My computer was infected after I downloaded files from a website that had apparently been compromised. I performed a factory reset, but afterward several accounts were accessed or targeted, including my gaming, shopping, social media, and Nintendo accounts. I'm concerned that a keylogger or other malware may still be running. I've been changing passwords and removing logged-in devices from my phone, and I've enabled two-factor authentication on important accounts. What should I do to properly secure my accounts and safely restore the computer? Do I really need to wipe the BIOS, or is there a less extreme way to make sure the infection is gone?
4 Answers
Treat the computer as compromised and don’t use it to change passwords or access important accounts. From your phone or another trusted device, secure your primary email first, then change passwords for other accounts, sign out all sessions, revoke unknown app sessions and recovery methods, and enable app-based or hardware-key two-factor authentication where possible. Check your email for forwarding rules and account-recovery changes too.
A BIOS-level infection is possible but very uncommon. Start with a properly created clean installation and update the motherboard firmware only through the manufacturer’s official instructions if there is a legitimate update. Don’t attempt a BIOS wipe casually, since interrupting firmware updates can make the computer unbootable.
Once Windows is reinstalled, fully update Windows, drivers, browsers, and applications, enable the built-in security protections, and use a reputable password manager. Review every account’s login history and connected devices over the next few weeks. If unauthorized access continues after a clean installation and password changes from a trusted device, contact the affected services and consider having a professional inspect the machine.
A factory reset may not be the same as completely erasing the system drive. Create official Windows installation media using a different, trusted computer, boot from it, delete the existing partitions during setup, and perform a clean installation. Don’t restore programs or unknown executables from the old installation; scan any personal files before copying them back.
Back up only documents, photos, and other necessary personal files. Avoid copying old installers, scripts, cracked software, or anything you downloaded shortly before the infection.

The email account is especially important because anyone who controls it can reset passwords for many of your other accounts. Also avoid reusing any password that was stored or typed on the infected computer.