I lent my Windows 11 laptop to a family member, and afterward it became unusually slow and started opening multiple Command Prompt windows. Several of my accounts were accessed, and after recovering my Discord account, someone was able to log in again shortly after I entered the new password on the possibly infected laptop. I'm not sure whether this came from a malicious download, a scam link, stolen browser cookies, or something else. I don't have many important files on the computer, so I'd rather completely erase it and start fresh. Would resetting Windows through Settings be enough, or should I use another method?
1 Answer
Treat the laptop as compromised and stop signing into accounts on it. From a different, trusted device, change your email password first, then change your other important passwords, sign out of all existing sessions, remove unknown recovery methods, and enable two-factor authentication. Since browser session cookies may have been stolen, changing only the password may not be enough unless you also revoke active sessions. Back up only personal documents you know are safe, then perform a clean Windows installation from a USB installer created on a trusted computer. A reset from Settings may work, but a clean USB install is generally the safer choice when you don’t know what changed on the system.
The built-in reset is better than continuing to use the infected installation, especially if you choose to remove everything, but it provides less confidence than deleting the partitions and installing Windows from trusted installation media. If you use Reset this PC, choose Remove everything, use the cloud download option if available, and update Windows fully before restoring files or signing into accounts.

Would using Windows’ built-in reset option be sufficient? Creating a USB installer would be difficult for me.