Back to PC Setup

My PC is Infected - Now What?

Stay calm. Follow these three steps in order. Skipping ahead - especially to Recovery - without completing Backup can mean permanent data loss.

Step 1: Diagnosis
Step 2: Backup
Step 3: Recovery
Step 1 - Diagnosis

Determine what you're dealing with before taking action. Rushing to wipe without documenting can leave you without important information.

Document What You See

  • Take photos or screenshots of any popups, warnings, ransom notices, or unusual behavior - use your phone if the screen is locked or your PC can't screenshot normally.
  • Note the exact error messages, URLs, or company names shown - these help identify the specific threat.
  • Note when the symptoms started and what you did right before (opened an email attachment, ran a downloaded file, visited an unfamiliar site, etc.).

Disconnect from the Network Immediately

Unplug the ethernet cable or disable Wi-Fi as soon as you suspect an infection. Many malware types report back to a command-and-control server, exfiltrate data, or spread to other devices on your network while connected. Cutting the connection limits the damage.

Run Malwarebytes (Free)

Malwarebytes Free is the most widely trusted second-opinion scanner - it catches threats that Windows Defender and built-in antivirus miss. Download it from another device if needed, transfer via USB, and run a full scan.

Download Malwarebytes Free →
  • Run a Threat Scan first - it covers the most common infection locations without a full disk scan.
  • Save the scan report - it lists exactly what was found and where. This helps confirm whether you caught everything.

Assess the Severity

Likely Recoverable

Adware, browser hijacker, PUPs (potentially unwanted programs), mild trojan - Malwarebytes often cleans these.

Wipe Required

Ransomware, rootkit, keylogger, remote access trojan (RAT) - these go deep. A clean reinstall is the only safe recovery.

When in doubt, wipe. A reinstall takes a few hours. An undetected keylogger can cost far more.

While it is very possible to clean a lightly infected system, Wizard Tech Services will always recommend a complete wipe for any level of infection and will consider the machine compromised until a full format and reinstall is complete.

Step 2 - Backup

Save what you can't replace. Do this before wiping - but be selective. Backing up infected files defeats the purpose.

Boot Into Safe Mode First

Windows

Hold Shift while clicking Restart → Troubleshoot → Advanced Options → Startup Settings → Restart → press 4 for Safe Mode. Many malware types cannot run in Safe Mode, making it safer to copy files.

Linux

Boot from a live USB (Ubuntu, Fedora, etc.) to access your drive without booting the infected OS. This gives you a clean environment to copy files from the mounted drive.

What to Back Up - Flat Data Only

Copy only files you cannot re-download or recreate. Use a fresh external drive or flash drive if possible - don't mix potentially exposed files with your known-clean backups.

Personal photos and videos
Game saves (check exact save locations per game)
Personal documents (.pdf, .docx, .xlsx, .txt)
Music you own (not streamed)
Browser bookmarks (exported, not synced profile)
Wallet files, 2FA backup codes, important credentials
Project files (art, music, writing, code you created)

What NOT to Back Up

Viruses and malware frequently hide inside or attach themselves to executable and system files. Copying these to your backup drive can re-infect a clean system the moment you open or run them.

.exe - Executables - programs, installers, launchers
.bat / .cmd - Batch scripts
.dll - Dynamic link libraries - commonly hijacked
.msi - Windows installer packages
.vbs / .ps1 - Visual Basic and PowerShell scripts
.lnk - Shortcuts - can point to malicious files
Program Files - Installed software folders
AppData - App data folders - often contain malware persistence

Check Cloud Sync - This Is Critical

If your cloud sync or browser profile was active during the infection, it may have already uploaded infected files or settings to the cloud. Signing into a fresh, clean PC without addressing this will re-download the infection automatically.

Google Chrome Sync

If Chrome was open during the infection, your synced profile (extensions, settings) may be compromised. Export your bookmarks manually (Bookmarks Manager → Export), note any saved contacts or passwords, then go to myaccount.google.com → Security → Manage all devices and sign out everywhere. In Chrome sync settings, turn off sync before signing in on a new device, then review your extensions carefully before re-enabling sync.

OneDrive / Google Drive / iCloud

Access your cloud storage through the web UI (onedrive.live.com, drive.google.com) - not the desktop app on the infected machine. Look for any recently synced files that seem unfamiliar or that weren't there before the infection. Manually delete any suspicious non-flat files (executables, scripts, zips from unknown sources). Do not restore from a backup snapshot taken after the infection started. If OneDrive was actively syncing, also check version history to verify your important files are clean before restoring them.

Step 3 - Recovery

The only guaranteed clean state is a fresh install. This is not optional for serious infections.

Wipe and Reinstall - No Exceptions

Attempting to "clean" a serious infection by deleting files or running tools on the live infected OS is unreliable. Rootkits and advanced malware can survive these attempts by hiding from scanners or reinstalling themselves on reboot. A full format and OS reinstall is the only trustworthy recovery path.

Windows

  1. Download the Windows 11 Media Creation Tool from microsoft.com on a clean PC
  2. Create a bootable USB (8 GB+)
  3. Boot from the USB (press F11/F12/Del at startup)
  4. Select Custom Install, delete all partitions on the target drive, and install fresh
  5. Do NOT choose "Keep my files" - this does not wipe the infection

Linux

  1. Download the ISO for your distro on a clean PC
  2. Flash it to USB with Balena Etcher or Rufus
  3. Boot the USB and choose to format the target partition during install
  4. Do not mount or restore from the infected drive until it is fully formatted

Get Up and Running Quickly After Reinstall

A clean install can feel bare. Both tools below are from Chris Titus - no download or install required, run directly from a single command. Visit the PC Setup page for more details on each.

Windows - PowerShell (Admin):

irm christitus.com/win | iex

Installs apps, removes bloat, applies tweaks - fully GUI-driven.

Linux - Terminal:

curl -fsSL https://christitus.com/linux | sh

Supports Ubuntu, Fedora, Arch, Debian - installs essentials, configures your distro from a TUI menu.

Stay Observant While Syncing Back

When moving files back from your backup drive, go category by category - don't drag everything over at once. Watch for any unexpected behavior or new popups as you restore files. If something triggers right after restoring a folder, that folder may still contain infected files.

  • Install Windows Defender or Malwarebytes before plugging in the backup drive
  • Scan the backup drive before copying anything off it
  • Re-enable cloud sync (OneDrive, Chrome, etc.) last, after you've verified the local machine is clean
  • Change passwords for any accounts that were logged in on the infected machine - especially email, banking, and any saved browser passwords

Data that may have been leaked: If the infection included a keylogger or information-stealing trojan, assume that any passwords typed, credit card numbers entered, or files opened during the infection period may have been exfiltrated. Change all passwords from a clean device and consider enabling fraud alerts with your bank and credit bureaus.

Need hands-on help?

Wizard Tech Services offers Remote Repair & Diagnostics - we can walk you through diagnosis and recovery, or take a remote look at your system before you decide to wipe.