A Compromised Computer Cannot Be Cleaned. It Must Be Rebuilt

michael-geiger-JJPqavJBy_k-unsplash

If a computer is INFECTED, it is COMPROMISED and CANNOT be trusted, even if infections are removed. It's impossible to know the damage that has been done. I don't care what the marketers, antivirus, anti-spyware companies, or local computer shops tell you.

  • Once it is determined that a system is infected, IF it's not backed up to a current or recent state, cleaning it up so it's usable enough to do that should be the ONLY goal.
  • Then, the system NEEDS to be unplugged from the internet, rebuilt, and restored from backups.
  • Don't believe BS that the system can be cleaned and left in production.

Even antivirus software can only be trusted to PREVENT infections.

Once infected, it's COMPROMISED and CANNOT be trusted.

A System Cleanup should only have to tidy things up.

To be clear, I mention spyware removal software in some blog posts on this website. This software should only be used to make the system usable long enough to grab files off it when a current backup is not available before a clean install of Windows.

Thank you so much for reading this blog post! You can keep up to date with my latest posts right here on KevinTheTechGuy.ca, or via the RSS feed. You can also check out my FREE newsletter. For bonus content and other perks, please consider supporting me on Patreon or Buy Me a Coffee! Your support makes my work possible.