How to Remove a Rootkit That Survives a Windows Reinstall
A rootkit is malware designed to hide inside an operating system or beneath it. After a full Windows reinstall, most users in Sydney, Melbourne, or Brisbane expect a clean slate. That expectation can be wrong, because a persistent rootkit can survive a fresh install by living in the firmware, in the boot record, or in a hidden recovery partition, so wiping the C: drive alone is not always enough.
Australians rely on home PCs for tax time lodgement with the ATO, online banking through Commonwealth Bank or ANZ, and everyday small-business admin. A rootkit that quietly logs keystrokes can drain a Westpac account or quietly inject fraudulent content into Word and Excel files before they are emailed. Recognising the warning signs early, including fake errors inserted into Office documents, can save months of grief.
The Australian Cyber Security Centre regularly warns about bootkits bundled with pirated downloads and fake Office activations. Under the Notifiable Data Breaches scheme, organisations must report serious intrusions. While individuals are not bound by that scheme, the same habits that keep a small business compliant keep a family PC safe too. Following guidance from Scamwatch and the eSafety Commissioner adds a useful extra layer.
This guide walks through the steps a careful user can take at home. It assumes you have a second working computer, a USB stick, and patience. None of the tools referenced here are exotic; most are free. Where the situation feels overwhelming, a local IT shop in a suburb like Parramatta, Geelong, or the Gold Coast can provide hands-on help.
Why a standard reinstall often falls short
A typical reinstall through "Reset this PC" or a recovery partition keeps user files while replacing system files. The hidden areas it does not touch are exactly where a rootkit wants to live: the Master Boot Record on an MBR disk, the EFI System Partition, the System Reserved Partition, and the UEFI firmware chip on the motherboard. Once parked there, the malicious code loads before Windows itself, so even a brand new operating system becomes its puppet.
Telstra and Optus customers occasionally blame the home line for sluggish speeds. The cause is often on the PC, not the connection. Treat any reinstall-only fix with suspicion. Look for repeated crashes, unexplained outbound connections in Task Manager, or files that reappear after deletion. These are not ghosts; they are symptoms of a deeper infection.
Boot from clean media and stay offline
The first practical move is to take the infected machine fully offline. Unplug the Ethernet cable, disable Wi-Fi in the firmware, or physically remove the wireless card on a desktop. A connected machine can phone home during cleanup, undoing the work ahead.
Download the official Windows Media Creation Tool or a Linux live ISO such as Ubuntu onto a different, trusted computer. Write it to a USB drive using Rufus or Etcher. Plug this USB into the infected machine, enter the boot selector (often F12, F2, or Del on Australian retail models bought from JB Hi-Fi or MSY), and boot from the stick. Choose "Repair your computer", open Command Prompt, and run bootrec /fixmbr, bootrec /fixboot, and bcdedit to inspect and repair the boot chain.
Scan with a dedicated offline rootkit tool
Anti-virus products running inside Windows have a blind spot: the very operating system they live in may be hiding the threat. Specialised scanners boot from their own USB and look at the disk outside the running OS. Kaspersky Rescue Disk, Bitdefender Rescue CD, and ESET SysRescue are well regarded and freely downloadable.
Burn the rescue ISO to a separate USB, boot from it, update its definitions through a temporary safe connection, then run a full scan. Some rootkits resist even this, persisting in firmware. If your scanner flags the firmware or cannot touch a particular sector, move to the next section rather than assuming the disk is clean. For residual browser-based threats after the rebuild, follow the dedicated adware cleanup steps to strip leftover hijackers.
Wipe hidden partitions and rebuild the boot chain
After rescanning, boot again from the Windows installer USB and choose "Custom" install. Delete every partition you see on the system disk, including the small 100 MB System Reserved and 500 MB Recovery partitions. Select the unallocated space and let Windows create fresh partitions. This is the only reliable way to remove an MBR implant or a tampered EFI partition.
On a laptop bought from a major Australian retailer, there is usually a separate OEM recovery partition from HP, Lenovo, ASUS, or Acer. Decide carefully whether you want it. If the rootkit entered through a tampered factory image, skip restoring it and rely on official media only. For advanced users comfortable in a shell, diskpart clean followed by convert gpt and a fresh bcdboot makes the new boot chain fully verifiable.
Reflash firmware and audit connected devices
A truly stubborn implant lives in the UEFI or BIOS flash chip. Many modern motherboards from ASUS, Gigabyte, and MSI include a "BIOS Flashback" USB port that lets you reflash from a FAT32-formatted drive without even booting. Download the exact firmware file for your model from the vendor's official Australian support page, verify the SHA256 hash, then follow the vendor's recovery procedure.
While the case is open, inspect every peripheral. Cheap USB drives from online marketplaces, especially those shipped from grey-import sellers via eBay AU or AliExpress, have been caught delivering U3 executables or HID payloads. Throw away unknown sticks. Unplug any USB hubs you do not recognise. If your machine has a built-in webcam you never use, cover it; an Australian Cyber Security Centre advisory last year noted webcam hijack attempts rising in Adelaide and Perth.
Restore data only from verified clean backups
Once the new Windows is in place and updated, resist the urge to roll back everything from your old backup. Files carried across may include the original rootkit installer tucked inside a .zip, a .lnk shortcut, or a macro-laden Office document. Scan every backup archive before extracting it. If you use Backblaze, iDrive, or a local NAS, sample a few files before restoring en masse.
For critical documents, restore them one folder at a time and run an offline scanner between folders. If you cannot confirm a backup is clean, accept that some files are lost and rebuild from sources like your bank's online statements, the ATO's myTax records, and email archives. Losing a few photos is painful; losing access to your Macquarie trading account is worse.
Harden the rebuild and keep it that way
Turn on Secure Boot and TPM 2.0 in the firmware if the hardware supports it. Enable BitLocker or a Linux equivalent with a strong recovery key stored somewhere other than the machine. Update Windows fully, including optional cumulative updates, then leave them automatic. Install a reputable anti-virus and a second-opinion scanner such as Malwarebytes Free.
Change every password from a different trusted device and turn on multi-factor authentication wherever it is offered. Scamwatch, run by the ACCC, sees credential theft as a leading driver of loss reports across Sydney and Brisbane postcodes. Email your contacts a short warning so they do not click any strange links they may have received from your address during the infection window. Going forward, treat any unexpected Office document with care, since malware that injects fake errors into Word and Excel files is increasingly common, and a careful eye beats any scanner.