Skip to content
SOS Informatique Computer repair in Lyon - Individuals and businesses

Virus removal and clean-up in Lyon

Before disinfecting, there has to be an infection in the first place. A good share of the “viruses” reported to us are not viruses at all.

That is the first service we provide on this subject: telling a real infection from a false alarm. Windows 11 is far better protected than its predecessors, and classic viruses have become rare on it. What remains common is adware, parasitic browser extensions, and above all web pages that imitate a security alert to get you to call a fake technical support line.

The signs of a real infection

  • Ads outside the browser, including with the browser closed. This is the most reliable sign: a web page cannot do that, only an installed program can.
  • A home page or search engine changed without your consent, and coming back after you fix it.
  • Unknown programs in the applications list, often installed on the same day, with names suggesting optimization, cleaning or video codecs.
  • A disabled antivirus that refuses to turn back on: a classic signature, the malicious program protecting itself.
  • A machine that has become slow for no reason, with the processor permanently busy on a process you do not recognize.
  • Messages sent to your contacts from your mailbox, without your knowledge.

On the other hand, a noisy page announcing “Your PC is infected, call this number” is not an infection. It is a scam, and the giveaway is infallible: no software vendor puts a phone number in an alert. See fake virus alert.

The different families

The word “virus” covers very different things, and the treatment changes with the family.

Adware is the most common: it injects ads, hijacks searches and sells on your browsing. Not very destructive, but it often serves as the way in for something worse.

Spyware quietly collects what you type, passwords included. It is the most insidious, because it gives no sign: the machine works normally.

A trojan presents itself as legitimate software and opens remote access. It is the one that then allows anything else to be installed.

Ransomware encrypts your files and demands payment. It calls for specific and urgent handling: see ransomware protection.

How we go about it

We first isolate the machine from the network, which stops data being sent out and further components being downloaded.

We then run an offline scan, executed before Windows starts. This is an important technical point: an active malicious program can hide from a normal scan, but not from one that runs while it has not yet loaded. Many clean-ups that “do not hold” come from this.

We then clean up by hand what no antivirus deals with: unwanted programs installed, browser extensions, a hijacked home page, notification permissions, shortcuts modified to reopen a page at launch, and above all the scheduled tasks that reinstall the pest a few days later. This is the longest step, and the one that makes the difference between a clean-up that holds and a relapse.

Finally we check the mailbox: automatic forwarding rules created without your knowledge, recovery addresses changed, authorized applications. That is how access is kept after a password change.

When we recommend a reinstall

Clean-up has its limits, and we would rather say so plainly. Three situations call for starting again on a clean system: when the antivirus refuses to turn back on, when the symptoms return after a full clean-up, and when the machine was used for banking during the infection. It takes longer, but it is the only real guarantee. Your documents are of course transferred first.

After the clean-up

Cleaning is not enough if your passwords have been out in the wild. We help you change the ones that matter, starting with your email - that is what lets every other account be reset - then your bank and shopping sites. And we turn on two-factor authentication wherever it is available, because that is the measure that protects best against a stolen password.

See also our page on antivirus installation and our article on securing your computer.

Remotely or at your place

A clean-up works very well by remote session as soon as the machine starts and reaches the internet: it is faster and cheaper than a visit. If it is too unstable, we come to you or work in the workshop.

What not to do in the meantime

Do not install a clean-up utility found at random through a search: that is the main way these programs spread, and the remedy becomes the problem. Above all, do not install one offered by a pop-up window or by the advertising itself. And never call the number shown in an alert, however serious it looks.

Frequently asked questions about this service

Does a paid antivirus protect better than the one built into Windows?

Not necessarily. Microsoft Defender, built in and up to date, scores comparably to commercial products for home use. What matters is having only one active.

How long does a clean-up take?

Allow one to two hours for a normal case, longer if the symptoms came back after an earlier clean-up. The manual part is the longest, and it is the one that prevents a relapse.

Are my files at risk?

A clean-up does not touch your documents. The only case where files are genuinely at stake is ransomware, which encrypts them - and there, only a backup or a known decryption tool will get them back.

How do I know the infection has really gone?

The signs of a return are always the same: ads outside the browser, a home page that changes on its own, an antivirus that turns itself off. A relapse a few days after a clean-up almost always comes from a scheduled task that was missed.

Can't find your question? It may be in our full FAQ.

Going further

Everything worth knowing before you hand over your equipment.

Unsure about the state of your machine?

Scan and clean-up, remotely or at your place across Lyon and the Rhône.

Contact Us