I wasn't paying close attention while browsing and downloaded and opened a program I didn't intend to install. Windows Defender detected and quarantined threats identified as "Lazy.PGLI!MTB" and "Trojan:BAT/Runner!MTB," but the infection seems to persist. I'm seeing a process with a green Windows-style icon and Chinese text, startup messages referring to a location under ProgramData, and possible malware-related items such as "Listener_net35_rc," "info_injecter," and a Task Scheduler entry named "ithost_v2_0" that runs when I log in. I tried stopping the process, deleting related files, and removing the scheduled task, but everything returned after restarting. What is the safest way to handle this, and how can I protect my accounts and financial information?
2 Answers
Treat the computer as compromised and take it offline immediately. The safest approach is a clean Windows installation, not just deleting visible processes or using the built-in reset option. From a separate, trusted computer, create Windows installation media on a USB drive, boot the affected PC from it, delete all partitions on the system drive, and reinstall Windows. This will erase everything, so copy only essential personal files if absolutely necessary—and avoid transferring executable files or programs.
Avoid relying on the local recovery image or simply deleting the scheduled task, since malware can leave behind startup mechanisms or tamper with recovery files. Create the installer using a known-clean computer and use the boot menu or BIOS to start from the USB. After reinstalling, fully update Windows and your security software before restoring files. If you have irreplaceable documents, copy only ordinary data such as photos or PDFs and scan them carefully; don’t restore unknown installers, scripts, or cracked software.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures