Could Malware Still Be Accessing My Accounts After a Fresh Windows Install?

0
0
Asked By MellowCedar47 On

I downloaded a suspicious file, and within two days several of my online accounts were compromised. Windows Defender found and removed multiple trojans. I then bought a new SSD and installed Windows from scratch, but I'm still receiving notifications about login attempts.

I've signed out of my accounts everywhere, reset my passwords, disconnected the computer, and flashed the BIOS. Some passwords were apparently changed without triggering my two-factor authentication, so I'm concerned that session tokens may have been stolen. Could this be a rootkit in the motherboard firmware or another drive? I'd prefer not to wipe every disk unless it's necessary. What else should I check?

4 Answers

Answered By CobaltMeadow26 On

If other internal or external drives were connected when the infection occurred, back up only personal documents and photos, then wipe those drives before reusing them. Don’t copy unknown executables or scripts. For maximum confidence, create the Windows installer using a separate trusted computer, or scan the system and drives from trusted bootable security media. Consider moving important accounts to a new email address after the existing ones are secured.

Answered By AmberLattice91 On

Check every account’s security settings for unfamiliar recovery addresses, phone numbers, authenticators, app passwords, active sessions, forwarding rules, and newly created access tokens. Secure your primary email first, since control of it can be used to reset other accounts. Also review your password manager from a clean device and replace any reused passwords.

Answered By PixelBirch62 On

A fresh Windows installation on a new system drive probably removed the original malware. A motherboard firmware rootkit is technically possible but extremely uncommon compared with stolen credentials, browser data, or session cookies. Reflashing the BIOS was already a reasonable precaution, but it usually isn’t the first explanation for this situation.

NorthwindMica3 -

The repeated attempts may simply be people using credentials that were stolen before the reinstall. Seeing attempts does not mean they can still access the accounts.

Answered By QuietHarbor8 On

First, distinguish between failed login attempts and successful account access. If the attacker stole your old passwords or email addresses, they may continue trying them for some time. Reset every password from a separate, trusted device, enable two-factor authentication, and use each service’s option to sign out all sessions or devices.

MellowCedar47 -

Some logins did succeed, and a few passwords were changed without prompting for 2FA. I’m wondering whether stolen session tokens explain that, although I’ve now signed out everywhere.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.