Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

If Microsoft Defender repeatedly reports VirTool:Win32/ExcludeProc.D or Behavior:Win32/ExcludeProc.A while PowerShell runs with -EncodedCommand, treat the activity as suspicious and investigate it. In the documented case, the commands attempted to exclude executable files, DLLs, the user profile, and the system drive from Defender scans. That weakens protection, but the command line alone does not identify the original infection or prove that explorer.exe itself is malicious.

Do not run the encoded command. Preserve the alert and process details, find what launched PowerShell, remove only exclusions and persistence you can identify as unauthorized, then scan and verify that the activity does not return.

What the ExcludeProc command does

The detection names in this case point to suspicious behavior involving Microsoft Defender exclusions; they do not, by themselves, identify a unique malware family. The decoded commands reported in the case were:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Add-MpPreference -ExclusionExtension @('exe','dll') -Force
Add-MpPreference -ExclusionPath @($env:UserProfile,$env:SystemDrive) -Force

The first attempts to exclude files with the .exe and .dll extensions. The second attempts to exclude the current user profile and system drive. If accepted, exclusions that broad could leave many programs and locations outside normal Defender scanning. Unless you recognize a legitimate administrative reason for them, treat these commands as unauthorized and potentially malicious.

#1 Best Overall

These commands change scanning exclusions; they do not themselves download a payload. That distinction matters: blocking the command or removing an exclusion may reduce risk, but it does not establish what first launched it or whether other malware is present. The original BleepingComputer case described repeated detections at startup, encoded PowerShell, and high CPU use attributed to Explorer. It is a resolved incident, not a universal cleanup recipe.

Base64 encoding is not encryption

PowerShell’s -EncodedCommand option accepts a Base64 representation of command text, normally encoded as UTF-16LE (which .NET calls Unicode). Base64 is reversible encoding, not secrecy or encryption. Administrators use it in legitimate automation too; the decoded content and its context determine whether it is harmful. Microsoft documents the option and encoding format in its PowerShell command-line reference.

To inspect a Base64 value without executing its contents, copy only the value after -EncodedCommand and decode it in a PowerShell session:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Dell Latitude 3190 11.6" HD 2-in-1 Touchscreen Laptop Intel N5030 1.1Ghz 4GB Ram 128GB SSD Windows 11 Professional (Renewed)
  • 1.1 GHz (boost up to 2.4GHz) Intel Celeron N5030 Quad-Core
  • 4GB DDR4 System Memory; 128GB Solid State Drive
  • 11.6" HD (1366 x 768) Multi-Touch Display
  • Combo headphone/microphone jack - Noble Wedge Lock slot - HDMI; 2 USB 3.1 Gen 1
  • Windows 11 Pro
$encoded = 'PASTE_ONLY_THE_BASE64_VALUE_HERE'
[Text.Encoding]::Unicode.GetString(
    [Convert]::FromBase64String($encoded)
)

This prints text; it does not run the resulting command. Do not paste an unknown string into Invoke-Expression, Invoke-Command, or a PowerShell -Command execution path just to see what it does. If decoding fails or produces nonsense, the value may be incomplete, wrapped in extra command-line text, or encoded differently. Microsoft also provides a method for finding and decoding encoded commands in running processes in its running-process example.

Preserve evidence and contain the computer

  1. If compromise appears active, disconnect the computer from Wi-Fi or wired networking. For a work-managed or sensitive system, contact your IT or security team promptly rather than improvising repairs.
  2. Do not use the affected computer for sensitive sign-ins. Avoid banking, email, work, and password-manager accounts while you investigate. From a separate trusted device, change important passwords and revoke active sessions if credential theft is plausible.
  3. Save the evidence before cleanup. Photograph or save Defender’s detection name, time, affected item, and action; record the full PowerShell command line, process ID, executable path, parent process, and any suspicious task or startup entry. Keep relevant files and logs intact if the machine may need professional investigation.
  4. Do not run the decoded command or a fix intended for somebody else’s computer. Killing Explorer or deleting a file identified in another case can hide symptoms, destroy evidence, or damage a legitimate installation.

