For the past few weeks, unfamiliar Chinese searches have been showing up in my YouTube history. Random children's, Spider-Man, and brightly colored videos are also being added to my liked videos, although they usually do not appear in my watch history. Changing my Google password did not stop it. I have also found outgoing SMS messages to several unknown numbers containing "YESPRODUPI" followed by random characters. They show as not sent, and I did not write them. This began after I installed a cracked or suspicious game on my Windows laptop. Later, my Instagram account sent scam links, and then I noticed unusual activity on my Google and YouTube accounts. Malware scanners and some command-line cleanup steps have been used, but the behavior continues. What should I check first, and how can I make sure both my computer and phone are safe?
3 Answers
Because this started after installing a cracked game and affected multiple accounts, I would not rely on a few scans or commands. Back up only personal documents and photos, then perform a clean Windows reinstall using official installation media, deleting the existing system partitions. Update the firmware and operating system afterward, reinstall software only from trusted sources, and change passwords after the reinstall. If the phone has an unfamiliar app with accessibility or administrator access, remove that access first and consider a factory reset if the behavior continues.
Treat this as a possible account compromise and potentially a compromised device. From Google’s security page, sign out every unfamiliar session, remove unknown third-party access, review recent security events, enable two-factor authentication, and change the password from a known-clean device. Check browser extensions and remove anything you do not recognize. On the phone, review installed apps, device-administrator permissions, accessibility access, notification access, VPNs, and apps with SMS permissions. Unknown apps or apps with blank or foreign names deserve special attention. The SMS could be a failed verification or activation attempt from an app, but do not assume it is harmless—check your carrier account and payment or wallet apps as well.
The claim that the malware is definitely “kernel-level but dead” is not something a command-line tool or chatbot can reliably prove. Assume the laptop is untrusted until it has been cleanly reinstalled. Also contact your mobile carrier about the outgoing messages and ask whether premium SMS, SIM changes, call forwarding, or account recovery changes occurred. Save screenshots and timestamps, and check Google, Instagram, email, banking, and payment-app activity for unauthorized changes.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures