I'm using Windows 11 and recently detected one or more trojans on my laptop. I quarantined them, restarted several times, and ran additional scans. After that, Windows prompted me to sign in to OneDrive, but the verification email appeared to be connected to an unfamiliar person's address. I don't recognize the name or email at all. When I tried creating a Microsoft account with my own email address, Microsoft reported suspicious activity and wouldn't let me continue. Could this be leftover malware, a compromised Microsoft account, or something else? I'm worried about losing my files and don't want to reinstall Windows unless absolutely necessary.
2 Answers
Treat the laptop and your online accounts as potentially compromised until you verify otherwise. Don’t enter passwords or approve sign-in prompts on that computer for now. From a different trusted device, change your Microsoft password and any other passwords used on the laptop, enable two-factor authentication, and review recent sign-ins and account recovery details. If the unfamiliar email is listed inside your Microsoft account, remove it only after securing the account. Save important documents, but scan the backup carefully and avoid copying programs or suspicious files. If the malware keeps returning or account settings have been changed, a clean Windows reinstall is the safest option, even though it’s inconvenient.
The unfamiliar OneDrive address doesn’t automatically prove that the virus created it. Windows may be showing an account that was previously connected to the device, or the laptop may have been purchased or configured with someone else’s Microsoft account. Check Settings > Accounts and the OneDrive account settings, but use a separate trusted device for password changes. Also run Microsoft Defender Offline and a reputable second-opinion scanner. A normal quarantine result is encouraging, but it doesn’t guarantee every change made by malware was undone.

Before considering a reset, disconnect the laptop from the internet, secure your accounts from another device, and make a careful backup of irreplaceable personal files. Don’t back up executable files or unknown archives. If scans, account activity, or repeated prompts still look suspicious afterward, preserving the files and performing a clean installation is safer than trusting an infected system.