Orca IT Solutions

Virus & Spyware Removal

Get it actually gone, not just quiet

Most infections we see were already cleaned once by a scanner that removed the payload and left the persistence behind. We look at scheduled tasks, registry run keys, services, WMI subscriptions and browser policy before we call anything fixed. And when a rebuild is genuinely the safer answer, we tell you that instead of billing hours.

🛡 Same-Day Response Honest Rebuild Advice💰 Account Recovery Help Never Outsourced

Overview

The payload is the easy part. Persistence is the job.

Antivirus finds the file. It frequently misses the four mechanisms that put the file back.

When a machine gets reinfected a day after being cleaned, it was almost never reinfected. Something on the box survived. We start every cleanup by enumerating persistence rather than by running another scanner. That means walking registry Run and RunOnce keys, scheduled tasks (especially ones with innocuous Microsoft-sounding names), Windows services with unsigned binaries, WMI event subscriptions, startup folders, Winlogon shell and userinit values, DLL search-order hijacks sitting next to legitimate executables, and browser policy keys such as Chrome's forced-extension list, which quietly reinstalls a hijacker every time the browser launches.

Not everything called a virus is one

A large share of what walks in the door is adware, a browser hijack or a scam, not malware in the classic sense. Search redirects and injected ads usually trace to a malicious extension, a modified browser shortcut with a URL appended to the target, a proxy or DNS override, or a policy key. Endless popups claiming your PC is infected, complete with a phone number and a siren noise, are a tech support scam page abusing full-screen mode. Nothing is infected until you call the number and let them in.

Browser notification spam deserves special mention because it fools experienced users. A site asks for permission to send notifications, someone clicks allow, and now fake virus warnings arrive on the desktop even when the browser is closed. There is no malware to remove. The fix is revoking the notification permission, and no scanner will ever find it.

When we clean, and when we rebuild

We clean when the infection is well understood and its scope is limited: adware, a hijacked browser, a bundled toolbar, a single known trojan caught early by EDR before it executed fully. We rebuild when we find anything that touched the boot path or the credential store, bootkits and UEFI-level persistence, rootkits hiding processes from the OS, or an infostealer that had free run of the machine.

That last category is the important one. Modern commodity malware is mostly credential theft. It scrapes saved browser passwords, session cookies, VPN profiles, saved RDP credentials, crypto wallets and Windows Credential Manager entries, then exfiltrates them within minutes of landing. Once that has happened the machine can be perfectly clean and you still have a problem, because the attacker has your logins and, worse, valid session tokens that can bypass MFA. Cleaning the machine does not un-steal them.

So our rule is blunt. If there is credible evidence of credential theft, or if the persistence mechanism is not fully explained, we recommend a flat rebuild from known-good media. Reimaging a workstation takes a few hours. Untangling a compromised Microsoft 365 tenant takes days.

Whichever path we take, the credential work is not optional. From a known-clean device, change passwords for email, banking, payroll, remote access and anything reused, do not do this from the infected machine. Then revoke active sessions in Microsoft 365 or Google Workspace so stolen cookies stop working, re-register MFA methods, and check the mailbox for the tell that gets missed constantly: inbox rules quietly forwarding or deleting messages, and unfamiliar OAuth app grants. Our free breach check and dark web scan are a useful sanity pass afterward.

Timing matters more than most people realize. The window between an infostealer landing and the stolen data being used is often hours, not days, and the machine frequently looks and behaves completely normally throughout. That is why we treat “it seems fine now” as an observation rather than an all-clear, and why the first instruction we give over the phone is to disconnect the machine from the network while leaving it powered on. Pulling the network cable stops exfiltration and lateral movement immediately; pulling the power destroys the volatile evidence that tells us what ran and what it reached.

For businesses there is a further step home users can skip: containment and scope. One infected endpoint on a domain is a question, not an answer. We isolate it, check whether the same credentials were used elsewhere, look for lateral movement, and review whether this was a precursor. Infostealer and loader infections are frequently the reconnaissance stage that precedes a ransomware event days or weeks later, which is why our ransomware protection work treats a single minor infection as a serious signal rather than a nuisance.

If we cannot explain how it got persistence, we do not tell you it is clean.Orca IT, Gilbert AZ

What We See Most

The infections actually walking through the door

Threat reports are abstract. This is what we handle week to week in the East Valley.

Infostealer

Credential-stealing trojans

Delivered by cracked software, fake installers and malicious ads. Scrapes saved passwords and session cookies within minutes, then usually deletes itself.

ClickFix

Fake CAPTCHA paste attacks

A page tells you to press Windows and R, then paste a verification command. It is a PowerShell downloader, and the user runs it with their own hands.

