I installed a game from an untrusted website, and a new drive appeared in File Explorer during or after the installation. I removed it, but later received notifications that passwords had been changed on several accounts, including Steam, Epic Games, Discord, Battle.net, and Microsoft. I disconnected the computer from the internet and recovered most of the accounts, but my Battle.net account was fully unlinked. I also tried enabling Windows Memory Integrity, but Windows would not allow it. What should I do now to make sure the malware is gone and my accounts and PC are safe?
3 Answers
Treat the computer as compromised. Memory Integrity is not a substitute for removing malware, and it may be blocked because of an incompatible driver. Back up only personal documents you know are safe, then perform a clean Windows installation from official installation media and delete the existing system partitions during setup. Do not restore unknown programs or pirated installers afterward. From a different, trusted device, change your email password first, then the passwords for your other accounts, enable two-factor authentication, revoke active sessions, and remove unfamiliar recovery methods or authenticator devices. Contact Battle.net support through its official account-recovery process and provide proof of ownership.
Disconnecting the PC was a good immediate step, but running scans on the existing installation may not be enough after multiple account takeovers. Use a separate clean device to secure your email and accounts, because passwords entered on the infected computer may have been captured. Check your email rules and forwarding settings too—attackers sometimes add rules that hide security alerts. After reinstalling Windows, install updates and drivers only from official sources, then scan any files before copying them back.
The new drive may have been a mounted disk image or part of the installer, but the account changes strongly suggest an infostealer or another malicious component. Save screenshots and recovery information for the affected accounts, and report the incident to each provider. If you reuse passwords anywhere, assume those accounts are exposed as well and replace them with unique passwords from a password manager.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures