The fastest way to check and remove a virus

Start by running a full system scan with Windows Defender (built into Windows) or a free antivirus tool like Malwarebytes. Restart your computer in Safe Mode with Networking first — this loads only essential programs and makes it harder for malware to hide or interfere with the scan. Once in Safe Mode, open your antivirus program, select "Full Scan" or "Scan All Files", and let it run to completion. This usually takes 30 minutes to two hours depending on your hard drive size.

When the scan finishes, the program will show you what it found. Most antivirus tools automatically quarantine (isolate) threats, which means they move suspicious files to a locked folder where they cannot run. Review the list of detected items — the program will recommend whether to remove, quarantine, or ignore each one. Click the button to remove or quarantine everything it flagged, then restart your computer normally.

If the scan finds nothing but your computer still behaves oddly (slow, freezing, unexpected pop-ups), run a second scan with a different tool. Sometimes one program catches what another misses. Malwarebytes and Windows Defender together cover most common threats.

Key Takeaways

  • Restart in Safe Mode with Networking before scanning so malware cannot interfere with the scan process.
  • Run a full system scan with Windows Defender or Malwarebytes and let it complete without interruption.
  • Review the scan results and remove or quarantine all flagged items, then restart normally.
  • If one scan finds nothing, run a second scan with a different antivirus tool to catch threats the first one missed.
  • After removal, change passwords for email and banking accounts from a different device in case malware logged your keystrokes.

How to restart your computer in Safe Mode

Safe Mode loads Windows with only the drivers and services it needs to run — no third-party programs, no startup items, and no network except what you explicitly enable. Malware often cannot function in Safe Mode, and it cannot block or interfere with antivirus scans the way it can in normal mode.

On Windows 10 or 11, hold down the Shift key, click the power button in the bottom right corner, and select "Restart". Your computer will show a blue screen with options. Click "Troubleshoot", then "Advanced Options", then "Startup Settings". Click "Restart" and your computer will reboot. When it comes back up, you will see a menu with numbered options. Press 6 for "Safe Mode with Networking" — the networking part lets you read antivirus tools if you need them.

On older Windows versions, restart and repeatedly press F8 or F12 (depending on your computer brand) before the Windows logo appears. You will see the same startup menu. Select Safe Mode with Networking and press Enter.

Your desktop will look different in Safe Mode — fewer icons, no taskbar items running in the background. This is normal. When you are done scanning, restart normally and your computer will return to its usual state.

Running a full antivirus scan step by step

Windows Defender is already on your computer. Click the Windows icon (bottom left), type "Windows Defender", and open "Windows Security". Click "Virus & threat protection" on the left side. Under "Current threats", click "Scan options". Select "Full scan" and click "Scan now". The scan will run in the background — you can use your computer while it works, though it will be slower. When finished, it shows a summary of what it found.

Malwarebytes is free to read. Go to malwarebytes.com, click "Free read", and run the installer. Open the program, click "Scan" on the left, then "Scan Now". Malwarebytes runs a quick scan by default, which takes 5 to 10 minutes. For a deeper check, click "Settings" (gear icon), then "Scan" on the left, and change "Scan Type" to "Full Scan". Run the scan again. When it finishes, review the detections and click "Quarantine Selected" to isolate all flagged items.

After either scan completes, restart your computer. The antivirus program may ask permission to remove items on restart — allow it. Once your computer restarts, the threats are gone.

What to do if your computer will not start normally

If your computer is so infected that it will not boot into Windows, or if it boots but when ready crashes or freezes, you may need to use a bootable antivirus tool. This is a program you run from a USB drive before Windows even loads.

From another computer, read Kaspersky Rescue Disk (free at kaspersky.com) or Avast Bootable Rescue Disk (free at avast.com). Follow the instructions to write the downloaded file to a USB drive using a tool like Rufus (free at rufus.ie). Insert the USB drive into your infected computer, restart it, and press F12, F2, or Delete (depending on your computer brand) to enter the boot menu. Select the USB drive and let the antivirus tool scan your hard drive before Windows loads. This bypasses any malware that blocks normal antivirus tools.

Bootable scans take longer — often one to three hours — because they scan every file on your drive. When finished, remove the USB drive and restart normally. Your computer should boot without the malware interference.

