I clicked a URL that appeared legitimate, but I'm worried it installed spyware. Since then, I've noticed unusual processes that I can't remove and memory usage around 14 GB even when I'm barely running anything. The issue may have started on my phone while it was connected to my computer, and now I'm concerned that files, passwords, and other account details may have been copied. I want to secure my accounts, preserve essential files, and then wipe and reinstall the operating system. What is the safest order of steps, and how can I back up data without exposing passwords or sensitive documents to a possible keylogger?
3 Answers
Back up only personal files you truly need, such as photos and documents, to an external drive. Avoid copying programs, installers, scripts, browser profiles, or unknown files. If a document contains highly sensitive information, consider leaving it offline until the system has been reinstalled and scanned. You can also have a professional handle the backup if you’re worried about opening files or exposing credentials. After reinstalling, restore files selectively and change passwords again if necessary.
For the computer, a clean operating-system installation is generally safer than trying to identify and delete every suspicious process. Create the installation media using a trusted computer, wipe the system drive during setup, and install all updates afterward. Hardware is usually not damaged by ordinary spyware; the unusual memory usage is more likely to be a software issue. If you suspect firmware-level malware or the machine behaves strangely after a clean install, have the device examined by a qualified technician.
Disconnect the computer and phone from the internet first, including Wi-Fi, Ethernet, Bluetooth, and any shared devices. Don’t use the possibly compromised computer or phone to change passwords. From a device you trust, change your email password first, then banking, password-manager, cloud-storage, and other important passwords. Revoke active sessions, remove unknown recovery methods, and enable two-factor authentication with an authenticator app or security key where possible.
If the phone may also be affected, use a different trusted device for the account changes. Review recent sign-ins and assume any password entered on the suspect devices could have been captured.

A clean install won’t protect files or accounts that were already copied, so secure accounts from a separate trusted device before reconnecting the wiped computer.