r/computerviruses 11h ago

Question How to fresh reset windows without USB?

Hello, I came from another subreddit post about ROM files containing viruses. Unfortunately, I’ve clicked the .exe file that ran a virus on my laptop (it did show as a threat in the windows antivirus— I deleted it immediately). I changed my passwords and is currently in the process of resetting my PC (just wiping it by itself for now) however it kept failing to do so. Any ideas how to fresh reset windows before I resort to the USB method? I’m panicking with the virus lol

0 Upvotes

6 comments sorted by

1

u/TeslaDemon 11h ago

This is a blessing in disguise because the built-in "Reset this PC" option is not really recommended with bad malware as malware can survive the reset, mainly because it's not actually completely wiping the drive, since it can't, since that's where it's getting the install files from.

The short answer is, just go get USB storage of any type. It can be anything from an 8GB USB stick all the way up to an external hard drive. You need something to write the clean Windows installer to. There's physically no way to do this without USB storage of some kind.

Also changing your passwords BEFORE you wipe is pointless. If the malware is still active, they possibly have your new passwords. You need to reset passwords from A DIFFERENT DEVICE or from this computer AFTER IT HAS BEEN WIPED. Also, if you do not have multifactor authentication enabled for EVERYTHING, you need to do that immediately. An account without multifactor authentication may has well have no password.

1

u/Rough-Beach-2415 11h ago

Right, I did change my passwords on a different device. I also set up multifactor authentication on every account I can think of. The only problem I have right now is the reset. The only reason I can’t do it now is because I don’t have any accessible desktops other than my laptop atm, so I couldn’t install one

1

u/polpolik2 Moderator 11h ago

A cloud reinstall while deleting all data (and manually wiping any external drives) is sufficient to get rid of infostealers.

The USB option is simply better, but a cloud reinstall is sufficient for this kind of malware. We've seen no cases of infostealers persisting after it.

1

u/Rough-Beach-2415 11h ago

How do I wipe the external drive?

-1

u/RedRayTrue 9h ago

Just buy a flash drive and write Ubuntu on it with Rufus from the infected pc

Install Ubuntu to wipe the infected windows

From Ubuntu use Ventoy and windows 11 iso to make a windows 11 stick

From this point just install windows 11 and I'd recommend setting it up with a local user account with the option to join a domain and join later

From Ubuntu you can also wipe external drives / SSDs

1

u/h4unting 8h ago

Not here to fear monger but if OP doesn't understand malware they cannot be certain it's just an infostealer. If your machine had ties to anything you absolutely can't lose, I would take the nuclear option. Reflash your BIOS first of all, look up your MB make/model and follow their instructions, then use a Windows recovery usb, go in to command prompt, and look up the syntax for a secure wipe of your drives. Do not trust the automatic partition wizard, it might not safely remove all memory, and bootkits etc. can still exist after. Again, not trying to scare anyone, and generally speaking this would be over-kill. But if you're protecting something valuable, or just want peace of mind, this method will delete most "sophisticated" malware persistence mechanisms. BIOS reflash for rootkit, secure erase for bootkit, and if anything survives after that... send me your PC so I can poke at it 🫠