The fastest way to remove a virus depends on whether your computer still starts

If your computer boots normally, run a full scan with your antivirus software—the one already installed on your machine, or a free scanner like Malwarebytes or Windows Defender (built into Windows). Let the scan finish completely, then quarantine or delete anything it finds. Most viruses caught early this way are gone after one scan and a restart.

If your computer won't start, boots very slowly, or shows constant pop-ups you cannot close, the infection is deeper. You will need to start the computer in Safe Mode (a stripped-down version that loads only essential files) or use a bootable antivirus tool on a USB drive from another computer. Both methods let you scan and remove the virus before Windows fully loads.

If you cannot do either of those things yourself, or if the virus returns after removal, take the computer to a local repair shop. They have tools and experience for stubborn infections and can also check whether the virus stole passwords or banking information.

Key Takeaways

  • Start with a full antivirus scan using Windows Defender or Malwarebytes if your computer boots normally.
  • Restart your computer after the scan completes to finish removing the virus.
  • If your computer won't start or is extremely slow, boot into Safe Mode and run the scan from there.
  • If the virus returns or you cannot remove it yourself, a local repair technician can use specialized tools to clean the infection.
  • After removal, change your passwords for email, banking, and other sensitive accounts from a different device.

How to scan your computer when it starts normally

Open Windows Defender (on Windows) or the antivirus software you have installed. Look for a button labeled "Scan" or "Full Scan"—not a quick scan, which only checks common locations. A full scan examines every file on your hard drive and takes 30 minutes to several hours depending on how much data you have.

Let the scan run completely without interrupting it. When it finishes, it will show you a list of threats found. Select all of them and choose "Quarantine" or "Remove." Quarantine moves the files to an isolated folder where they cannot run; remove deletes them. Either way, the virus is disabled.

Restart your computer when the scan is done. Some viruses hide in memory (the computer's active workspace) and only fully disappear after a restart.

Starting your computer in Safe Mode if it will not boot normally

Safe Mode loads Windows with only the bare minimum—no third-party programs, no network drivers, no fancy graphics. Viruses often cannot run in Safe Mode, which makes it the right place to scan if your computer is frozen, extremely slow, or stuck in a restart loop.

On Windows 10 or 11, restart your computer and hold down the Shift key while clicking the restart button (do this from the login screen if you can reach it). The computer will show a menu; select "Troubleshoot," then "Advanced Options," then "Startup Settings." Restart again and choose "Safe Mode" or "Safe Mode with Networking" (use Networking if you need internet to read an antivirus tool).

On older Windows versions, restart and press F8 repeatedly as the computer starts, before the Windows logo appears. You will see a menu with Safe Mode options.

Once in Safe Mode, open your antivirus software and run a full scan. The process is the same as a normal scan, but the virus has fewer places to hide.

Using a bootable antivirus tool when the computer will not start at all

If your computer will not reach the login screen or Safe Mode, you need a bootable antivirus—a small program that runs from a USB drive before Windows even loads. The most common free option is Kaspersky Rescue Disk, which you read and write to a USB drive from another computer.

Go to another working computer and read Kaspersky Rescue Disk from Kaspersky's website. You will need a USB drive with at least 1 GB of space. Use a tool like Rufus (free, Windows) or Etcher (free, Mac or Linux) to write the Kaspersky image to the USB drive. This erases everything on the drive, so use one you do not need.

Insert the USB drive into the infected computer, restart it, and press the key that opens the boot menu—usually F12, F2, Esc, or Del, depending on the computer brand. Select the USB drive from the menu. Kaspersky will load and offer to scan your hard drive. Let it scan and remove everything it finds, then restart the computer normally.

What to do if the virus comes back after removal

If the same virus or new ones appear within days of removal, the infection is either very stubborn or your computer has been compromised in a way that antivirus tools alone cannot fix. This sometimes happens with ransomware, rootkits, or spyware that modifies Windows system files.

At this point, take the computer to a local repair shop. They can use specialized forensic tools, check whether the virus is still active, and determine whether a clean Windows reinstall is necessary. A reinstall erases everything and puts a fresh copy of Windows on the drive—it always removes the virus, but you lose all your files unless they are backed up first.

Before you take it in, ask the shop whether they can recover your files. Some shops can extract your documents, photos, and other data to an external drive before reinstalling Windows.

Protecting your accounts after virus removal

A virus that was on your computer long enough may have recorded your passwords, banking login, or credit card information. You cannot know for certain what it captured, so treat your accounts as if they were compromised.

From a different device (a phone, tablet, or another computer), change the passwords for your email, bank, PayPal, social media, and any other account with sensitive information. Use a password manager like Bitwarden or 1Password to create new, unique passwords for each account—do not reuse passwords across sites.

Check your bank and credit card statements for unauthorized charges. If you find any, contact your bank when ready. Consider placing a fraud alert with the three credit bureaus (Equifax, Experian, TransUnion) so that anyone trying to open accounts in your name will be flagged.

How to avoid viruses in the future

Most viruses arrive through email attachments, fake read links, or compromised websites. Do not open attachments from people you do not know, and do not click links in unexpected emails—instead, go directly to the website by typing the address yourself.

Keep Windows and your antivirus software updated. Updates patch security holes that viruses use to get in. Turn on automatic updates in Windows settings so you do not have to remember.

Use a password manager and enable two-factor authentication on important accounts like email and banking. Two-factor authentication means a hacker needs both your password and a code from your phone to log in, which stops them even if they have your password.

Frequently Asked Questions

How do I know if my computer actually has a virus?

Common signs are unexpected pop-ups, programs running slowly, the hard drive light constantly on, programs crashing, or your antivirus software showing alerts. Run a full scan to know for certain. If the scan finds nothing and the computer runs normally, you probably do not have a virus.

Is it safe to use my computer while the antivirus scan is running?

Yes, but the scan will run slower if you are using the computer at the same time. It is better to start the scan and leave the computer alone for a few hours so it finishes faster. Do not restart the computer or unplug it while the scan is in progress.

Will removing a virus delete my files?

Antivirus removal usually does not touch your documents, photos, or other personal files—it only removes the virus itself. However, if the virus encrypted your files (ransomware), removal will not decrypt them. A repair shop may be able to recover encrypted files, but there is no may provide.

What is the difference between a virus and malware?

A virus is one type of malware. Malware is the umbrella term for any malicious software—viruses, spyware, ransomware, and others. Antivirus software removes all types of malware, despite the name. The removal process is the same regardless of which type infected your computer.

Can I remove a virus without restarting my computer?

The antivirus scan will remove the virus files, but a restart is necessary to clear the virus from your computer's memory and make sure it does not reload when you restart later. Always restart after a scan finishes.