About three weeks ago, I downloaded a malicious file and discovered the next day that my social media account had been accessed: posts were made and unfamiliar accounts were followed. I immediately disconnected the PC, cleared browser cookies, changed passwords, signed out other devices, and performed a clean Windows 11 reinstall from a USB drive after deleting every partition on the storage drive. My other accounts have remained normal since then, and I use a clean phone for account recovery and password changes. However, I recently logged back into another social media account and found that the username, display name, profile picture, and date of birth had all been changed. I deactivated that account, but now I'm worried that the infostealer somehow survived the reinstall. Is there a reliable way to check whether the PC is still infected, or is this more likely to be an old stolen session or an account-specific compromise?
3 Answers
If the account was changed only once and the rest of your accounts are unaffected after a full reinstall, that does not strongly suggest the malware is still present. It could have been an old session that remained valid, a reused or similar password, or a separate breach involving that service. Check the account’s login history, recovery email and phone number, connected applications, forwarding rules, and any unfamiliar authorized devices.
A clean reinstall that deletes all partitions should remove ordinary infostealer malware from the Windows installation. The more likely explanation is that the attacker stole an active session token or login cookie. Password changes do not always invalidate every existing session, so use each account’s security page to sign out every device and revoke active sessions, then change passwords again from the clean phone or freshly reinstalled PC. Turn on two-factor authentication as well.
Avoid reusing variations of the same password. An infostealer may have captured browser-stored credentials, cookies, or encryption material before the reinstall. Use a unique random password for every account, preferably generated by a reputable password manager, and enable app-based or hardware-based two-factor authentication where possible. Also scan any files or installers restored from backups before opening them.
That’s probably part of the problem since I tend to reuse variations of one base password. I’ll replace those with unique passwords and review the connected apps and sign-in history.

I did sign out all other devices and change the passwords, which is why it’s strange that only this one account was affected much later. My other accounts still look normal.