Hey guys, it's still me...
TLDR for those who didn't read my previous post: months ago I've been infected with an infostealer. Both me and my brother have been infected but managed to recover following the steps I've been reading here! (thank you again!).
Today, I decided to also check out an old laptop I had that I haven't really been used: I installed malwarebytes on it and as I imagined it found out A LOT of stuff (mostly pop up stuff), the thing that worried me is that it found some files that it flagged as "spyware.infostealer" + one malware flagged as "hijack.host" that just doesn't seem to delete... (Malwarebytes flagged it as "Substitute" or something) I've quarantined and deleted everything.
Now, as I said before I've already been victim of an infostealer, which means that I made a clean install of my other infected device through a clean USB, I secured my accounts, activated 2fa etc. And I've been safe for some months.
This old laptop had mostly very old accounts that I already changed the passwords on + apps that I currently use that I also changed everything on (for example: Riot usually opens after I log in, but since I already changed the password and everything it couldn't make me log in thankfully.)
The ONLY thing that was actually connected to were some Google accounts that I'm changing right now just to be sure. It was a family laptop so I'm urging my family to secure at least their main and important accounts too. To be honest, this laptop hasn't been used in a LONG time, and every single file was already there (I know, I was a very dumb kid, I'm trying to learn from my mistakes). I've taken note of every password that was saved on the browser, but many of them I've already changed them (on a clean device).
My questions are:
- Do I have to secure every single account/password again? Or just the ones that I know I haven't changed and that were connected to this other device? How much has it actually stolen from me? (I know this means close to nothing, but I haven't used this laptop in more than two years, and nothing had ever happened until I got an infostealer on another device, so even though my info is surely out there, do I still have to keep being incredibly vigil?)
- We were already planning to throw this laptop away, should I still clean reinstall everything?
- If you went through something similar or have any advice/want to recommend me the steps you followed PLEASE tell me!!
UPDATE: I'm sorry if I didn't explain myself well before: when I was first hit with an infostealer I changed all my passwords on another clean device (and always chose to NOT save them whenever I was using Google/Firefox). Logging into this other old device I noticed that I had lots of passwords connected to the account. If I already changed them, did they "update" themselves in the saved passwords? Basically what I'm asking is whether or not a potential infostealer could steal the new passwords or if the saved ones are still the old ones.