the path and command, then run another scan. Judge the complete path and publisher—not just the filename.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
PowerShell profiles
A PowerShell profile runs when a particular PowerShell host starts. To display the current user profile path, run:
$PROFILE
Profiles vary by user and host. Review the file for unfamiliar commands rather than deleting it automatically; it may contain legitimate customizations.
Shortcuts, browsers, and recent applications
Inspect suspicious shortcuts and look for commands appended after the normal application path. Review recently installed applications, browser extensions, browser notification permissions, and downloads.
A browser scareware page can display a convincing “PowerShell virus” warning without installing a resident Trojan. Remove unwanted notification permissions, close the page, uninstall suspicious extensions, and scan the computer. Do not call a phone number or install a “cleanup” tool offered by the warning.
Recommended Free Tools
Execution policy will not remove the infection
Check the policies applied at different scopes with:
Get-ExecutionPolicy -List
Some users try:
Set-ExecutionPolicy Restricted
This may reduce accidental script execution, but it is not a cure. It does not terminate a running process, remove a scheduled task, delete a downloaded payload, or undo account compromise. Microsoft states that PowerShell execution policies are a safety feature, not a security system, and malicious software can bypass them. Group Policy can also override local settings. Read Microsoft’s execution-policy documentation.
Rank #4
- SPEED-OPTIMIZED, CROSS-PLATFORM PROTECTION: World-class antivirus security and cyber protection for Windows (Windows 7 with Service Pack 1, Windows 8, Windows 8.1, Windows 10, and Windows 11), Mac OS (Yosemite 10.10 or later), iOS (11.2 or later), and Android (5.0 or later). Organize and keep your digital life safe from hackers
- SAFE ONLINE BANKING: A unique, dedicated browser secures your online transactions; Our Total Security product also includes 200MB per day of our new and improved Bitdefender VPN
- ADVANCED THREAT DEFENSE: Real-Time Data Protection, Multi-Layer Malware and Ransomware Protection, Social Network Protection, Game/Movie/Work Modes, Microphone Monitor, Webcam Protection, Anti-Tracker, Phishing, Fraud, and Spam Protection, File Shredder, Parental Controls, and more
- ECO-FRIENDLY PACKAGING: Your product-specific code is printed on a card and shipped inside a protective cardboard sleeve. Simply open packaging and scratch off security ink on the card to reveal your activation code. No more bulky box or hard-to-recycle discs. PLEASE NOTE: Product packaging may vary from the images shown, however the product is the same.
If you change a policy, treat it as an administrative hardening measure after cleanup—not as malware removal.
Use Malwarebytes as an optional second opinion
Malwarebytes can provide an additional on-demand check after or alongside Defender. Its current Windows feature table lists Quick Scan and Custom Scan as free, while Threat Scan, scheduled scanning, real-time protection, and web protection are paid features. See the Malwarebytes feature comparison.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →The free scanner can be useful when Defender finds nothing, but it is not required to run Defender Offline. Buying a subscription does not replace investigating persistence, changing exposed passwords, or reinstalling a compromised system. Avoid installing several products with overlapping real-time antivirus protection.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.If the detection keeps returning
A recurring alert does not always mean the same process is still active. Possible causes include:
- A scheduled task recreates a quarantined file.
- A second-stage downloader remains.
- A cache, restore point, or backup restores the file.
- A browser extension or unwanted application relaunches it.
- The detection is a false positive or a stale notification.
- A work-managed security policy is reinstalling an approved script.
- Malware has tampered with security settings.
Compare the new and old detection paths, timestamps, hashes where available, and protection-history status. Confirm whether each item was quarantined, removed, blocked, or allowed. Then run Defender Offline, perform an optional second-opinion scan, and review scheduled tasks and startup entries again.
If a trusted, digitally signed file is being flagged, do not delete it solely by name. Check its location, publisher, parent process, and vendor reputation, and submit the detection or file to the security vendor for analysis using the vendor’s official process.
When resetting or reinstalling Windows is safer
Stop manual cleanup and consider a Windows reset or clean reinstall when:
Best Value
- DEVICE SECURITY - Award-winning McAfee antivirus, real-time threat protection, protects your data, phones, laptops, and tablets
- SCAM DETECTOR - We'll automatically identify risky texts, emails, and videos that attempt to steal your personal or financial information. You can even use our mobile app to check social messages and QR codes for scams on-demand, without missing a beat.
- SECURE VPN – Secure and private browsing, unlimited VPN, privacy on public Wi-Fi, protects your personal info, fast and reliable connections
- IDENTITY MONITORING – 24/7 monitoring and alerts, monitors the dark web, scans up to 60 types of personal and financial info
- SAFE BROWSING – Guides you away from risky links, blocks phishing and risky sites, protects your devices from malware
- The detection survives Defender Offline.
- The attacker may have had administrator access.
- Defender, Task Manager, Registry Editor, or Windows Update was disabled.
- Unknown administrator accounts or remote-access tools appear.
- Credential theft, ransomware, or rootkit activity is suspected.
- System files or security settings were materially altered.
- The computer handles banking, business, healthcare, or other sensitive information.
- You cannot confidently identify and remove the persistence mechanism.
Microsoft notes that irreversible malware changes may require resetting the PC and restoring files from backup. Backups created after infection may contain malicious scripts or altered documents. Preserve only necessary data, scan it, and reinstall applications from official sources. A clean reinstall provides higher confidence than repeatedly deleting individual files when the compromise cannot be explained.
After the computer is clean
- Change passwords from a known-clean device and enable MFA.
- Review email forwarding rules, account recovery details, active sessions, and unfamiliar sign-ins.
- Monitor bank and payment accounts if financial information was used on the PC.
- Update Windows, browsers, extensions, and applications.
- Remove unused or untrusted browser extensions.
- Restore only scanned personal files from backups.
- Keep one primary real-time antivirus product enabled and avoid broad exclusions.
FAQ
Can I delete PowerShell?
No. Do not delete powershell.exe or other Windows components based only on an alert. PowerShell is a legitimate Windows component, and removing it can damage administration and trusted software without removing the actual persistence mechanism.
Does -ExecutionPolicy Bypass prove malware?
No. It is a suspicious signal because malware commonly uses it, but legitimate installers and administration tools may also use it. Verify the script path, publisher, parent process, task, and context.
Can System Restore bring the detection back?
It can restore older files or system state, so a restore point may reintroduce a malicious component or an old launcher. If a detection returns after restoration, rescan and avoid restoring unverified system state.
How do I know whether an alert is a false positive?
Compare the exact detection, path, signature, publisher, command line, and behavior. A trusted path or publisher does not guarantee safety, but a random user-writable path is a warning sign. Submit uncertain files to the security vendor rather than overriding or deleting them blindly.
For the original forum-style problem, the safest conclusion is not “delete PowerShell.” It is to identify what starts the command, scan outside normal Windows operation, protect exposed accounts, and reinstall when persistence or compromise cannot be explained.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errors

