About a week ago, my Discord and Steam accounts were compromised and used to post a scam message. I changed my passwords, enabled two-factor authentication, and haven't noticed any more unauthorized logins. I also ran a malware scan, which came back clean. However, I'm concerned that the attacker may have stolen active session tokens or installed something that the scan missed. How can I determine whether my PC is safe, and should I reinstall Windows?
3 Answers
Changing passwords and enabling two-factor authentication is a strong improvement, especially if every account has a unique password stored in a password manager. However, 2FA may not stop an attacker who already stole a login session token. Sign out of all devices and revoke sessions after cleaning the computer, then change passwords again from a device you trust. Avoid running unknown downloads, including unofficial game installers, since they can be bundled with credential-stealing malware.
It’s impossible to say for sure without knowing how the accounts were compromised. A clean scan is reassuring, but it doesn’t prove that every possible threat is gone. Run thorough scans with Windows Security and a reputable second-opinion scanner, review your browser extensions and installed programs, and check your account security pages for unfamiliar sessions or devices. Sign out of all sessions and revoke active tokens where the services provide that option.
If you want the highest level of confidence, back up only personal documents and photos—not programs or suspicious files—and perform a clean Windows installation from official installation media. The reinstall itself can be fairly quick; preparing the backup and installation media usually takes longer. Afterward, fully update Windows, reinstall applications only from trusted sources, and change your account passwords again.

I’m using a password manager now, with different passwords and 2FA everywhere. If this was a session-token theft, does signing out of all devices normally invalidate the stolen sessions?