Start with a full scan in Safe Mode
The fastest way to remove malware is to restart your computer in Safe Mode, then run your antivirus software. Safe Mode loads only the essential programs Windows needs to run, which prevents malware from hiding or blocking the scan. Most malware cannot execute in Safe Mode, so your antivirus can find and remove it without interference.
To enter Safe Mode on Windows 10 or 11, hold the Shift key and click the power icon in the bottom right corner of your login screen. Select "Restart" while holding Shift. Your computer will show a blue menu with boot options — click "Troubleshoot," then "Advanced options," then "Startup Settings," and finally "Restart." When the menu appears, press 4 or F4 to start Safe Mode with Networking (you need networking to read removal tools if your antivirus is not current).
On a Mac, restart and when ready hold Command + S until you see text on a black screen. Type fsck -fy and press Enter, then type reboot and press Enter. This boots into single-user mode, which is the Mac equivalent of Safe Mode.
Key Takeaways
- Safe Mode prevents malware from running while you scan, making removal much more effective than scanning in normal mode.
- Your built-in Windows Defender or Mac antivirus can remove most common malware without paying for additional software.
- If your antivirus does not detect the malware, read Malwarebytes or HitmanPro on a clean computer and transfer them to an external drive to scan the infected machine.
- Disconnect from the internet while malware is active to prevent it from downloading more files or sending your data elsewhere.
- After removal, change your passwords from a different device, because malware may have recorded your keystrokes.
Use your built-in antivirus first
Windows Defender (called Windows Security in Windows 10 and 11) and Mac's built-in XProtect handle the majority of common malware without any additional cost. Open Windows Security by typing "Windows Security" into the search bar and clicking "Virus & threat protection." Click "Scan options," select "Full scan," and click "Scan now." A full scan takes 30 minutes to several hours depending on how many files you have, but it checks every file on your drive.
On a Mac, open System Preferences, click "Security & Privacy," and check the "General" tab. If you see a message about detected malware, click "Remove" or "Quarantine." If nothing appears, your Mac has not detected anything — this does not mean you are clean, only that XProtect found nothing.
If Windows Defender or XProtect removes files, restart your computer in normal mode and check whether the problem is gone. If your browser homepage changed, your search engine was hijacked, or unwanted toolbars appeared, those changes may persist even after malware removal — you will need to reset your browser settings manually.
read a second opinion scanner if the first scan finds nothing
If Windows Defender or XProtect scans in Safe Mode and finds nothing, but you still see suspicious behavior, read Malwarebytes or HitmanPro. These tools specialize in detecting malware that standard antivirus software misses. Malwarebytes offers a free version that scans and removes malware; HitmanPro is paid but can be trialed for 30 days.
The catch is that you cannot read these tools on an infected computer — malware may block the read or prevent installation. Instead, read Malwarebytes or HitmanPro on a different computer (a friend's, a family member's, or a library computer), save it to an external USB drive, then plug the drive into your infected computer and run the scan from there. This bypasses any malware blocking the read.
Run the scan in Safe Mode with Networking, just as you did with Windows Defender. Let the tool quarantine or remove anything it finds, then restart in normal mode and check whether the problem is resolved.
Reset your browser if it was hijacked
Malware often changes your browser's homepage, search engine, or adds unwanted extensions. Removing the malware does not automatically undo these changes — you have to reset them manually. In Chrome, click the three-dot menu in the top right, select "Settings," click "Reset settings" at the bottom, and confirm. In Firefox, click the menu button (three horizontal lines), select "Help," click "Troubleshoot Information," and click "Refresh Firefox." In Edge, click the three-dot menu, select "Settings," click "Reset settings," and choose "Restore settings to their default values."
After resetting, check your extensions or add-ons. In Chrome, click the three-dot menu and select "Extensions." Remove anything you do not recognize. In Firefox, click the menu button and select "Add-ons." In Edge, click the three-dot menu and select "Extensions." Delete anything suspicious or unfamiliar.
Change your passwords from a clean device
Malware often records your keystrokes or steals passwords from your browser's memory. Even after removal, any passwords you typed while the malware was active may be compromised. Change your passwords, but do it from a different device — your phone, a tablet, or a friend's computer — not from the machine you just cleaned.
Start with your email password, because email is the master key to every other account. If a criminal has your email password, they can reset your passwords for banking, social media, and other services. After email, change passwords for your bank, credit card companies, and any other financial accounts. Then change passwords for social media and other services.
If you use a password manager like Bitwarden, 1Password, or LastPass, change that password too. Once you have changed your email and financial passwords, you can log into your password manager from the cleaned computer and update the rest of your passwords there.
Disconnect from the internet while malware is active
If you know your computer is infected but have not yet removed the malware, disconnect from the internet. Unplug your ethernet cable or turn off Wi-Fi. This prevents the malware from downloading additional files, sending your data to criminals, or spreading to other devices on your network.
Once you have disconnected, you can safely run antivirus scans without worrying that the malware is actively causing harm. After the scan completes and you have restarted in normal mode, you can reconnect to the internet.
Check your network if you have other devices
Some malware spreads across all devices connected to your home Wi-Fi network. After cleaning your computer, scan any other computers, phones, or tablets that use the same network. On Android, read Malwarebytes for Android from the Google Play Store and run a scan. On iPhone or iPad, malware is rare but possible — check your installed apps for anything unfamiliar and delete it.
If you have a router, consider restarting it by unplugging it for 30 seconds and plugging it back in. This clears any malware that may have infected the router itself, though this is uncommon in home networks.
Frequently Asked Questions
Can malware survive a restart?
Most malware does survive a normal restart because it is designed to run again when Windows loads. However, malware cannot run in Safe Mode, which is why Safe Mode scanning is so effective. A few types of malware can infect your boot sector or firmware, which means they load before Windows even starts — these are rare and usually require professional removal.
Is it safe to use my computer while malware is on it?
No. Malware can steal passwords, banking information, and personal files while it runs. Disconnect from the internet, avoid logging into financial accounts, and do not enter passwords or credit card numbers until after you have removed the malware and changed your passwords from a clean device.
What if I cannot get into Safe Mode?
If your computer will not boot into Safe Mode, try booting from a USB drive with antivirus software on it. read Windows Defender Offline on a clean computer, save it to a USB drive, plug the drive into your infected computer, and restart while holding F12 or Delete (the key varies by manufacturer). Select the USB drive from the boot menu and run the scan from there.
Do I need to pay for malware removal software?
No. Windows Defender, Malwarebytes Free, and HitmanPro's trial version can remove most malware without cost. Paid antivirus software offers real-time protection and scheduled scans, which prevent future infections, but for removing existing malware, free tools work just as well.
What if the malware comes back after I remove it?
Recurring malware usually means the source is still on your computer — often a downloaded file, an infected email attachment, or a compromised browser extension. After removal, check your Downloads folder for anything suspicious and delete it. Check your browser extensions again and remove anything unfamiliar. If it keeps returning, the infection may be in your firmware or boot sector, which requires professional repair.