Malware infection question


Recommended Posts

Usually when I have somebody come up to me with a computer that has Malware on it, I simply re install everything for them. Say what you want abotu it, but it is much faster to re-install than spend potentially days fixing the computer and making sure it is right before they go back to their banking.

So my question is this, I usually do a format, and re-install. Will a Windows 8 Clean Install Upgrade get rid of infections? I only ask because it still does make a Windows.Old folder if I remember. Couldn't the malware be in there when it is all done?

Lastly, has there been any word as to the $40 Windows 8 upgrade and installing it on a fresh drive? When I installed it, I needed Windows 7 fully installed before in order to get 8 to activate.

Link to comment
https://www.neowin.net/forum/topic/1120900-malware-infection-question/
Share on other sites

You should be able to format the HDD with the upgrade media, yes. At least I could with mine...

Ah I gotcha. So I think what I am understanding right is that I DO need to have some previous Windows version installed, but when I boot with the Windows 8 media, I can format it there just like Windows 7? That is probably why it did not work for me, nothing was on the drive when I tried.

3 hours, if it takes longer than 3 hours you are doing it wrong or they have a million files or so or a computer built in 1990.

I spend a few hours cleaning it, if it comes back within a week, which rarely does, I wipe and rebuild. You need new techniques.

On to your question, if you don't delete the partition and reformat the infection can still be in the boot sector. In the past, when doing a clean install from a upgrade disk you would just need to put in your old os media (xp, vista, etc).

Ah I gotcha. So I think what I am understanding right is that I DO need to have some previous Windows version installed, but when I boot with the Windows 8 media, I can format it there just like Windows 7? That is probably why it did not work for me, nothing was on the drive when I tried.

I also have 3 HDD's in my machine, which could have triggered the option to pop up. :p

3 hours, if it takes longer than 3 hours you are doing it wrong or they have a million files or so or a computer built in 1990.

I spend a few hours cleaning it, if it comes back within a week, which rarely does, I wipe and rebuild. You need new techniques. If you don't format, the infection can still be in the boot sector.

I seem to notice more and more that people's solution to a computer that doesn't work or is infected seems to be "step 1: format the machine." It's bizarre, for me a format has always been the final option, not the first. I would have lots of unhappy customers if I kept taking their laptop away and wiping it. :laugh:

I seem to notice more and more that people's solution to a computer that doesn't work or is infected seems to be "step 1: format the machine." It's bizarre, for me a format has always been the final option, not the first. I would have lots of unhappy customers if I kept taking their laptop away and wiping it. :laugh:

No one would trust me to do squat and word of mouth would be nil. Have to keep people happy, have to be fast, and have to keep data integrity. They want their computer back in a working state with all of their apps and files in tact.

I seem to notice more and more that people's solution to a computer that doesn't work or is infected seems to be "step 1: format the machine." It's bizarre, for me a format has always been the final option, not the first. I would have lots of unhappy customers if I kept taking their laptop away and wiping it. :laugh:

Format and reinstall is the only way to be 100% sure the malware is gone. I swear by this and its always my first option. Also you will have less repeats when this happens. Customers are alot careful due to the format and reinstall.
Format and reinstall is the only way to be 100% sure the malware is gone. I swear by this and its always my first option. Also you will have less repeats when this happens. Customers are alot careful due to the format and reinstall.

Sorry, I disagree. As sc302 said, all wiping their machine will do is send them to someone else next time who will attempt to preserve their data and settings. If someone on my team suggested formatting a machine as the first step, I'd have them removed from my team.

See we like our customers and like referrals. Referrals is free money. I spent 0 advertising dollars to get them in my door. I formatted once and cost a client and a minimum of 10 of their friends. I explained what was needed and she was not happy then when she picked up her computer she wasn't happy that I didn't have everything back to the way it was when she gave it to me. To get her out the door I had to eat it. Never has it happened again. Most people appreciate the effort and understand that if it needs to come back within a week that they should have a backup performed (I charge extra for the backup) but will wipe and rebuild their computer with any software they provide at no additional cost.

