Powershell Process at Startup


mccnavy

Member
Local time
9:00 AM
Posts
88
OS
Windows 11
I have a desktop and laptop both running Windows 11. I've noticed that the laptop always has two Windows Powershell processes running at startup while the desktop does not. Is this normal? What would require the Powershell processes to run? I've run Microsoft Defender, including an offline scan, with no findings.
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom
    CPU
    Intel i7-7700K
    Motherboard
    Asus Prime Z-270A
    Memory
    32GB 2666Mhz (Kingston Hyper X Fury)
    Graphics Card(s)
    Asus Nvidia 1050Ti
    Sound Card
    N/A
    Monitor(s) Displays
    Samsung C27F390
    Screen Resolution
    1920 x 1080
    Hard Drives
    Samsung 850 Evo 512GB

Bastet

Well-known member
Member
VIP
Local time
3:00 PM
Posts
223
Location
Manchester. UK.
OS
Windows 11 Pro 64bit
It wouldn’t be normal imo. I would run a scan with Malwarebytes free & also AdwCleaner.
I would check task manager>startup to see if there’s any disc cleaning software or even something unknown running at that time.
 

My Computer

System One

  • OS
    Windows 11 Pro 64bit
    Computer type
    Laptop
    Manufacturer/Model
    PC Specialist Optimus VII V17-960 Gaming Laptop.
    CPU
    6th Gen Intel Core i7-6700HQ Quad Core processor.
    Memory
    16GB HyperX IMPACT 1600MHz SODIMM DDR3 (2 x 8GB)
    Graphics Card(s)
    NVIDIA® GeForce® GTX 960M - 2.0GB DDR5 Video RAM - DirectX® 12
    Sound Card
    Intel 2 Channel High Def. Audio + SoundBlaster™ Cinema 2 & Realtek
    Monitor(s) Displays
    Optimus Series: 17.3" Matte Full HD IPS LED Widescreen (1920x1080)
    Screen Resolution
    Full HD IPS display (1920 x 1080).
    Hard Drives
    2TB SSD (internal).
    1x 1TB & 1x 5TB external HDDs.
    Cooling
    STANDARD THERMAL PASTE FOR SUFFICIENT COOLING
    Keyboard
    Logitech K800 wireless keyboard
    Mouse
    Logitech M705 wireless mouse
    Internet Speed
    Upto 100Mbps
    Browser
    Edge.
    Antivirus
    Windows Defender & MalwareBytes pro.

johnlgalt

Antidisestablishmentarianistentarianist
Power User
VIP
Local time
10:00 AM
Posts
2,423
Location
3rd Rock
OS
Windows 11 21H2
I have a desktop and laptop both running Windows 11. I've noticed that the laptop always has two Windows Powershell processes running at startup while the desktop does not. Is this normal? What would require the Powershell processes to run? I've run Microsoft Defender, including an offline scan, with no findings.
Also check to see if your laptop manufacturer might have included proprietary apps that run at startup, such as MSI Center (for MSI laptops, not all laptops). One or more of those OEM apps may be doing some sort of checking for updates for the software installed on the system.
 

