I used a PowerShell command from an unfamiliar website to activate Microsoft Office because I couldn't afford a license. The command appeared to work, but I'm now worried that it may have downloaded and executed malware. How serious is this, and what steps should I take to protect my computer, accounts, and files?
3 Answers
Yes, you should treat the system as compromised. Reports indicate the script disables security protections, downloads additional components, establishes persistence, and may fetch more code later. Disconnect the computer from the network, back up only personal documents you can verify, then wipe the drive and perform a clean operating-system installation. Don’t rely on simply uninstalling the activation tool.
A command that downloads and executes code from an unknown site is dangerous even if it successfully activates Office. The fact that the software appears to work does not make the script safe. For future use, stick to official licenses or free alternatives such as LibreOffice, and avoid running commands you haven’t inspected and understood.
Reset every password that was used or saved on that computer, but do it from a different, trusted device. Prioritize email, banking, work accounts, password managers, and accounts with payment information. Enable multifactor authentication where possible, and contact your IT department immediately if the computer was connected to a business network.

I’m already starting a clean installation. I wish I had checked what the command did first.