I installed Golf Gang through Steam after someone I had recently met online encouraged me to play it with them and gifted me the game. Shortly afterward, my webcam activated and I became concerned that a remote-access trojan or other malware had been installed. I was also nearly locked out of several accounts that were signed in on that computer. After resetting the PC and changing many passwords, the same people began sending me Discord friend requests containing screenshots of private conversations, which feels like an attempt to intimidate or extort me. I chose the cloud-reset option in Windows, but I'm unsure whether that completely removed the malware. What steps should I take to secure my accounts and make sure the computer is clean?
3 Answers
Treat the computer as compromised until you can reinstall Windows from trusted installation media. Using a different, trusted device, change every important password, make each one unique, revoke active sessions, check recovery email addresses and phone numbers, and enable app-based two-factor authentication. Prioritize email, Steam, Discord, banking, and password-manager accounts. Save evidence of the messages and report the harassment, but do not engage with or pay the people contacting you.
A cloud reset is generally much safer than keeping personal files, but the most thorough approach is to create official Windows installation media on a trusted computer, boot from it, delete the existing system partitions, and perform a clean installation. If you aren’t comfortable doing that, take the machine to a reputable repair shop or ask someone technically experienced to help. Don’t restore unknown programs or downloads afterward, and update Windows and your security software before signing back into accounts.
The person also pushed me to install another game and sent the invitations through Steam messages. I didn’t use a workshop mod as far as I know, so I’m worried the account or a malicious download was involved.
Don’t assume the game itself is definitely the cause without forensic evidence. The attacker could have used social engineering, a malicious link, a fake installer, stolen credentials, or another download. Review account-login alerts and connected applications, scan other devices that shared credentials, and contact your email provider, financial institutions, or local cybercrime authority if money or sensitive data was involved. Block the accounts sending threats and tighten Discord privacy settings so only trusted contacts can add or message you.

Is the normal Windows reset enough, or do I need a USB installer? I don’t currently have one and I’m not sure how to create it.