Again, that doesn't happen often. Once last year was the last I can remember.

Sorry, I disagree. As sc302 said, all wiping their machine will do is send them to someone else next time who will attempt to preserve their data and settings. If someone on my team suggested formatting a machine as the first step, I'd have them removed from my team.

I'm with you on this one, I used to just wipe and reinstall, but once I was trained up in a repair shop on how to remove malware thoroughly, formatting is only the very last option if all else fails.

I became pretty good at killing malware that more often than not, once I had done all my manual steps, scanners such as malwarebytes wouldn't find any leftovers for things like Antivirus 2010 fake AVs etc

I'm on both sides of this

1) If I was infected with malware (which I have never been) I would restore from a good image. after the malware was removed I would not use the installation in its current state. I would never again trust it.

2) None of us can be 100% sure we got everything it's impossible. Having said that when i'm done I am pretty confident the infection is gone. Rarely do I reformat and very rarely do I get any systems immediately back.

3) 3 hours can be about right. Hell a full scan with malwarebytes is usually 40 mins. I also do an external scan with kaspersky rescue from outside of windows. That can be another 40 mins or longer. I usually remove all temp and internet temp files (usually with ccleaner) to make the scans go as fast as possible.

4) If I had to format and reinstall I don't see my customers saying bad things about. It's not they would loose all their data.

3) 3 hours can be about right. Hell a full scan with malwarebytes is usually 40 mins. I also do an external scan with kaspersky rescue from outside of windows. That can be another 40 mins or longer. I usually remove all temp and internet temp files to make the scans go as fast as possible.

I always run CCleaner before Malwarebytes, works a treat to get all the junk cleared out before you scan for infection. Those two go together like peanut butter and jelly ;)

I always run CCleaner before Malwarebytes, works a treat to get all the junk cleared out before you scan for infection. Those two go together like peanut butter and jelly ;)

Correct, if you don't remove those internet temp files first 1 scan can EASILY! TAKE 2 hour - 3 hours. Yesterday I removed someones internet temp files, they had over 100,000 Internet temp files.

Correct, if you don't remove those internet temp files first 1 scan can EASILY! TAKE 2 hour - 3 hours. Yesterday I removed someones internet temp files, they had over 100,000 Internet temp files.

I once saw it remove over 15GB of temp files. I was floored...

I once saw it remove over 15GB of temp files. I was floored...

I sometimes use ccleaner, but sometimes I remove the internet temp files by hand and then rerun ccleaner for the rest of the files. ccleaner takes FOREVER to remove what takes far less time doing it by hand. As far as the reinstalls go, before I format I also backup their software registry Hive. I then run that through a product key finder and it extracts a lot of their product keys which allows me to reinstall some of their stuff for them, like office, norton and such.

I'm on both sides of this

1) If I was infected with malware (which I have never been) I would restore from a good image. after the malware was removed I would not use the installation in its current state. I would never again trust it.

2) None of us can be 100% sure we got everything it's impossible. Having said that when i'm done I am pretty confident the infection is gone. Rarely do I reformat and very rarely do I get any systems immediately back.

3) 3 hours can be about right. Hell a full scan with malwarebytes is usually 40 mins. I also do an external scan with kaspersky rescue from outside of windows. That can be another 40 mins or longer. I usually remove all temp and internet temp files (usually with ccleaner) to make the scans go as fast as possible.

4) If I had to format and reinstall I don't see my customers saying bad things about. It's not they would loose all their data.

Just to put something out there.

If you actually know what you are doing, then yes you can be 100% certain it is gone. If you send a customer a machine where you are only pretty certain it is gone, then that's really bad.

That is just inviting all sorts of headaches, especially if you didn't get it and they have their identity stolen.

If you cannot take the time to be certain you have eliminated the threat then send them to someone else or close shop.

Man, I really am getting more like Ramsay as time goes on...

Just to put something out there.

If you actually know what you are doing, then yes you can be 100% certain it is gone. If you send a customer a machine where you are only pretty certain it is gone, then that's really bad.

