The infection is gone; the plumbing damage isn't
Antivirus products are built to neutralize code, not to undo configuration, and the gap between those two jobs is exactly where post-infection symptoms live. The classics: a proxy server or DNS override that survived the disinfection, a hosts file full of redirects, and a search engine that will not change back because the malware wrote browser policy keys into the registry. Add scheduled tasks and Run-key entries that re-download the payload, file associations quietly remapped to adware, and "clean" scans start to look like a technicality. That broken plumbing is also why symptoms persist for days after every engine reports green.
There is a second kind of damage that no scanner flags: data. Infostealers vacuum browser password stores, session cookies and crypto wallets long before the removal ever happens, which makes password rotation part of the repair, not an afterthought. Assume that every secret the browser had stored is in someone else's database now. Machines used for banking, work or shared family access deserve an honest evaluation of the full-reinstall route.
The repair order that works
Work from the network inward, because a still-hijacked connection re-infects faster than you can repair. Each step below takes minutes, and together they remove the overwhelming majority of persistence mechanisms that survive a standard disinfection. Do them in order, since several only make sense once the ones before are done. Set a restore point first, so you can undo your own repairs and not just the malware's.
- Network reset: proxy off, DNS back to automatic, then netsh winsock reset and ipconfig /flushdns
- Open C:\Windows\System32\drivers\etc\hosts and delete everything that is not a comment
- Delete rogue browser policies under HKLM\SOFTWARE\Policies (Chrome, Edge, Firefox keys)
- Audit Task Scheduler and the Run keys in HKCU/HKLM for entries that re-download payloads
- Remove unknown extensions and re-set the search engine in every browser and profile
- Rotate exposed passwords from a clean machine, starting with email and banking
Trust but verify: the two-week watch
After the repair, verify that Windows Update and the Microsoft Store actually work — broken updates are the most common lasting wound, and DISM /Online /Cleanup-Image /RestoreHealth followed by sfc /scannow heals most of them. Create a fresh restore point once the machine behaves, then give it two weeks of attention: sluggish boot, returning popups or a browser that reverts its own settings are all reasons to stop patching and reinstall instead. For machines that carried infostealers, seriously consider the reinstall-or-reimage route — it is the only repair that comes with a guarantee. A final pass over the dropper's bundled junk (toolbars, "driver updaters", fake cleaners) closes the case, and a leftover-mapping tool like Kleaner PRO finds those remains faster than a manual hunt through AppData.
Questions and Answers
Is my PC safe after malware removal?
Removal neutralizes the payload — it does not undo configuration damage or leaked data. Repair the proxy, policies, tasks and passwords before calling the machine safe.
Why does my browser still redirect after removing the virus?
Almost always a search engine locked via browser policy keys or a rogue extension. Delete the entries under HKLM\SOFTWARE\Policies and strip the unknown extensions.
Know what is included before you buy.
The one-time 30-minute trial covers core tools. PRO-labelled features stay locked until a paid license is activated.
Read next
Write to us: [email protected]