I'm using Windows 11 and recently detected one or more trojans on my laptop. Windows Security quarantined them, and I've restarted and run several scans. Afterward, Windows prompted me to sign in to OneDrive, but the email address shown for verification didn't belong to me and I don't recognize the name connected to it. When I tried creating a Microsoft account with my own email address, I received a message saying the attempt was blocked because of suspicious activity. Could this be leftover malware, or might someone have accessed my Microsoft account? I'm worried about losing my files and don't want to reinstall Windows unless it's absolutely necessary.
3 Answers
The unfamiliar OneDrive address doesn’t automatically prove that the virus created it. It could be an old Windows profile, a previously linked account, or a sign-in prompt for a different Microsoft account. Check Settings > Accounts and OneDrive directly rather than following the popup. The suspicious-activity message can also be triggered by too many attempts, a VPN, or an unusual sign-in location, but you should still secure the account from another device first.
Treat the laptop as potentially compromised until you can verify it’s clean. From a different, trusted device, change your Microsoft password and any other important passwords that were used on the laptop. Turn on two-factor authentication, review recent Microsoft account activity, and remove unfamiliar devices or sign-in methods. Don’t enter credentials into a prompt unless you opened the official Microsoft settings page yourself. Back up only personal files you’re confident are safe, then run an offline scan. If detections return or account activity looks unfamiliar, a clean Windows reinstall is the safest option.
Quarantine is a good start, but it doesn’t guarantee that every change made by malware was removed. Disconnect the laptop from the internet while checking it, save essential documents to a separate backup, and avoid backing up unknown programs or executables. If you can’t confidently confirm that the trojan and its persistence mechanisms are gone, preserving the important files and reinstalling Windows is safer than continuing to use a possibly compromised system.

I really don’t want to reinstall because the laptop has a huge amount of data on it. I’ll check the account activity and linked devices from another device before trying anything else.