That is just inviting all sorts of headaches, especially if you didn't get it and they have their identity stolen.

If you cannot take the time to be certain you have eliminated the threat then send them to someone else or close shop.

Man, I really am getting more like Ramsay as time goes on...

If you want to go through every registry key and reverse engineer every file on the hard drive be my guest. What I'm saying is using the tools that I use, they tell me the system is clean. The issue they came in with is no longer there. I inspect the system and known malware locations, and running processes, host files, .... nobody can be 100% sure.

The last scan of many I do, is an external system scan with a kaspersky rescue disc, just to make sure I do the best I can to find infections that are trying to hide from the running OS.

I never had an issue with a customer being mad because of a format and reinstall. I have had issues where one of our other technicians tried to clean a system and return it to a customer only to have them come back again. I would sooner say in the position I am in I would get more angry people with the removal than I would the clean install. If the customer has data they must keep I boot them to something where they can back up the files to an external they provide. Once that is done then I blast away the system. Either way the risk of ID theft and such is too great to let the customer just leave with a simple removal.

If you want to go through every registry key and reverse engineer every file on the hard drive be my guest. What I'm saying is using the tools that I use, they tell me the system is clean. The issue they came in with is no longer there. I inspect the system and known malware locations, and running processes, host files, .... nobody can be 100% sure.

Yes exactly, if I tell my clients that do their banking and sensitive information that I could spend 3 or more hours fixing it, or spend the same amount of time re-installing. Most of them prefer re-installing.

It is much faster for me to install fresh and install their programs, than it is to try to mess with it. This is why I format, not because I am too stupid to clean it. But when people bank and have their tax stuff on there, you better be damn sure they prefer to wipe it.

I have my methods, you have yours. This post was not to get on me for my format choice. In my experience, it is much faster, and after I do a format I make a disk image and give it to them if they need it.

If you want to go through every registry key and reverse engineer every file on the hard drive be my guest. What I'm saying is using the tools that I use, they tell me the system is clean. The issue they came in with is no longer there. I inspect the system and known malware locations, and running processes, host files, .... nobody can be 100% sure.

The last scan of many I do, is an external system scan with a kaspersky rescue disc, just to make sure I do the best I can to find infections that are trying to hide from the running OS.

Doing that is not necessary to ensure the system is clean.

You can be certain and if you're not confident in your work being 100% accurate it has no business going back to a customer.

Going back to the Ramsay point. If you work in a restaurant are going to serve food you think isn't spoiled or food that you know isn't spoiled?

If it is the former the then I don't want you in my kitchen. :p

If you want to go through every registry key and reverse engineer every file on the hard drive be my guest. What I'm saying is using the tools that I use, they tell me the system is clean. The issue they came in with is no longer there. I inspect the system and known malware locations, and running processes, host files, .... no body can be 100% sure.

I so agree...one has to remember also you can not spent many hours or even days on a machine if you are in business , you are paid for volume of machines you put thru and your roi (return on investment) diminishes each hour you work on a machine. For the sake of discussion let's say you charge $200 (or something eqivilent in your currency) to fix it, 4 hours to reload it $50 an hour, 8 hours to find and kill malware $25 an hour and you have worked twice as hard

