I use a Windows desktop PC and recently downloaded a program from a suspicious site that displayed a fake download screen. Soon afterward, malware began sending cryptocurrency scam messages through my Discord account, and my Steam account was accessed and used to send gifts charged to my payment card. I replaced the card, requested refunds, changed my Discord and Steam passwords, and ran Malwarebytes, which found more than 20 Trojans and other threats.
I have continued scanning the computer and have not found anything else, but I am now seeing attempted logins on my two main email accounts, followed by attempts involving old Chess.com and Roblox accounts. I am worried that an information-stealing malware program captured passwords or browser data before it was removed. What should I do next, and how can I be sure my accounts and computer are safe?
3 Answers
With a large number of information-stealing Trojans involved, the safest option is a clean Windows reinstall from official installation media created on a separate clean computer. A malware scanner can remove many threats, but it cannot guarantee that a sophisticated infostealer or persistence mechanism is gone. Back up only personal documents, not programs or unknown executables, and fully wipe the system drive during installation.
Treat every password that was stored or entered on that computer as compromised. Change them from a different, known-clean device, use unique passwords, and review active sessions, connected apps, recovery email addresses, phone numbers, and forwarding rules. Two-factor authentication helps, but it does not undo stolen session cookies or recovery settings, so sign out all other sessions and revoke unfamiliar devices and app access.
The login attempts are consistent with stolen credentials being tested against other services, possibly from an old data leak or from the infected PC. Secure your primary email accounts first because they can reset everything else, then handle financial, gaming, and other accounts. Contact your bank, monitor transactions, remove saved payment methods where appropriate, and preserve security alerts and login history in case an account needs further recovery.

I changed my email, banking, Steam, Discord, Ubisoft, and Epic passwords and enabled two-factor authentication. I’ll also check recovery settings, active sessions, and linked accounts rather than relying on 2FA alone.