Check whether Defender exclusions were added

In Windows Security, open Virus & threat protection, then Virus & threat protection settings, and review Exclusions. The exact labels can vary slightly by Windows version or organizational policy. Look for exclusions covering an entire drive or profile, broad extensions such as .exe and .dll, or unfamiliar temporary, download, or AppData folders.

Remove exclusions you did not authorize, but do not blindly erase every entry. Some managed applications and development workflows use narrow, deliberate exclusions. If a device is managed by an employer, ask its administrator before changing policy-controlled settings. Record suspicious entries first; then remove unauthorized ones and rescan. If exclusions reappear, a process or policy may be restoring them, so continue looking for the launcher rather than repeatedly deleting the visible setting.

Rank #3
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
  • 256 GB SSD of storage.
  • Multitasking is easy with 16GB of RAM
  • Equipped with a blazing fast Core i5 2.00 GHz processor.

Identify the process and its launcher

Task Manager is a useful first look, but a process name is not proof of identity. A legitimate Windows process can be abused through injection or malicious module loading, and malware can also use a familiar-looking filename from a different directory. Check the full path, signature, command line, parent, start time, child processes, and loaded modules together.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft Sysinternals Process Explorer can show active processes, handles, and loaded DLLs. In its process tree, open the suspicious process’s properties and review its image path, verified signer, parent process, and command line; record the PID and start time. The expected Explorer path is normally C:Windowsexplorer.exe, and its signer should be Microsoft. A correct path or valid signature is reassuring evidence, not proof that the process has not been abused. Review unexpected children and unsigned or newly created modules in context; unsigned alone does not mean malicious. The current Microsoft page lists Windows 11 and Windows Server 2016 or later, so Windows 10 users should confirm current compatibility before relying on that utility. PowerShell and Task Manager remain alternatives, though they reveal less context.

To locate running PowerShell processes whose command lines contain the encoded-command option, Microsoft shows this query:

Rank #4
15.6 Inch Laptop Computer, N4020, 4GB DDR4 RAM, 128GB eMMC,with Windows 11
  • EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
  • 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
  • RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
  • ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
  • LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.
Get-CimInstance -ClassName Win32_Process `
  -Filter 'CommandLine LIKE "%EncodedCommand%"'

An elevated PowerShell session may be needed to see all relevant processes. Capture the output before stopping a process. The process that matters may be the parent or an earlier launcher, not Explorer itself.

Then work backward from what launched PowerShell. Review Task Scheduler for unfamiliar tasks triggered at logon, startup, idle, or on a recurring timer; inspect each task’s action and trigger. Check startup folders and Run/RunOnce registry entries, services and drivers, WMI permanent event subscriptions, Group Policy startup or logon scripts, PowerShell profiles, and suspicious shortcut arguments. Look for recently created scripts or binaries in locations such as %AppData%, %LocalAppData%, %ProgramData%, %Temp%, and Downloads. These locations also contain legitimate software, so judge entries by path, publisher, creation time, command line, and relationship to the alert—not unfamiliarity alone.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Correlate the command’s time with Task Scheduler history, Windows Event Logs, PowerShell operational logs, Defender Protection History, and process-creation events if auditing or Sysmon was already enabled. Preserve the relevant task, registry value, script, and log details before disabling or deleting them. Removing only the visible PowerShell command or its Defender exclusion can leave the persistence mechanism in place to recreate it.

Best Value
Sale
15.6 Inch Win 11 Laptop Computer, N4020, 4GB DDR4 RAM, 128GB Storage
  • WINDOWS 11 | STABLE PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 system, this laptop delivers stable performance for everyday computing tasks. It supports web browsing, online learning, document editing, email communication, and basic office work with optimized power efficiency, providing a practical and reliable experience for essential daily use for daily use.
  • 15.6” FHD IPS DISPLAY: Features a 15.6-inch Full HD IPS display with narrow bezels, offering wider viewing angles and clearer image details compared to standard panels. The improved screen-to-body ratio enhances visual experience for study, reading, document work, and video playback, making it suitable for both productivity and entertainment use.
  • 4GB DDR4 + 128GB eMMC STORAGE: Equipped with 4GB DDR4 memory and 128GB eMMC storage for everyday basics such as browsing, documents, email, and online learning platforms. The built-in TF card slot supports storage expansion up to 1TB, giving you more flexibility for files, photos, videos, and daily documents. TF card not included.
  • CONNECTIVITY & PORTS: Includes 1× TF card slot, 2× USB 3.2 Gen1 ports, and 2× full-featured Type-C ports (USB 3.2 Gen1). The Type-C ports support data transfer, charging, and video output, enabling flexible connection with external devices such as monitors, storage, and peripherals for daily work and study use.
  • LIGHTWEIGHT DESIGN | ONLINE COMMUNICATION: Designed with a slim, portable profile, this laptop is easy to carry for school, commuting, and travel. A built-in 1MP front camera supports online classes, video meetings, remote communication, and everyday conferencing. The 3300mAh battery works with the low-power system design to support practical daily use, while thermal optimization helps maintain quieter operation during extended tasks.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Scan, clean up, and verify

