My PC was infected after I downloaded files from a previously trusted website. I performed a factory reset, but shortly afterward my Riot account was compromised, and someone attempted to access a newly created eBay account. They also got into Facebook and a Nintendo account I had not used recently, so I'm concerned that malware or a keylogger may still be active. I've been changing passwords and removing logged-in devices from my phone and have enabled two-factor authentication on important accounts. What is the safest way to clean the computer, and do I really need to wipe or reflash the BIOS?
4 Answers
The Nintendo compromise does not necessarily prove the malware was still recording keystrokes. Attackers may have obtained an older password, reused credentials from another breach, or accessed a saved session. Check breach notifications, replace reused passwords everywhere, review account login history, and contact each service’s official support if recovery details or purchases were changed.
A factory reset may not be the same as completely wiping the system drive. The safest approach is to use a separate, trusted computer to create official Windows installation media on a USB drive. Boot the affected PC from that USB, delete the existing Windows partitions during setup, and perform a clean installation. Back up only personal documents you’re confident are safe; do not restore programs or suspicious files.
A BIOS or UEFI infection is possible in theory but is much less common than an incomplete reinstall, stolen credentials, reused passwords, or an already logged-in session. I would not start by reflashing the BIOS unless there is specific evidence of firmware tampering. After reinstalling Windows, fully update it, install drivers and applications only from official sources, and scan any backup files before copying them back.
Treat the computer as untrusted until the clean installation is finished. From your phone or another known-clean device, change the password for your primary email first, then change other important passwords using unique passwords. Sign out all sessions, remove unknown recovery methods, review email forwarding rules, and enable app-based or hardware-based two-factor authentication where possible. Your email account is especially important because it can be used to reset other accounts.

I’m not sure whether the drive was actually wiped during the reset, so I’ll make sure to use installation media and remove the old partitions.