I downloaded a cracked game on September 2 and apparently picked up an information-stealing malware infection. That same day, my Discord account began sending contacts a scam message, so I disconnected the computer from Wi-Fi and performed a Windows reset/reinstallation. I then changed the passwords for all of my accounts and email addresses using new passwords that had never been used on that computer, signed out unknown devices, enabled two-factor authentication, and froze online and international payments while I arrange to speak with my bank. I have also run deep scans with Malwarebytes and another security tool.
On September 15, my Steam profile was changed to an unfamiliar name and image containing a QR code. I changed the password again, disabled and re-enabled Steam Guard, signed out all devices, and ran additional malware scans. Since then, Steam has stopped showing unfamiliar login locations, and fortunately nothing was purchased or removed from the account.
Is there anything else I should do to make sure the infection is gone and my accounts are secure? The whole experience has made me anxious about using the computer again.
3 Answers
The Steam activity stopping is a good sign, but keep checking account history and security settings for a while. Make sure your recovery email and phone number are still yours, remove unfamiliar devices and authorized applications, use Steam Guard, and avoid cracked software in the future since it is a common way for credential stealers to spread.
Since an information stealer may have captured passwords, session tokens, browser data, or payment information, changing passwords from a potentially compromised system is not enough by itself. Use a different, trusted device to change them, make every password unique, revoke active sessions and connected apps, and keep two-factor authentication enabled. Contact your bank and monitor your accounts and credit closely as well.
A normal factory reset or Windows reset is helpful, but for high confidence you should completely erase the system drive and perform a clean Windows installation from official installation media. Back up only personal files you know are safe, avoid restoring browser profiles or executables, install all updates, and change important passwords again after the clean install.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures