In August 2026, I downloaded a cracked game and later discovered that an unknown person had posted scam content on my Instagram story and sent it to people I know. There were also several attempted Uber transactions on my accounts. I suspect the download contained an information-stealing malware infection that exposed data saved in Chrome.
I ran one malware scanner that found 63 suspicious files, quarantined and deleted them, then used two other scanners that reported no remaining threats. I changed my passwords, but about a week later someone accessed Instagram again and repeated the same scam activity. I plan to sign out of every device and change all my passwords again, but I am unsure whether the computer is safe or whether I should reset it completely.
A full reset is difficult because I have important family photos on the computer and cannot currently afford a USB drive. Is deleting the detected files and getting clean scan results enough, or should I back up my personal files and reinstall the operating system?
4 Answers
The safest option is a clean operating-system reinstall, not simply deleting the files that a scanner found. Before doing that, secure your accounts from another device and invalidate all active sessions. Also remove saved passwords and payment information from the affected browser, check email forwarding rules, and review account login history. If you cannot reset immediately, disconnect the computer from the internet except when absolutely necessary and do not use it for banking or password changes.
You do not necessarily need to buy a USB stick right away. If Windows still works, you can use its built-in Reset this PC feature and choose the option that removes apps and personal files, preferably with cloud download if your connection allows it. Still make a careful backup first. Family photos can be copied to another trusted computer, an external drive, or a reputable cloud storage service, but do not copy executable files or the entire browser profile.
You should treat the computer as compromised until it has been reset or Windows has been freshly reinstalled. Information stealers can grab browser sessions and authentication cookies, so changing a password alone may not stop access if the attacker is still using a stolen session. From a different, trusted device, change your email password first, then your financial, social, gaming, and other important passwords. Enable two-factor authentication, sign out of all sessions, revoke unknown app access, and contact your bank or payment providers about the attempted charges. Back up only personal files such as photos and documents—not programs, installers, scripts, or browser profiles—and scan the backup before opening anything. Then use Windows' built-in reset or installation media when possible. A clean scan is encouraging, but it cannot prove that a sophisticated infection or stolen session is gone.
I did change passwords after the first incident, but Instagram was accessed again about a week later. I will change everything again from a different device, sign out everywhere, and reset the computer after backing up only my photos and documents.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures