My Discord account on my PC was recently compromised and used to promote cryptocurrency. I signed out, changed my passwords, and have not logged back into Discord for three days. Today, Steam attempted to send a game as a gift to another person, but Steam blocked the transaction. I already have Steam Guard enabled, so this was unexpected.
Windows Defender's quick and full scans found nothing. I have not knowingly downloaded anything recently, although I visited reservation websites while planning an international trip. I'm unsure whether this is simply a series of compromised sessions or whether malware on my computer is stealing browser cookies or account credentials.
I later ran HitmanPro, which detected and quarantined five items. A second scan and a scan with RKill found nothing, and I'm also running Malwarebytes. What other steps should I take to confirm the computer is safe and protect my accounts?
3 Answers
Do not log back into important accounts repeatedly until the system has been checked. If the scans keep finding threats, or you notice more unauthorized activity, back up only personal documents, wipe and reinstall the operating system, apply all updates, and then change passwords again from the clean installation. Also contact Steam support about the blocked transaction and monitor your payment methods.
Run a reputable second-opinion scanner such as HitmanPro and Malwarebytes, then check your browser extensions, downloads folder, installed programs, and notification permissions for anything unfamiliar. Clear browser cookies and cache, and remove anything you do not recognize. Since several accounts were targeted, change passwords from a known-clean device and make sure every account has a unique password and two-factor authentication enabled.
A clean Windows scan does not completely rule out stolen browser sessions or credentials. Review the security pages for your email, Discord, Steam, and other important accounts: sign out all sessions, revoke unknown authorized apps, remove unfamiliar recovery methods, and regenerate backup codes if necessary. Also check whether any browser extensions or saved sessions were compromised.
The Discord password was unique and only used for a streaming account, so password reuse may not explain it. I’m checking active sessions and authorized applications as well as scanning the computer.

HitmanPro found five items and quarantined them. A second scan found nothing, and I’m running Malwarebytes now. Steam Guard was already enabled, which is why the attempted gift seemed especially strange.