Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

A Windows 11 reinstall that appears not to solve a security problem does not, by itself, prove that malware survived. Account takeovers can continue after Windows is clean because passwords, recovery methods, browser sessions, or other devices remain compromised. A reinstall can also leave other drives untouched or bring the problem back through restored files and browser sync. Firmware-level attacks can survive an operating-system reinstall, but they are specialized and should not be the first assumption.

Protect your accounts from a known-clean device first. Then work out whether the evidence points to Windows, a browser, another device, or firmware—and only reinstall again if the way Windows was originally reinstalled did not fully wipe the system disk or there is evidence of an active Windows infection.

What the BleepingComputer case did—and did not—establish

The question comes from a real BleepingComputer malware-removal thread opened on August 13, 2024. The user reported repeated compromise of Windows, Google, Facebook, and other accounts despite using two-factor authentication, and was unsure about administrator access. The posted FRST logs described Windows 11 Pro 23H2, build 22631.4037, on an ASUS system. A volunteer requested more information, but the user did not continue; the thread was closed on August 21, 2024, without a diagnosis or removal instructions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The logs mentioned Microsoft Defender, ASUS utilities, browser extensions, stopped scans, a locked Defender-related service, and Code Integrity events involving hh.exe and ESET’s eamsi.dll. Those details are leads for an analyst, not proof of a rootkit or of malware surviving a clean install. A service name containing “Mp” is not automatically malicious; “locked service” alone does not establish a rootkit; and a Code Integrity warning is not synonymous with infection. ASUS, Microsoft, Intel, NVIDIA, ESET, and other installed software can generate complex service, driver, and security-event records. Stopped scans merit investigation, but do not identify who or what stopped them. The thread itself is available at BleepingComputer.

First identify what is actually compromised

“My computer is still compromised” can describe several different problems. Separating them prevents a risky or unnecessary reinstall.

  • Online account: unfamiliar sign-ins or devices, sent messages you did not write, password-reset alerts, changed recovery details, unexpected purchases, or new security settings.
  • Windows: a confirmed malware detection, an unknown startup item or service, security settings changed without permission, or a repeatable suspicious process. An unfamiliar name alone is not enough; legitimate drivers and utilities may be unfamiliar.
  • Browser: extensions you did not install, search or homepage changes, unwanted notification permissions, or suspicious account activity that returns when browser sync is enabled.
  • Firmware or boot chain: unexplained UEFI setting or boot-order changes, unknown boot entries, or evidence of a suspicious EFI boot file. These findings warrant expert interpretation.
  • Misread event or normal behavior: driver, security-product, DCOM, or Code Integrity messages can look alarming without demonstrating an infection.

Multiple unrelated accounts being abused is strong reason to secure those accounts. It is not, on its own, evidence that one Windows installation contains persistent malware.

Why a problem can continue after reinstalling Windows

Accounts and sessions outlive the PC installation

A reinstall does not change an email password, invalidate every logged-in session, remove an attacker’s recovery method, revoke an OAuth app, or undo an email-forwarding rule. Passwords or session tokens may have been stolen before Windows was reinstalled. An attacker may also have access through an app password, passkey, or recovery channel rather than repeatedly infecting the PC. Two-factor authentication is valuable, but account abuse despite 2FA does not prove that the second factor was technically bypassed: phishing, a stolen active session, compromised recovery information, or a malicious app grant are among the possibilities.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
  • 256 GB SSD of storage.
  • Multitasking is easy with 16GB of RAM
  • Equipped with a blazing fast Core i5 2.00 GHz processor.

Old files, drives, browser sync, and backups can bring trouble back

A reinstall of Windows does not necessarily touch other internal disks, an external backup, cloud-synchronized files, or a browser profile. Restoring a full system image or immediately syncing every browser setting can reintroduce an unsafe program, extension, or configuration. A data backup may be useful while an old installer, script, or executable in it is not safe to run.

Another device or the network may be involved

A phone, tablet, family computer, work device, or shared password manager can be the source of continuing credential theft. A compromised router or altered DNS settings can also create suspicious browsing behavior. A clean Windows install cannot clean another device or repair an account that has already been taken over.

Firmware persistence is possible, but not the default explanation

UEFI or other firmware-level malware can run before Windows and may survive reinstalling the operating system or replacing a drive. Microsoft describes such attacks as targeted and technically demanding; its guidance on the BlackLotus bootkit notes the need for prior privileged or physical access in the relevant attack chain. That makes firmware investigation appropriate when there is supporting evidence, not just because account alerts or an unusual Windows log appeared. See Microsoft’s overview of firmware attacks and BlackLotus investigation guidance.

