My cousins borrowed my Windows 11 laptop, and afterward it became very slow with multiple Command Prompt windows appearing unexpectedly. Several of my accounts were compromised, and after I recovered one and logged in again from this laptop, someone accessed it the following day. I'm worried that malware may be stealing passwords or browser session data, though I don't know whether it came from a download or a scam link. I don't have many important files on the laptop, so I'm considering completely resetting Windows. Would that be enough, and what steps should I take to make sure the infection is gone?
1 Answer
Treat the laptop as compromised and stop logging into accounts from it. Using a different, trusted device, change your email and other important passwords, sign out of all active sessions, remove unfamiliar recovery methods, and enable two-factor authentication. Then reinstall Windows rather than trying to clean the existing system. A full reset from Settings may work, but a clean installation from a USB created on another known-clean computer is the safer option. Back up only personal documents and photos after checking them, and do not restore unknown programs, browser extensions, or executables.
The built-in reset is better than continuing to use the infected installation, especially if you choose to remove everything and download or reinstall Windows. However, external installation media made on a clean computer is more reassuring when accounts have clearly been compromised. Either way, change passwords and revoke sessions before signing in again, and fully update Windows and your security software afterward.

Would the built-in reset option be enough? Creating a USB installer on another computer might be difficult.