Powershell Windows Toolbox helps to install Google Play on Windows 11 is malicious code
A third-party tool used to install the Google Play Store on Windows 11, among other functions, has been found to be malicious. Quite a few people have become victims when using this tool to install the Play Store.
This tool called "Powershell Windows Toolbox" has been posted to GitHub and LinuxUserGD users have noticed that the hidden lines of code are very confusing and contain malicious bits. Then other users continued to report problems related to this tool. Powershell Windows Toolbox has now been removed from GitHub.
Here's what the tool claims it can do:
First, the tool uses Cloudflare workers to load a script. In the How to user section of the tool, the developer instructs the user to run the following command in the CLI:
While the script is being loaded, code scrambling is also performed. After overturning the obfuscation, experts discovered that these are lines of code used to download malicious scripts from Cloudflare workers and files from user alexrybak0444's GitHub repo. This repo has also been reported and removed.
The scripts then create an extension for Chromium-based browsers. This is believed to be the main malicious component of this malware distribution campaign. It appears to be that certain links or URLs are used to generate revenue through afiliates and referrals by promoting certain software or scams through Facebook and WhatsApp messages.
If you happen to install Powershell Windows Toolbox you need to remove the following components from your computer. Here's what the malware adds during the infection:
- MicrosoftWindowsAppIDVerifiedCert
- MicrosoftWindowsApplication ExperienceMaintenance
- MicrosoftWindowsServicesCertPathCheck
- MicrosoftWindowsServicesCertPathw
- MicrosoftWindowsServicingComponentCleanup
- MicrosoftWindowsServicingServiceCleanup
- MicrosoftWindowsShellObjectTask
- MicrosoftWindowsClipServiceCleanup
At the same time, you also need to delete the hidden folder "C:systemfile" created by the malicious code during the intrusion. In case you do a system restore make sure you use a recovery file that is not created by the Powershell Windows Toolbox as it will not remove the malware.
However, before installing the Google Play Store, TipsMake.com notes you: according to Microsoft, to run Android apps on Windows 11 you need a computer with relatively high configuration.
You've just finished reading the article "Powershell Windows Toolbox helps to install Google Play on Windows 11 is malicious code" edited by the TipsMake team. You can save powershell-windows-toolbox-helps-to-install-google-play-on-windows-11-is-malicious-code.pdf to your computer here to read later or print it out. We hope this article has provided you with many useful tech tips and tricks. You can search for similar articles on tips and guides. Thank you for reading and for following us regularly.
- How to Install or Update PowerShell on Windows 11
- Android apps contain malicious code that uses motion sensors to avoid detection
- 238 applications found on Play Store contain malicious code that paralyzes smartphones
- Instructions on how to use PowerShell in Windows Server 2012
- 10 million Android devices are preinstalled with malicious code from the factory
- Microsoft Windows PowerShell and SQL Server 2005 SMO - Part 3
- Google 'purged' 24 applications downloaded nearly 500,000 times containing malicious malware
- More than 200 apps containing malicious code were discovered and downloaded millions of times on the Google Play Store.
- 9 malicious applications on Google Play, if installed, should be removed immediately
- App Installer on Windows 10 was used to install BazarLoarder malware
- Warning: The new Facebook virus, a malicious code that is spreading rapidly through Messenger
- Detecting SharkBot malware hiding in anti-virus applications on Google Play
- A series of malicious applications that collect user data, delete immediately if you are installing
- Decode all errors that appear on Google Play and how to fix them (Part 1)