A brief PowerShell window during installation or the first few sign-ins is not, by itself, evidence of malware. Windows performs an online configuration phase during the first boot, installing hardware support, drivers, applications, updates, and OOBE components. The fact that the windows stopped appearing after setup is reassuring. }
To verify the installation:
- Confirm the installation media came directly from Microsoft’s
- Install all Windows updates and run a Full scan from Windows Security. For additional assurance, run Microsoft Defender Offline.
- Check Event Viewer under Applications and Services Logs > Microsoft > Windows > PowerShell > Operational for entries matching those times. PowerShell activity is recorded there, although the amount of detail depends on which logging options were enabled.
If Defender finds nothing, the media was obtained directly from Microsoft, and PowerShell no longer opens, this was most likely temporary setup, driver, or application provisioning rather than an infection.