Hijack

Browser and search hijacks

Modified shortcuts, forced extensions, proxy or DNS overrides and policy keys that reinstate the hijacker on every launch.

Scam

Tech support popups

Full-screen scare pages with a support number. Nothing is infected yet. The damage begins when someone calls and grants remote access.

Adware

Bundled junk and toolbars

Shipped alongside free utilities and driver updaters. Not dramatic, but it degrades performance and often carries a data collection component.

Loader

Ransomware precursors

Quiet footholds whose job is to sell access on. Treating one of these as a minor cleanup is how businesses end up encrypted a month later.

Our Process

How a cleanup actually runs

01

Isolate

Off the network, still powered on where forensics matter. On a business network we also check whether anything else is showing the same indicators.

02

Investigate

We enumerate persistence, review recent process and network activity, and identify what the malware family is known to take before we touch anything.

03

Clean or rebuild

Targeted removal where the scope is clear and limited. A clean rebuild from trusted media where credentials or the boot path were in play.

04

Secure

Password resets from a clean device, session revocation, MFA re-registration, mailbox rule review, then EDR and patching so it does not happen again.

Suspect something is wrong right now?

Disconnect from the network before you do anything else, then call us.

Get a Free Assessment

Business vs Home

The same infection, two different jobs

A home PC needs the machine fixed. A business needs the blast radius understood.

01

Home and personal

Fast turnaround, data preserved, browsers reset, banking and email passwords changed, and a straight conversation about how it arrived so it does not repeat.

02

Business endpoints

Isolation first, then scope: which accounts logged into that machine, what network shares it touched, what credentials were cached on it.

03

Domain environments

Cached domain credentials mean one workstation can expose far more than itself. We check for lateral movement and force resets where warranted.

04

Microsoft 365 exposure

Stolen session cookies can bypass MFA outright. We revoke sessions, audit sign-in logs, inspect inbox rules and review OAuth grants.

05

Regulated data

For medical, dental, legal and financial clients an infection may carry notification obligations. We document what we found and when, so you can advise counsel properly.

06

Preventing the repeat

EDR with behavioral detection, removing local admin rights, application control and patching close the doors that let it in the first time.

Cleaned once already and it came back?

That is persistence, not reinfection. Bring it to us in Gilbert or let us look remotely.

Talk to Your Pod

Virus and spyware questions

My antivirus says it removed everything. Why is it still misbehaving?

Scanners are good at deleting known files and much weaker at reversing configuration. A removed payload can leave behind a scheduled task, a policy key, a modified browser shortcut or a proxy setting that keeps the symptoms alive. Those are found by inspection, not by scanning again.

Do I really need to wipe the machine?

Not always. Adware, hijacks and a single trojan caught early are usually cleanable. We recommend a rebuild when there is credible evidence of credential theft or the persistence mechanism cannot be fully explained, because at that point you can no longer trust the machine.

Will I lose my files?

No. Even on a rebuild we copy your data off first, scan it separately, and restore documents, photos and profile data to the fresh install. Programs get reinstalled properly rather than copied, which is also a good opportunity to leave the junk behind.

Which passwords should I change, and when?

Email first, then banking, payroll, remote access and anything you reused. Do it from a different, known-clean device, not the infected one. If the machine was compromised for any length of time, treat every password saved in the browser as public.

I have MFA. Am I safe?

MFA is essential but it is not absolute. Modern infostealers take session cookies, which represent an already-authenticated session and can be replayed without a second factor. That is why we revoke active sessions rather than only changing the password.

What about those full-screen your computer is infected pages?

Almost always a scam page, not an infection. Close the browser with Task Manager, do not call the number, and clear the site's notification permission. If someone did call and granted remote access, treat it as a full compromise and get the machine looked at properly.

Is a Mac immune to this?

No. Mac adware and browser hijacking are common, and macOS infostealers targeting keychain and browser data are an active and growing problem. The persistence lives in launch agents, configuration profiles and login items instead of the registry.

How fast can you look at it?

Usually the same business day. Remote cleanup can often start within the hour if the machine is still usable, and we cover clients in all 50 states. For East Valley businesses we can be onsite, and drop-off is available in Gilbert.

Talk to Your Pod

Infected machine? Disconnect it and call us.

Unplug the network cable, leave it powered on, and get in touch. We can usually look the same business day.

(602) 677-0779

Family owned in Gilbert, AZ since 2015 · onsite across the Phoenix metro · remote support nationwide · never outsourced

Same-day response No long contracts Flat, honest pricing Five-star service

Get your free IT consultation

A few details and your pod gets right back to you, usually the same business day.

Spam-protected with a quick CAPTCHA. Your message goes straight to our team in Gilbert. We only use your details to help with your request. Never sold, never shared.