I noticed my browser had been closed even though I normally leave it open with several tabs. When I checked the history, it showed attempts to visit an orphanage donation page, access my bank account, and search Google for "card." Malwarebytes detected Trojans and spyware, which I removed, but the browser was closed again later and there was more suspicious activity. I have disconnected the computer from the internet and am changing my passwords. Could someone remotely control the computer even while the desktop is locked, and should I completely erase the drive and reinstall Windows? What else should I do to protect my accounts and files?
4 Answers
Keep the computer disconnected for now and secure your accounts from a different, known-clean computer or phone. Contact your bank immediately, explain that the device may have been compromised, and ask about replacing cards and reviewing recent transactions. Change important passwords, starting with email and financial accounts, and enable two-factor authentication where possible.
A malware scan finding Trojans or spyware doesn’t guarantee the system is clean. Remote-access malware and information stealers can sometimes evade detection and may continue operating while Windows is running, even if the desktop is locked. The safest approach is to back up only essential personal documents, carefully avoiding unknown programs or scripts, securely wipe the system drive, and perform a fresh Windows installation using official installation media.
Treat recently downloaded files and installers as potentially unsafe. Don’t copy over cracked software, browser extensions, executables, or anything you downloaded around the time the problem started. Re-download applications from their official sources after reinstalling, fully update Windows, and enable built-in security protections before restoring your files.
Assume that passwords and browser-stored payment information used on that computer may have been exposed. Sign out of active sessions, revoke unfamiliar account devices or app access, remove saved cards from browsers and websites, and monitor bank and email accounts for changes. If you need evidence of what happened, take photos or save notes before wiping the machine, but don’t reconnect it just to investigate.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures