I tried to download GTA IV for free from a website I had used before, but I later noticed the address had a slightly different punctuation mark. I opened the downloaded file, then deleted it when I realized something was wrong. A few hours later, the email address and password on my EA account had been changed, although I recovered it. I also changed my Gmail password, signed out other devices, and made sure my Apple email—with two-factor authentication enabled—is the only backup method I recognize. The next morning, someone accessed my Instagram, posted spam, and sent cryptocurrency promotions to everyone I follow. I changed that password and the activity stopped. I have limited technical knowledge, so what should I do to make sure the malware is gone and secure all my accounts?
4 Answers
The file may have stolen saved browser passwords or session cookies, so changing passwords alone may not be enough until the machine is clean. Use a trusted device for the changes, contact support for any account you cannot recover, and monitor email and financial accounts for unusual activity. In the future, avoid unofficial game installers—even a familiar-looking website can be an imitation.
Check every important account, not just the ones that showed obvious activity. Review login history, forwarding rules and filters in your email, newly added devices, backup methods, connected applications, and security notifications. Also check your Microsoft account and other social media accounts, since stolen credentials are commonly tried across multiple services.
Change every password from a different, trusted device, and never reuse any of the old passwords. Start with your primary email, Apple or Microsoft account, password manager, banking, and recovery accounts, then work through gaming and social accounts. Sign out all sessions, remove unfamiliar recovery emails and phone numbers, revoke unknown connected apps, and enable two-factor authentication wherever possible. Attackers often test the stolen password on many other services.
Treat the computer as compromised. Disconnect it from the internet, back up only personal documents and photos, then perform a clean Windows reinstall rather than relying on deleting the suspicious file. Malware can install additional components or create scheduled tasks that survive a simple deletion. After reinstalling, run all system updates and install software only from official sources.

I’ve started changing everything and found that the attacker had access to several of my passwords. I’ll make sure the old ones are not used anywhere else.