Protecting your passwords and accounts after removal

If malware was on your computer for any length of time, it may have recorded your keystrokes or stolen passwords. Change your passwords for email, banking, and any account with sensitive information — but do it from a different device (phone, tablet, or another computer) to be safe.

Start with your email password, because email is the master key to resetting passwords for other accounts. Then change passwords for your bank, credit card company, and any online shopping or payment accounts. For accounts you use less often, change the password within the next week.

If you see unauthorized charges on a credit card or bank account, contact your bank when ready. Most banks can reverse fraudulent charges if you report them quickly. You can also place a fraud alert with the three major credit bureaus (Equifax, Experian, TransUnion) by visiting annualcreditreport.com — this makes it harder for someone to open new accounts in your name.

Common mistakes that let viruses stay on your computer

The most common mistake is not restarting in Safe Mode. Many people run a scan in normal mode, see that nothing was found, and assume the computer is clean. But malware often hides from antivirus tools when Windows is fully loaded. Safe Mode strips away the places malware hides, so the scan catches it.

Another mistake is stopping the scan early. A full scan can take hours, and people often cancel it after 30 minutes thinking "nothing is happening". Let the scan run to completion — progress may be slow, but it is working. If your computer is extremely slow, restart and try again in Safe Mode, where the scan will run faster.

A third mistake is using only one antivirus tool. Different programs catch different threats. If Windows Defender finds nothing, run Malwarebytes. If Malwarebytes finds nothing, run a bootable scan. Layering scans catches infections that a single tool might miss.

Finally, do not ignore browser toolbars, search engine changes, or unexpected pop-ups. These are often signs of adware or browser hijacker malware. If your home page changed, your search engine switched, or you see new toolbars you did not install, run a full scan when ready.

When to consider professional help or a fresh Windows install

If you have run multiple full scans with different tools, restarted in Safe Mode, and your computer still behaves oddly — freezing, crashing, running slowly, or showing pop-ups — the infection may be severe or your hard drive may be failing. At this point, a local computer repair shop can diagnose the problem faster than you can troubleshoot alone.

If a technician determines the malware is too embedded to remove safely, or if your hard drive is failing, you may need a fresh Windows install. This erases everything on your computer and reinstalls Windows from scratch, which removes all malware but also removes all your files. Before doing this, back up any important documents, photos, or files to an external drive or cloud storage.

A fresh install takes two to four hours and costs $100 to $300 at a repair shop, or it is free if you do it yourself (though it requires downloading Windows and creating a bootable USB drive). This is a last resort, but it is the most reliable way to may provide malware is gone.

Frequently Asked Questions

Can I remove a virus without restarting in Safe Mode?

You can try, but Safe Mode is much more effective. Malware often blocks or interferes with antivirus scans when Windows is fully loaded. Safe Mode disables most programs and services, so malware cannot hide or interfere. If a normal-mode scan finds nothing but your computer still has problems, restart in Safe Mode and scan again.

Is Windows Defender enough, or do I need Malwarebytes too?

Windows Defender catches most common viruses and malware. Malwarebytes is better at finding adware, browser hijackers, and less common threats. If Windows Defender finds nothing but your computer still has problems, run Malwarebytes. Using both tools together is more thorough than either alone.

How long does a full scan take?

A full scan with Windows Defender or Malwarebytes usually takes 30 minutes to two hours, depending on how many files you have and how fast your hard drive is. Bootable scans take longer — one to three hours — because they scan every file on your drive. Do not interrupt the scan; let it run to completion.

What if the antivirus program says it found a virus but will not remove it?

Some viruses lock themselves so antivirus tools cannot delete them while Windows is running. Restart in Safe Mode and run the scan again — Safe Mode often allows removal. If it still will not remove, restart and try a bootable antivirus tool, which runs before Windows loads and has full access to delete anything.

Do I need to buy antivirus software, or is free software enough?

Free antivirus tools like Windows Defender and Malwarebytes remove most viruses and malware. Paid versions add extra features like real-time monitoring and automatic updates, but for removing an existing infection, free tools work well. Start with free tools; if they do not solve the problem, consider professional help.