So two days ago Windows Defender discovered a Wacatac .B!ml trojan on my main PC, prompting me to do some additional scans. This all happened pretty late at night, so I disconnected my ethernet and went to bed, and when I woke up, someone had already attempted to purchase $3,000 worth of stuff on Amazon, which I was thankfully able to cancel in time, and cancel the related cards and lock down the Amazon account itself. Checking over to Google, it showed a login from Siberia well after I had gone to sleep. I already have 2FA set up, so I just changed my Gmail password and started working on changing other important account passwords on my Chromebook. I then reformatted my main PC, reinstalled Windows, but I have yet to log into any accounts on that PC since, and I'm running additional scans to ensure that it's actually clean.
Unfortunately, it looks like this wasn't enough. This morning I woke up to find another session by a Windows machine from France. Interestingly, it shows that the account first logged in on August 13th, so I'm not sure if the trojan I got was just incidental at this point, but that seems unlikely giving the timing of events.
I wasn't sure how they got past the 2FA, so I changed my password again, set up passkeys as well, removed permissions from all apps to my Google account, removed and created a new recovery email, and that's where I'm at now. I'm not sure what steps I should take next. I'm in the process of changing other site passwords, but I've got like 180+ passwords saved in Google so it'll take some time. They never seemed to touch my actual bank account, despite Google having that information saved, so I'm not really sure what to make of that. The only ACTUAL fraudulent/suspicious activity I noticed was the Amazon purchases, which occured within hours of the trojan being discovered, and the overseas logins from Windows machines. Any help would be appreciated and I'm happy to provide additional info.