Powershell Windows Toolbox helps to install Google Play on Windows 11 is malicious code
This tool called "Powershell Windows Toolbox" has been posted to GitHub and LinuxUserGD users have noticed that the hidden lines of code are very confusing and contain malicious bits. Then other users continued to report problems related to this tool. Powershell Windows Toolbox has now been removed from GitHub.
Here's what the tool claims it can do:
First, the tool uses Cloudflare workers to load a script. In the How to user section of the tool, the developer instructs the user to run the following command in the CLI:
While the script is being loaded, code scrambling is also performed. After overturning the obfuscation, experts discovered that these are lines of code used to download malicious scripts from Cloudflare workers and files from user alexrybak0444's GitHub repo. This repo has also been reported and removed.
The scripts then create an extension for Chromium-based browsers. This is believed to be the main malicious component of this malware distribution campaign. It appears to be that certain links or URLs are used to generate revenue through afiliates and referrals by promoting certain software or scams through Facebook and WhatsApp messages.
If you happen to install Powershell Windows Toolbox you need to remove the following components from your computer. Here's what the malware adds during the infection:
- MicrosoftWindowsAppIDVerifiedCert
- MicrosoftWindowsApplication ExperienceMaintenance
- MicrosoftWindowsServicesCertPathCheck
- MicrosoftWindowsServicesCertPathw
- MicrosoftWindowsServicingComponentCleanup
- MicrosoftWindowsServicingServiceCleanup
- MicrosoftWindowsShellObjectTask
- MicrosoftWindowsClipServiceCleanup
At the same time, you also need to delete the hidden folder "C:systemfile" created by the malicious code during the intrusion. In case you do a system restore make sure you use a recovery file that is not created by the Powershell Windows Toolbox as it will not remove the malware.
However, before installing the Google Play Store, TipsMake.com notes you: according to Microsoft, to run Android apps on Windows 11 you need a computer with relatively high configuration.
You should read it
- How to install PowerShell 7.0 in Windows 10/8/7
- About PowerShell
- Instructions on how to use PowerShell in Windows Server 2012
- What to do when Windows can't find PowerShell?
- Use PowerShell to download any file on Windows 10
- PowerShell command in Windows
- How to Install or Update PowerShell on Windows 11
- How to check PowerShell version in Windows 10
- How to join videos using the Video Toolbox online
- Next time, Microsoft will release PowerShell updates via Windows Update Windows
- How are Command Prompt (cmd) and PowerShell different?
- How to use PowerShell's default parameter to change the command behavior