It's a virus.
As long as you are absolutely sure you he only gave out your password, but didn't run any file, you should be fine just changing your password and secret question should be enough.
You can change this on
https://account.live.com/.
Run a good virusscanner to be sure, and don't give out your password to your brother again
.