Share via

Hacked

Anonymous
2024-09-26T09:38:14+00:00

A nice person have checked my computer for malware on this website and said that there was no malware on my laptop . but today i found out a hacker have logged in into my account and changed a password using my google account and deleted the password change e-mail right away . This was the details on the device that was used "Web, Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36".

I really need help can someone here help me. I have searched my local and there seems to be no computer expert here

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

7 answers

Sort by: Most helpful
  1. _AW_ 67,926 Reputation points Volunteer Moderator
    2024-09-29T00:22:49+00:00

    The command powershell.exe -W Hidden is just a shortened way of writing powershell.exe -WindowStyle Hidden.

    It just means you'll see a brief flash of the Powershell window and then the window will be hidden while it's still executing in the background.

    If the command didn't have the -WindowStyle argument, you would have seen what was happening and been able to close it.

    It has no bearing as far as detection goes, or any ability to really hide itself.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. _AW_ 67,926 Reputation points Volunteer Moderator
    2024-09-27T23:20:26+00:00

    They're all common log files from Microsoft Office, One Drive, Malwarebytes and Windows Defender signature update.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. _AW_ 67,926 Reputation points Volunteer Moderator
    2024-09-27T00:55:43+00:00

    If the computer is not infected, then there's no way the hacker could get a new password.

    Assuming that the command you previously pasted into the run box was successful, it appears from my research of similar URLs used, that the particular stealer used has no persistence; it runs from the user temp folder and just does its thing then terminates.

    If you've changed your passwords since then, you should be OK.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. _AW_ 67,926 Reputation points Volunteer Moderator
    2024-09-26T09:56:29+00:00

    Run a scan with Malwarebytes to ensure nothing has infected the computer since your last question.

    https://www.malwarebytes.com/mwb-download 

    Even though no malware was present when I checked your computer, considering what has happened, it's fair to assume that at some point your computer has been compromised by a password/info stealer. If Malwarebytes shows nothing, you should change your password for every important account and set up MFA where possible.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  5. Anonymous
    2024-09-26T18:43:49+00:00

    are there any way the hacker can get info of my new password when there are no malware detected by defender and malwarebytes? should i be worried?

    Was this answer helpful?

    0 comments No comments