For the past few weeks, unfamiliar Chinese searches have been appearing in my YouTube history. Random children's, Spider-Man, and brightly colored videos are also being added to my liked videos, although they usually do not show up in my watch history. Changing my Google password has not stopped the activity.
I have also found outgoing SMS messages addressed to several unknown numbers. The messages contain "YESPRODUPI" followed by random characters, but they appear as "Not Sent," and I did not write them.
This may have started after I installed a cracked or suspicious game on my Windows laptop. Later, my Instagram account was compromised and sent betting or scam links, followed by unusual activity on my Google and YouTube accounts. I have tried Malwarebytes and some command-line instructions, and one tool suggested the malware might have reached a deep system level. What should I check and secure first?
2 Answers
Treat this as a possible account compromise and potentially compromised devices. From your Google Account security page, sign out every unfamiliar device, remove unknown third-party access, review recent security events, and enable two-factor authentication using a method you control. Change the Google password from a known-clean device, and do not reuse it anywhere else. Also check browser extensions and remove anything you do not recognize.
On the phone, review installed apps for unfamiliar, duplicated, blank, or oddly named entries. Check Accessibility, Device Administrator, notification access, VPN, and default SMS permissions for apps you did not deliberately authorize. The SMS could be a failed verification or activation attempt from an app, but it is safer to contact your carrier and ask whether premium SMS, message forwarding, or unusual account activity is enabled.
Because the laptop came from a cracked-game installation and other accounts were affected, do not rely on a few cleanup commands or a chatbot’s claim that malware is “dead.” Back up only personal documents, then perform a clean operating-system reinstall from official installation media, fully update it, and change important passwords afterward from the rebuilt system. Check financial and payment accounts for unauthorized activity as well.
The YouTube behavior may indicate that someone still has an active session, a browser extension is controlling the account, or another device is signed in. Password changes alone may not remove existing sessions or stolen browser tokens, so revoke all sessions and connected applications. Check YouTube’s account activity from a clean device and secure the recovery email and phone number too.
For the phone, take screenshots of the SMS details, check which app generated them, and ask the carrier to investigate the destination numbers and message type. If the phone has an unknown app with Accessibility or administrator access, disconnect it from sensitive accounts and consider a factory reset after backing up essential data. Do not restore untrusted apps or a full device backup afterward.

The suspicious game was installed on my Windows laptop before the Instagram and Google activity began. I ran Malwarebytes and some commands, but I’m not sure whether the machine is actually clean, so I’ll treat a clean reinstall as the safer option.