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • While LibreOffice is not pleased to see a new competitor, they are absolutely correct in stating that Euro-Office using a MS file standard as a default is not being truly "European." Using a MS standard just means Euro-Office is just a "bastardized MS Office Suite." (Wasn't a major purpose of Euro-Office was to get away from being captive and enslaved to MS's Office Suite??)
    • Microsoft continues its long-term policy of spying on their users--despite vehement denials. That feature will be disabled (or removed) either "elegantly" with MS providing a true way to disable it, or "quick and dirty" via a third-party who WILL come up with a way to disable it. Your choice MS...
    • Helium Browser 0.13.3.1 by Razvan Serea Helium is a private, fast, and honest Chromium-based web browser — built for people, with love. It offers the best privacy by default, unbiased ad-blocking, and a clean experience free from bloat and noise. Proudly based on Ungoogled-Chromium, Helium removes Google’s clutter while keeping a fast, efficient development pipeline. With thoughtful touches like native !bangs and split view, Helium is a people-first, fully open-source browser that puts control back in your hands. Privacy, security, and control come first. Ads, trackers, and third-party cookies are blocked automatically, HTTPS is enforced everywhere, and all Chromium extensions work seamlessly — while Google can’t track your activity. Helium’s 13,000+ offline-ready !bangs let you jump straight to sites or AI tools like ChatGPT instantly. Open-source, people-first, and unbiased, Helium delivers a browsing experience that’s fast, secure, and free from noise, ads, and compromises. Helium Browser key features: Performance Fast, efficient, and lightweight — built on Chromium’s optimized engine. Energy-saving and consistent — stays fast over time without slowing down. No bloat — stripped of unnecessary components for maximum speed. Minimalist interface — compact, clean, and distraction-free. Customizable toolbar — hide elements you don’t need. Smooth and stable — no flicker, lag, or animation glitches. Comfort-focused experience — intuitive and unobtrusive. Privacy & Security Best privacy by default — blocks ads, trackers, phishing, and third-party cookies. Unbiased ad-blocking — powered by community filters and uBlock Origin. No telemetry or analytics — zero background web requests on first launch. Strict HTTPS enforcement — warns for insecure sites. Passkeys supported — modern authentication made simple. No built-in password manager or cloud sync — your data stays yours. Extension Compatibility Full Chromium extension support — including MV2 extensions. Anonymized Chrome Web Store requests — Google can’t track extension installs. Extended MV2 support — maintained for as long as possible. Smart Features Native !bangs — browse faster using 13,000+ offline-ready shortcuts. AI integration — use !chatgpt and others directly from the address bar. Offline functionality — bangs work without an Internet connection. Philosophy People-first design — open source, transparent, and community-driven. No ads, no noise, no bias — privacy and honesty over profit. Helium Browser 0.13.3.1 changelog: f53b28d update: helium 0.13.3.1 (#292) b3cbb2ba revision: bump to 3 (#1925) bcacb8c7 chromium: update to 149.0.7827.114 (#1924) Download: Helium 64-bit | Portable 64-bit |~100.0 MB (Open Source) Download: Helium ARM64 | Portable ARM64 Links: Helium Home Page | macOS | Linux | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Microsoft Weekly: Xbox exclusives are back, big Windows app updates, and more by Taras Buria This week's news recap is here. Microsoft is returning to XBOX exclusives, Windows 11 gets new preview builds, the Low-latency Profile is here, big updates for inbox Windows apps, Patch Tuesday updates, and more. Quick links: Windows 10 and 11 Windows Insider Program Updates are available Reviews are in Gaming news Great deals to check Windows 11 and Windows 10 Here, we talk about everything happening around Microsoft's latest operating system in the Stable channel and preview builds: new features, removed features, controversies, bugs, interesting findings, and more. And, of course, you may find a word or two about older versions. The June 2026 Patch Tuesday updates are now publicly available. Windows 11 users can download KB5094126, which introduces plenty of new features and security updates, including the Low-latency Profile for better performance, shared Bluetooth audio support, and more. Windows 10 users with PCs enrolled in the Extended Security Update program can download KB5094127. In addition, Microsoft released new Defender updates for its operating systems. Speaking of Defender, Microsoft will now deliver EDR updates via Microsoft Update for