My Computers

System One System Two

  • OS
    Windows 11 21H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    HomeBrew
    CPU
    AMD Ryzen 9 3950X
    Motherboard
    MSI MEG X570 GODLIKE
    Memory
    4 * Corsair Vengeance 32 GB 3600 MHz
    Graphics Card(s)
    EVGA GeForce RTX 3080 Ti XC3 ULTRA GAMING (12G-P5-3955-KR)
    Sound Card
    Realtek® ALC1220 Codec
    Monitor(s) Displays
    Eve Spectrum ES07D02 280 Hz QHD | Eve Spectrum ES07D03 4K Gaming Monitor
    Screen Resolution
    1440p | 4k
    Hard Drives
    3x Samsung 980 Pro NVMe PCIe 4 M.2 2 TB SSD (MZ-V8P2T0B/AM)
    PSU
    PC Power & Cooling’s Silencer Series 1050 Watt, 80 Plus Platinum
    Case
    Fractal Design Define 7 XL Dark ATX Full Tower Case
    Cooling
    ZXT KRAKEN Z73 73.11 CFM Liquid CPU Cooler (3x 120 mm push top) + Air 3x 140mm case fans (pull front) + 1x 120 mm (push back) and 1 x 120 mm (pull bottom)
    Keyboard
    SteelSeries Apex Pro Wired Gaming Keyboard
    Mouse
    Logitech MX Master 3 for Business
    Internet Speed
    Logitech MX Master 3 for Business
    Browser
    Nightly (default) + Firefox (stable),Chrome, Edge/ß/Dev/Canary
    Antivirus
    Defender
  • Operating System
    Windows 10 x64 Pro build 21H1
    Computer type
    Laptop
    Manufacturer/Model
    Dell Latitude E5470
    CPU
    Intel(R) Core(TM) i5-6300U CPU @ 2.40GHz, 2501 Mhz, 2 Core(s), 4 Logical Processor(s)
    Motherboard
    Dell
    Memory
    16 GB
    Graphics card(s)
    Intel(R) HD Graphics 520
    Sound Card
    Intel(R) HD Graphics 520 + RealTek Audio
    Monitor(s) Displays
    Dell laptop display 15"
    Screen Resolution
    1920 * 1080
    Hard Drives
    Toshiba 128GB M.2 22300 drive
    INTEL Cherryvill 520 Series SSDSC2CW180A 180 GB SATA III SSD
    PSU
    Dell
    Case
    Dell
    Cooling
    Dell
    Mouse
    Logitech MX Master (shared) | Dell TouchPad
    Keyboard
    Dell
    Internet Speed
    AT&T LightSpeed Gigabit Duplex
    Browser
    Edge Chromium | Chrome | Firefox Nightly | Brave
    Antivirus
    Defender + MB4

The-Hive

Well-known member
VIP
Guru
Local time
3:00 PM
Posts
6,702
Location
Wiltshire UK
OS
Windows 11 Pro
A couple of mins after startup are they still running? if not imo I guess it is part of the startup process and all is fine
 

My Computers

System One System Two

  • OS
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    Alienware Area 51m R2
    CPU
    10th Gen Core i9 10900K
    Memory
    32GB
    Graphics Card(s)
    Geforce RTX 2080 Super
    Sound Card
    Nvidia HD
    Screen Resolution
    1920x1080
    Hard Drives
    C: Samsung 2TB P981A
    D: Samsung 2TB 970 Evo
    Case
    Dark side of the moon
    Mouse
    Alienware AW610M
    Browser
    Chrome and Firefox
    Antivirus
    Norton
    Other Info
    Killer E3000 Ethernet Controller
    Killer AX1650i Wi-Fi Network Adaptor
    Alienware Z01G Graphic Amplifier
    Tobii Eye Tracker
  • Operating System
    Dual Boot Windows 11 Pro / Windows 11 Pro Dev build
    Computer type
    Laptop
    Manufacturer/Model
    Dell Inspiron 3501
    CPU
    11th Gen i-7 2.80 gb
    Memory
    16Gb
    Screen Resolution
    1920 x 1080
    Hard Drives
    512Gb SSD
    WD 2GB EXT
    Browser
    Chrome
    Antivirus
    Norton

mccnavy

Member
Thread Starter
Local time
9:00 AM
Posts
88
OS
Windows 11
Interesting...I will monitor but it looks like I did get infected. I recall reading something in the news about a Bitcoin scam that uses Windows Event Viewer and uses a log file. Malwarebytes found it and I quarantined (then deleted) it. As of last two Powershell isn't there...which is good. I also ran Adwcleaner and Defender, Malwarebytes, and Adwcleaner show nothing abnormal at this time.
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom
    CPU
    Intel i7-7700K
    Motherboard
    Asus Prime Z-270A
    Memory
    32GB 2666Mhz (Kingston Hyper X Fury)
    Graphics Card(s)
    Asus Nvidia 1050Ti
    Sound Card
    N/A
    Monitor(s) Displays
    Samsung C27F390
    Screen Resolution
    1920 x 1080
    Hard Drives
    Samsung 850 Evo 512GB
Top Bottom