About three weeks ago, I downloaded a malicious file and apparently got infected with an infostealer. I noticed the next day when my Instagram account posted content and followed unfamiliar accounts. I disconnected the computer from the internet, cleared cookies from Chrome and Opera GX, changed my passwords, and performed a clean Windows 11 reinstall from a USB drive after deleting all partitions on the storage drive. Everything seemed normal afterward.
Today, I opened Twitter and found that I had been logged out. After signing back in, I discovered that the account's handle, display name, profile picture, and date of birth had all been changed. I deactivated the account because I rarely use it, but this made me wonder whether the computer could still be infected. My Instagram, Steam, Discord, and other accounts appear normal.
I have already changed passwords, cleared cookies, and signed out or removed every other device from my accounts. I only used my phone for those changes, and the phone is clean. Is there any reliable way to determine whether an infostealer remains on the PC? I am running Windows 11 Home and also have Group Policy Editor installed.
3 Answers
There is no single Windows setting or Group Policy option that can prove an infostealer is absent. Run an updated Microsoft Defender Offline scan and review startup items, scheduled tasks, browser extensions, and installed applications, but remember that a clean reinstall is generally more trustworthy than trying to disinfect the old installation. If suspicious account activity continues after the reinstall and full session revocation, investigate the email account, reused passwords, recovery options, and third-party app access before assuming the PC is still infected.
Check the account’s login history and connected apps for the time and location of the suspicious activity. Also make sure your email account and Microsoft account are secure, since access to either can help someone reset other accounts. Avoid reusing similar passwords; if one variation was exposed, attackers may try predictable variations. Use unique passwords from a reputable password manager and turn on an authenticator app or security key where possible.
A clean reinstall that deletes the existing partitions makes a continuing infection on the Windows installation unlikely, assuming the USB installer itself was created from a trustworthy computer and the firmware has not been compromised. The more likely explanation is that the attacker retained an active session token or that the Twitter account was compromised separately. Changing a password does not always invalidate every existing login session, so use each service’s security page to sign out all sessions, revoke connected applications, remove unknown recovery methods, enable two-factor authentication, and generate backup codes.
I did sign out all devices and change the account passwords, which is why the Twitter-only incident seemed unusual. I was mainly concerned that the malware somehow survived the reinstall.

I tend to reuse variations of the same base password, so that is definitely something I need to fix. My Microsoft account was also signed out on other devices and had its password changed.