faster security improvements independent of Patch Tuesday updates. Following the release of this month's Patch Tuesday updates, Microsoft also published new Windows 11 images available in the Media Creation Tool app. Now, you can create bootable USB media for clean Windows 11 installations with the latest releases. Some unfortunate stuff is going on with certain PCs from Dell and HP. Dell acknowledged that the SupportAssist bug causes black screens of death, while HP systems are suffering from Secure Boot update issues and boot loops. Both companies issued official advisories. Windows Insider Program Here is what Microsoft released for Windows Insiders this week: Builds Canary Channel Builds 29610.1000 and 28120.2302 This week's "Canary" builds only contain performance improvements and fixes, including the Low-latency mode, which is now available in the Stable channel for all Windows 11 24H2 and 25H2 users. Dev Channel Build 26300.8687 Microsoft brought some useful File Explorer changes with this build. You can now open folders in a new tab by middle-clicking them in the address bar. Beta Channel Build 26220.8680 and 28020.2298 Screen Tint, improved Windows Widgets, and other enhancements are included in this week's Beta releases. Release Preview Channel Builds 26200.8728 and 26100.8728 These builds also feature better widgets, new Windows Update controls, point-in-time restore, File Explorer improvements, and more. In addition to new Windows 11 preview builds, Microsoft announced that inbox Windows 11 apps now have their dedicated release notes in the official documentation. Also, Microsoft dropped massive feature updates for six apps, including Paint, Clock, Calculator, Camera, Media Player, Photos, and more. Updates are available This section covers software, firmware, and other notable updates (released and coming soon) delivering new features, security fixes, improvements, patches, and more from Microsoft and third parties. Google has some bad news for those still using MV2-based extensions in Chromium-based browsers, particularly Chrome. The company is now removing flags responsible for Manifest V2-based extensions (uBlock Origin is one of the most popular). However, some browsers resist this change, and Opera issued a statement that it will allow users to continue using MV2 extensions for as long as possible. While Microsoft is still not ready to share new details about MV2 extensions in Microsoft Edge, the company shared important details about the way it will be updating the browser going forward. Now, Microsoft wants to update Edge every two weeks across all platforms instead of the current four-week schedule (only the Extended Stable is exempt from this change). This week, Microsoft confirmed a useful new Teams feature that is coming to the messenger soon. It also detailed all the improvements that made the platform better for users in 2026. However, not all changes are great, as the company is moving ahead with the check-in feature, which many believe will lead to employee monitoring. PowerToys received a feature update this week. Version 0.100 arrived with a big rework for the Shortcut Guide, a new extension gallery for Command Palette, new Dock features, and plenty of other changes. Here are other updates and releases you may find interesting: Microsoft is bringing big performance improvements to OneDrive on Mac Popular Windows 11 file manager Files gets improved tags, layouts, and a new OneDrive icon New Outlook for Windows and Web is getting a simple but very useful email feature Microsoft had to shut down 70+ GitHub repos after getting hacked, bringing back some Microsoft AI boss no longer believes that AI will replace human workers Microsoft wants to end printer driver headaches with Windows Ready Print SQL Server Management Studio 22.7 brings "What's New" page, T-SQL formatting, and lots more Microsoft releases Visual Studio Code 1.124 with smarter autonomous AI agents Windows Server gets DNS over HTTPS (DoH) support Here are the latest drivers and firmware updates released this week: NVIDIA 610.52 Hotfix with multiple fixes for black screens of death, sleep issues, G-SYNC, and more. Reviews are in Here is the hardware and software we reviewed this week Steven Parker reviewed a rather unorthodox device here on Neowin this week. He took for a spin the DWARF mini, the world's smallest smart telescope for night and day sky captures. It tracks objects in the sky, has a sun filter, and has a low learning curve. There is also nice build quality and a quite affordable price. Pulasthi Ariyasinghe reviewed 007 First Light. The game turned out to be a satisfying spy adventure in the James Bond universe with great gunplay and combat, impressive crowds, over-the-top action sequences, and more. There are a few quirks here and there, but overall, the game scored