I downloaded a suspicious file yesterday and then noticed Chrome moving around by itself, as if someone else was controlling my computer. I disconnected the Ethernet cable and disabled Wi-Fi, and I'm changing my passwords from a separate device. What is the safest way to perform a clean Windows 11 installation, and will it remove the malware? I'm also unsure what files are safe to back up and whether my router needs to be replaced.
5 Answers
Disconnect any other storage drives during the installation if you can. Wiping only the Windows partition may leave malware or unwanted files on another drive, and reconnecting it immediately could reintroduce a problem. If you keep a data drive, scan it from the freshly installed system before opening anything and avoid restoring executable files or pirated software.
The safest approach is to create a Windows installer USB on a known-clean computer using Microsoft’s official Windows 11 download page. Do not create it from the compromised PC. Keep the affected computer offline, boot from the USB, choose Custom installation, and delete every partition on the system drive until it shows as unallocated space. Then install Windows there. This removes normal malware on that drive much more reliably than using Windows’ built-in Reset option. Be aware that it erases everything, so only back up files you are certain are safe; documents, photos, and other data can potentially contain malicious files.
After reinstalling, fully update Windows and your software before restoring files. From the clean device, change passwords for email, banking, shopping, and social accounts, revoke active sessions, check recovery email addresses and phone numbers, and enable app-based or hardware-key two-factor authentication where possible. Two-factor authentication can still be bypassed if a session token was stolen, so signing out every device is important.
You probably do not need to replace the router just because the PC was infected. Change the router’s administrator password, confirm its DNS and firmware settings have not been altered, install the latest firmware, and use a strong Wi-Fi password. Replacing it is reasonable if you find suspicious configuration changes or cannot verify that it is secure, but the Windows reinstall and account cleanup are the priorities.
Since the attacker viewed browser data and possibly searched for pictures of cards or other sensitive information, assume anything stored in the browser or account may have been exposed. Contact your bank or card provider if payment details were visible, monitor accounts, and remove saved passwords and payment information from the compromised account. Do all account security work from a clean device.

I’m not confident I can tell which files are safe, so I may wipe the whole drive and reinstall my games afterward.