  1. After preserving evidence, run a Microsoft Defender Offline scan from Windows Security’s scan options. An offline scan can help when malware interferes with normal Windows operation.
  2. Once Windows is running again, review Defender Protection History and run a full scan. If your organization has a response process, follow it instead of adding multiple third-party cleaners.
  3. Remove a task, startup item, service, script, or other persistence only when you have established it is unauthorized—or get qualified help interpreting it. Do not use another person’s FRST fixlist or delete every unfamiliar entry.
  4. Recheck Defender exclusions and scan again. Confirm that the exclusions remain as intended and that no encoded PowerShell command or suspicious startup launcher returns after restart and sign-in.
  5. Observe Explorer and other processes after restart. If CPU usage spikes again, record the process tree and timing; a clean scan alone does not prove persistence is gone.

The report that high CPU activity stopped when Task Manager opened is an observation, not a diagnosis. A malicious process might react to analysis tools, but scheduling changes, a short-lived child process, Explorer workload changes, or monitoring artifacts can produce similar timing. Do not treat opening Task Manager as a fix or infer anti-analysis behavior without corroborating process or event evidence.

Consider the incident unresolved if detections recur, exclusions return, the launcher cannot be identified, security tools are disabled, or suspicious activity persists. A professional responder is appropriate for business devices, sensitive data, signs of remote access or ransomware, or possible credential theft.

When a Windows reset or clean reinstall is safer

Manual cleanup can preserve applications and help identify the source, but it is easy to miss persistence or remove a legitimate component. A reset or clean reinstall is often the safer route if malware repeatedly returns, an attacker had administrator access, Defender or system security services were tampered with, system files are damaged, remote-access or credential-stealing malware is suspected, or you cannot confidently distinguish malicious persistence from legitimate software. The higher the sensitivity of the computer’s data, the lower the threshold for professional incident response.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Back up only personal files you need, not unknown scripts, installers, or programs that could restore the problem; scan backups before restoring them. A reinstall does not undo account compromise. From a trusted device, change exposed passwords, revoke sessions and tokens where possible, enable multifactor authentication, and review email and cloud-account activity.

What the original case establishes—and what it does not

The case began in April 2022 and was later marked clean and closed by the forum helper. That outcome shows that one incident with these symptoms was resolved; it does not prove that a particular file deletion or tool sequence works for every computer. In particular, the symptoms do not establish that the genuine Explorer executable caused the CPU spike, and the command line alone does not reveal the entire infection chain. The useful lesson is to decode safely, trace the launcher, preserve evidence, and verify that both the unauthorized exclusion and its persistence source are gone.

Quick Recap

Bestseller No. 1
HP 14' HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
HP 14" HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
$249.99
Bestseller No. 2
Dell Latitude 3190 11.6' HD 2-in-1 Touchscreen Laptop Intel N5030 1.1Ghz 4GB Ram 128GB SSD Windows 11 Professional (Renewed)
Dell Latitude 3190 11.6" HD 2-in-1 Touchscreen Laptop Intel N5030 1.1Ghz 4GB Ram 128GB SSD Windows 11 Professional (Renewed)
1.1 GHz (boost up to 2.4GHz) Intel Celeron N5030 Quad-Core; 4GB DDR4 System Memory; 128GB Solid State Drive
$169.99
Bestseller No. 3
Dell Latitude 5420 14' FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
256 GB SSD of storage.; Multitasking is easy with 16GB of RAM; Equipped with a blazing fast Core i5 2.00 GHz processor.
$309.00

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.