high on our scale. On the gaming side Learn about upcoming game releases, Xbox rumors, new hardware, software updates, freebies, deals, discounts, and more. Microsoft held the latest XBOX Games Showcase this week. There, the company announced plenty of cool stuff, including a remake of Halo: Combat Evolved, a special 25th anniversary XBOX Series X with a classic translucent green design (coming in November 2026), details about Gears of War: E-Day, Spyro: A Realm Beyond after nearly 20 years since the last release, a new Hellblade game from Ninja Theory, a new expansion for DOOM: The Dark Ages, fresh details about State of Decay 3, and even a new entry in the Crazy Taxi series. More improtantly for XBOX fans, Microsoft announced the return of XBOX exclusives, with Gears of War: E-Day and Clockwork Revolution kicking it off. Microsoft also has some good news for Nintendo Switch 2 owners. Minecraft is coming natively to the second-gen Switch, offering better performance and new features, including the visual overhaul called "Vibrant Visuals." Playground Games revealed a 30-minute gameplay video of the upcoming Fable, showcasing combat, action, NPC simulation, relationships, and player choices. Additionally, the studio confirmed a bug with Forza Horizon 6 wiping saves for some gamers. It also had to shut down one of the game's online modes after users discovered an infinite money glitch. NVIDIA announced new games for the GeForce NOW streaming service and a big Summer sale that lets you get 12 months of GeForce NOW for $35 or $70 less, depending on the tier. Speaking of discounts, check out this week's Weekend PC Game Deals article, full of discounts and the latest freebies from the Epic Games Store. Great deals to check Every week, we cover many deals on different hardware and software. The following discounts are still available, so check them out. You might find something you want or need. GIGABYTE Radeon RX 9070 XT Gaming OC ICE 16G - $649.99 | 13% off 1TB Samsung T7 Portable SSD - $189.98 | 31% off AirPods Pro 3 - $179 | $50 off Edifier R1280Ts Powered Bookshelf Speakers - $129.99 | 24% off This link will take you to other issues of the Microsoft Weekly series. You can also support Neowin by registering for a free member account or subscribing for extra member benefits, along with an ad-free tier option.
    • Microsoft Flight Simulator's City Update 15 enhances Midwest cities by Pulasthi Ariyasinghe The third major city update of the year has landed for the original Microsoft Flight Simulator and the 2024 release. The latest drop is upgrading the visuals and regional accuracy of three metropolitan regions in the American states of Illinois, Minnesota, and Wisconsin. The 15th city update is adding eight new areas of interest that have been enhanced with high-fidelity TIN (triangulated irregular network) surface texturing in the mentioned regions. The free update highlights Chicago, Elgin, Cicero, and Arlington Heights in Illinois, as well as Minneapolis, St. Paul, Bloomington, Duluth, Brooklyn Park, Woodbury, Lakeville, Plymouth, and Blaine in Minnesota. In Wisconsin, the development has also upgraded the lands and buildings of Milwaukee, Madison, and Racine. The update lands just as one of the world's largest enthusiast flight simulation conventions, FlightSimExpo, kicks off in downtown St. Paul, Minnesota, on June 14. The Flight Sim development team's 40-minute keynote at the event can be watched here. At the same time, Microsoft is bringing the 6-seat, single-engine, multi-use light civil airplane Piper M600 into the game as a part of its Expert Series 2 program. This premium plane can be purchased from the in-game marketplace for $24.99. City Update 15: The United States Midwest is now available in Microsoft Flight Simulator, as well as the newer Microsoft Flight Simulator 2024, as an optional download. It can be accessed across Steam and the Microsoft Store for PC, Xbox Series X|S, and PlayStation 5, as well as Xbox and PC Game Pass subscriptions. Xbox One, mobile, and PC players can also jump into the new content using Xbox Cloud Gaming if they have a Game Pass Ultimate membership. The game must be updated to the latest version to download this free update from the in-game marketplace.
  • Recent Achievements

    • Week One Done
      ssd21345 earned a badge
      Week One Done
    • Contributor
      MarkHughes4096 went up a rank
      Contributor
    • Dedicated
      jordanspringer earned a badge
      Dedicated
    • Rookie
      Rimplesnort went up a rank
      Rookie
    • One Year In
      Markus94287 earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      507
    2. 2
      +Edouard
      179
    3. 3
      PsYcHoKiLLa
      140
    4. 4
      ATLien_0
      91
    5. 5
      Steven P.
      78
  • Tell a friend

    Love Neowin? Tell a friend!