I use a Windows desktop PC and recently downloaded a fake installer from a pop-up-heavy website. It displayed a download screen that never finished, but malware was apparently installed. Soon afterward, a command sent a cryptocurrency scam message to my Discord contacts, my Steam account was accessed, and unauthorized gifts were purchased using my card. I replaced the card, requested refunds, and changed my Discord and Steam passwords. Malwarebytes found more than 20 trojans and other threats, which it removed, and later scans have been clean. However, I have since received suspicious login attempts involving both of my main email accounts, an old chess account, and an unused Roblox account. I have changed several passwords and enabled two-factor authentication, but I am worried that the malware stole saved credentials or that something is still active. What might be happening, and what steps should I take now?
3 Answers
An information-stealing infection may have copied passwords, browser cookies, saved payment details, and session tokens before the antivirus scan removed it. A clean scan does not prove that every credential was safe. Change passwords from a different, known-clean device, starting with your email accounts, banking, password manager, and anything that can reset other accounts. Make every password unique, sign out other sessions, and review recent activity and recovery options. Two-factor authentication helps, but it is not a guarantee if an attacker already stole an active session or recovery method.
Check every account's linked devices, connected applications, forwarding rules, recovery email addresses, phone numbers, backup codes, and active login sessions—not just the password and 2FA setting. Remove anything unfamiliar and generate new backup codes. Contact your bank or card provider about the unauthorized activity, monitor statements, and consider using a new primary email address if the old ones were heavily exposed.
Because multiple accounts are being targeted after a serious infection, the safest option is a full Windows reinstall from official installation media. Back up only personal documents, photos, and other files you know are safe; do not restore unknown programs, cracked software, browser profiles, or executables. After reinstalling, fully update Windows and your browser, reinstall programs from official sources, and change passwords again from the clean system.

I changed my email, bank, Steam, Discord, Epic, and Ubisoft passwords and enabled two-factor authentication. I will check the recovery settings and active sessions too.