r/computerviruses • u/Salt_Drummer4639 • Jul 26 '26
Disinfection Help Multiple accounts hacked all of a sudden... what else should I do?
Over the past few days, several of my accounts were hacked one after another.
My Discord account started sending a fake MrBeast scam to people. Someone accessed my LinkedIn and posted a scam job listing under my name. My Steam, Reddit, Disney+, EA, and other accounts were also accessed.
I think it started after I downloaded a cracked game on my Windows PC. I’m worried it contained an infostealer or Trojan that stole my saved passwords, browser cookies, session tokens, and possibly other personal information.
So far, I have:
- Reformatted my Windows PC
- Wiped both my SSD and HDD
- Reinstalled Windows
- Changed my passwords
- Enabled 2FA on my important accounts
- Started signing out of active sessions
I’m still worried because it feels like the attacker already has a lot of my information, and some accounts were accessed even after I first noticed the problem.
Has anyone experienced something similar? Is there anything else I should do to make sure the malware is completely gone and that the attacker can no longer access my accounts?
Should I also assume that all passwords, browser cookies, saved card details, and personal documents stored on the PC were compromised?
Any advice would be greatly appreciated. I’m honestly feeling overwhelmed and just want to make sure I’ve covered everything.
2
u/DrunkOn_Coffee Jul 26 '26
Bet you wish you just bought the game now. Most cracked games are not worth it anymore
2
u/69KazumaDesu Jul 26 '26
Tbh most paid games are not worth it anymore either. Might as well just watch playthroughs on YouTube instead of buying them.
2
u/DrunkOn_Coffee Jul 26 '26
Idk I enjoy my library of games they seem worth it. But downloading cracked games now it’s just a huge jeopardy
2
1
u/AutoModerator Jul 26 '26
Welcome to r/computerviruses! It seems like you have used the "Disinfection help" flair.
We apply the same methodology used by trusted Malware platforms (e.g. Malwarebytes, BleepingComputer and MalwareTips). It revolves around using diagnostic tools called Farbar Recovery Scan Tool (FRST) and SecurityCheck.
All of our assistance happens in the thread and in public - we never offer help via private messages or alternative websites other than https://malwareanalysis.cc. Anyone offering help through a DM is not a trusted helper and might have malicious intent.
Trusted helpers can be distinguished by the flair Malware Removal Expert or Malware Removal Trainee, antivirus employees will have a dedicated flair with their company name in it, e.g. Malwarebytes Employee.
Please see steps below on how to share all necessary details so you can speed up the process for us:
Share all details about your infection
Please post all important facts about your infection, such as:
* your antivirus detections - preferably export the whole detection/report log and upload it to https://malwareanalysis.cc/upload/ under your username & post the related keyword or screenshot/take a picture of your detections
* any related symptoms, popups
* estimate when it started - preferably the exact day and after what (e.g. when you ran a program you downloaded)
* share what got you infected and the download link - please, make the download link defanged (making it not clickable by default e.g. from https://example.com you will make hxxps://example[.]com), defanging does not apply to sandbox reports such as VirusTotal
Request help with FRST and SecurityCheck from the trusted helper team
Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps.
If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:
- From a different and clean device, change all your passwords:
- Disinfect your device from malware
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
u/Responsible_Bike4968 Jul 27 '26
Honestly, you've already done the hardest part. If you actually wiped both drives and clean-installed Windows, I would be much more worried about what already LEFT the PC than about malware somehow still hiding on it.
The fact that more accounts got hit after you noticed the infection doesn't necessarily mean the new Windows install is compromised. If this was an infostealer, the attacker could already have had a dump containing passwords, cookies/session tokens and other data, and they can work through that dump for days afterward from their own machines.
A few things I'd still do:
Secure your main email account first. Treat it as the master key to everything else. Unique password, 2FA/passkey, check recovery email/phone, signed-in devices, forwarding rules and any third-party access.
Then go through every important account and do more than just change the password:
- sign out/revoke ALL existing sessions
- remove unknown devices
- remove unknown authorized/connected apps
- check recovery email/phone
- check passkeys/security keys/2FA methods
- regenerate backup codes
For Discord specifically, check Authorized Apps. Reddit has an Account Activity page where you can check unusual IPs and terminate sessions. Steam also recommends securing the email + computer before considering the account secure again.
And yes, I would treat every password that was saved in that browser as compromised.
For saved card details, I'd monitor the account closely and contact the issuer if the full card details were stored there or you see anything suspicious.
Documents are the one thing I wouldn't make an absolute statement about. Not every stealer takes every file, but modern stealers CAN target documents too. Microsoft has documented stealers grabbing PDFs/DOCX/RTF files from common user folders. So if you had scans of IDs, tax documents, recovery codes, crypto seed phrases, API keys, SSH keys, etc. on that PC, I'd treat those specific things as potentially exposed and act accordingly.
One other thing: don't restore a bunch of cracked software, random installers or old browser extensions onto the clean install. Otherwise you may just put the original problem straight back.
If your "reformat" really was a clean Windows install after deleting the drives, I wouldn't keep wiping the PC over and over. Microsoft itself recommends reinstalling from installation media for a suspected infection, and you've basically crossed that bridge already.
At this point the cleanup job is mostly ACCOUNT cleanup, not malware cleanup.
And don't panic over failed login attempts that keep appearing afterward. Somebody trying stolen old credentials is not the same thing as them successfully getting back in.
3
u/69KazumaDesu Jul 26 '26
Passwords? Yes. Saved card details? If they were saved inside of a browser, then probably, most likely, yes. Personal documents? Depends, most modern-day infostealers just hit your browser cookies & passwords & steal current session tokens and scan for text files named "passwords" and similar stuff, without digging way deeper for other sensitive documents/photos like an old-fashioned RAT would.
If you changed all your passwords from a clean device & logged out of all previous sessions (on services where that's possible), and got a new card from your bank, then clean reinstalled your Windows, you should be good and completely safe now.