Rank #3

Contain account risk before investigating the PC

  1. Stop using the suspected PC for sensitive activity. Do not use it for email, banking, password changes, or authentication while you are unsure it is safe.
  2. Use a known-clean phone or computer. Secure your primary email account first, because it may be used to reset other accounts. Change its password to a unique one.
  3. Review account access. Sign out unfamiliar sessions and devices; remove unknown connected apps, app passwords, passkeys, forwarding rules, and recovery addresses or phone numbers. Check that your own MFA methods remain enabled and that no attacker-controlled method has been added.
  4. Secure other important accounts. Change unique passwords for Microsoft, Google, Apple, financial, social-media, shopping, and password-manager accounts. Prioritize accounts that can reset other passwords. If a password manager may be exposed, secure that account and follow its provider’s recovery guidance.
  5. Contact financial providers if needed. Report unauthorized transactions or exposed payment details promptly.
  6. Preserve evidence. Record dates, alerts, unfamiliar sessions, changed settings, and relevant screenshots or email headers before deleting things or repeatedly reinstalling. If the case may involve work, regulated information, or legal reporting, contact the responsible IT or incident-response team before wiping evidence.

Do not change passwords on the suspected machine: if it is capturing credentials, the new passwords could be captured too. Do not restore a complete system image or browser profile until it has been reviewed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check Windows with supported tools

If Windows is still running and there is no immediate reason to disconnect it, update Microsoft Defender security intelligence and run a full scan. For suspected recurring malware, Microsoft’s consumer guidance recommends Microsoft Defender Offline, which restarts the PC and scans outside the normal Windows environment. Save open work first.

  1. Open Windows Security.
  2. Select Virus & threat protection, then Scan options.
  3. Choose Microsoft Defender Antivirus (offline scan), then Scan now.
  4. Allow the restart and scan to complete. After Windows returns, review the protection history and record detections rather than deleting unfamiliar system components by hand.

Microsoft’s malware detection and removal guidance covers the supported workflow. A second-opinion scanner may be useful, but obtain it only from its vendor’s official site. Avoid installing several real-time antivirus products at once: Microsoft notes that another real-time antimalware product can turn Defender off or create conflicts. See Microsoft’s antivirus-provider guidance.

Rank #4
15.6 Inch Laptop Computer, N4020, 4GB DDR4 RAM, 128GB eMMC,with Windows 11
  • EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
  • 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
  • RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
  • ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
  • LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.

Advanced users may use PowerShell diagnostics such as Get-MpComputerStatus, Get-MpThreatDetection, Get-CimInstance Win32_StartupCommand, Get-ScheduledTask, or Get-Service. These commands inventory status or configuration; their output does not diagnose malware by itself. Do not delete a service, task, registry entry, driver, or EFI file merely because its name is unfamiliar. Preserve logs and ask a qualified analyst to interpret ambiguous findings.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When another clean install is justified

Choose a controlled USB clean install if the earlier operation was an in-place upgrade, an OEM recovery that retained data, or a reset whose options are unclear; if the system disk was not fully wiped; or if there are credible Windows malware indicators. If several online accounts alone remain under attack, do account recovery first rather than assuming another reinstall will solve it.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft distinguishes a bootable installation-media clean install from Reset this PC. Reset offers options including Keep my files, Remove everything, Cloud download, and Local reinstall; local reinstall uses files already on the PC. For a suspected infection, do not assume every reset option provides the same assurance as deliberately booting official media and removing partitions on the intended system disk. See Microsoft’s Reset this PC guidance and installation-media instructions.

Best Value
Windows 11 Laptop with i3 Processor 15.6" Work Laptop for College Students
  • 【Efficient Performance】 Powered by Intel Core i3 processor (2 cores, 4 threads, up to 3.4GHz) with 12GB RAM and 256GB SSD. Handles multitasking, office software, online classes, and HD video streaming smoothly. Integrated Intel UHD Graphics 620
  • Backlit Keyboard & Complete Package】Comes with a cool backlit keyboard. Comes with awebcam, dual stereo speakers (8Ω/1.0W each), DC charger, and user manual – ready for late-night studying, online classes, video conferencing, and daily productivity
  • 【Vibrant Display】 15.6-inch Full HD (1920x1080) anti-glare screen with 16:9 aspect ratio delivers crisp images and vivid colors – perfect for studying, watching lectures, or entertainment. Thin-bezel design maximizes viewing area
  • 【Fast Connectivity & Expansion】 Equipped with WiFi 6 (802.11ax) and Bluetooth 5.2 for stable, high-speed wireless. Features 3 x USB 3.0, HDMI 2.1, Type-C (supports PD3.0 fast charging), and a TF card slot expandable up to 2TB – easily connect external monitors, mice, drives, or expand storage for all your files
  • 【Long Battery Life & Portable】 Built-in 11.55V 5000mAh/57.75Wh high-capacity battery delivers approximately 7 hours of mixed-use battery life – enough for a full day of classes and assignments. Lightweight at just 1.63kg (3.6 lbs) and 19.5mm thin, plus a compact packing size – easily slips into a backpack for campus, library, or coffee shop
  1. Prepare on a known-clean computer if possible. Download Windows 11 installation media from Microsoft and create a bootable USB. Keep the device’s Windows edition and activation details in mind.
  2. Protect data carefully. Back up only files you need. Disconnect unnecessary external drives before installation so you cannot erase the wrong disk. Treat old programs, scripts, and installers as untrusted until checked.
  3. Boot the affected PC from the USB. If you are unsure how to select boot media, use the computer manufacturer’s instructions.
  4. Identify the intended system disk by model and capacity. At Windows Setup’s disk-selection screen, delete the partitions on that disk until it shows unallocated space, then install Windows there. This destroys data on the selected disk; do not delete partitions on other disks by mistake.
  5. Build a minimal system first. Complete setup, run Windows Update, and install drivers only from Microsoft or the PC or motherboard manufacturer. Avoid optional utilities until Windows is current and stable.
  6. Verify security before restoring. Confirm Defender is active and updated. Check Secure Boot and TPM status where supported. Add essential applications gradually; install browser extensions one at a time and delay full browser sync, system images, and old software collections.

A wipe of the selected Windows disk removes ordinary Windows-resident malware on that installation. It does not clean other disks, cloud accounts, other devices, the router, or firmware. Microsoft’s clean-install guide warns that files, applications, settings, and manufacturer customizations on the selected installation are removed.

When to investigate UEFI or firmware

Escalate to the PC or motherboard manufacturer, or a qualified incident-response professional, if you find unknown boot entries, Secure Boot unexpectedly disabled, unexplained boot-order or firmware-setting changes, a suspicious EFI file, or a reproducible pre-boot symptom that returns after a verified USB wipe and minimal rebuild. Prior privileged attacker access or physical access raises concern. Repeated account abuse without these indicators is not enough to diagnose a bootkit.

Document firmware settings before changing them. If advised, update UEFI/BIOS using the exact manufacturer procedure, load defaults, then deliberately re-enable Secure Boot and TPM. Do not remove boot entries or EFI files casually; a mistake can prevent the PC from starting. Secure Boot reduces risk by checking trusted boot components, but it is not a guarantee against every boot-chain attack. Microsoft’s boot-process documentation explains its role and limitations. Replacing a motherboard or PC is not a routine consumer step; reserve it for evidence-based, high-risk cases with expert guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to decide what to do next

  • Multiple accounts affected, but no concrete Windows evidence: contain and recover accounts from a clean device; review sessions, recovery channels, apps, and other devices.
  • Windows security tools are disabled, malware is detected, or the previous reinstall did not wipe the system disk: preserve relevant evidence, then use official installation media for a controlled clean install.
  • The same symptom returns only after syncing a browser profile or restoring a backup: isolate that restoration source and rebuild without it; do not infer firmware compromise.
  • Unknown UEFI entries, unauthorized firmware changes, or repeatable pre-boot evidence: stop experimenting, document the state, and seek manufacturer or forensic assistance.

A practical recovery endpoint is reached when account sessions and recovery methods are yours, unauthorized forwarding rules and connected apps are removed, Defender is active and updated, scans complete without unresolved detections, Secure Boot is enabled where supported, and no unexplained startup items or tasks remain after expert review. Restore data and browser sync in stages; if suspicious behavior returns at a particular step, that gives you a more useful lead than another undirected reinstall.

Quick Recap

Bestseller No. 1
Bestseller No. 2
Dell Latitude 5420 14' FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
256 GB SSD of storage.; Multitasking is easy with 16GB of RAM; Equipped with a blazing fast Core i5 2.00 GHz processor.
$294.98
Bestseller No. 3
HP 14' HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
HP 14" HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
$249.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.