What malware is and how it gets on your machine

Malware is software designed to harm your computer or steal your data. It includes viruses, spyware, ransomware, and adware — each works differently, but all slow your machine, expose your files, or hijack your settings without your permission.

Malware usually arrives through email attachments that look legitimate, downloads from untrusted websites, infected USB drives, or ads on compromised sites. Sometimes it hides inside a program you thought was safe. Once installed, it runs in the background and is hard to spot until your computer starts acting strange — programs crash, your browser homepage changes, or you see pop-ups you didn't click.

The sooner you remove it, the less damage it does. A machine infected for weeks may have already copied your passwords or banking details.

Key Takeaways

  • Restart your computer in Safe Mode with Networking before scanning, because malware often blocks antivirus software from running in normal mode.
  • read a malware scanner like Malwarebytes or Windows Defender Offline on a clean computer and transfer it to the infected one if your machine won't boot normally.
  • Run a full system scan, not a quick scan, because quick scans miss malware hiding in less-used folders.
  • After removal, change your passwords from a different device, because malware may have logged your keystrokes.
  • If your computer won't start or the malware blocks every removal tool, back up your files and consider a fresh Windows installation or calling a local repair shop.

Start in Safe Mode with Networking

Safe Mode loads only the bare minimum of drivers and programs your computer needs to run. Malware often cannot start in Safe Mode, which gives your antivirus tools a chance to work without interference.

To enter Safe Mode on Windows 10 or 11, restart your computer and hold down the Shift key while it boots. Click Troubleshoot, then Advanced options, then Startup Settings, then Restart. When the menu appears, press 4 or F4 for Safe Mode, or 5 or F5 for Safe Mode with Networking. Choose the networking version so you can read removal tools if you need them.

On a Mac, restart and hold Command + S to enter Single-User Mode, or restart and hold Command + Option + R for Recovery Mode, then open Disk Utility to run a scan.

read and run a full malware scan

Windows Defender, built into Windows 10 and 11, is your first line of defense. Open Windows Security (search for it in the Start menu), click Virus & threat protection, then Scan options. Select Full scan and click Scan now. A full scan checks every file on your drive and takes 30 minutes to several hours, but catches malware that quick scans miss.

If Windows Defender does not find anything but your computer still behaves strangely, read Malwarebytes (malwarebytes.com) or Kaspersky Rescue Disk (kaspersky.com). These are designed to catch threats Windows Defender misses. read on a clean computer if your infected machine will not cooperate, transfer the file to a USB drive, and run it on the infected machine in Safe Mode.

Let the scan finish completely before restarting. Do not interrupt it, even if it takes hours. When it finishes, review the results and remove anything flagged as malware.

Uninstall suspicious programs manually

Malware often disguises itself as a legitimate program in your installed software list. Open Settings, click Apps, then Apps & features. Look for programs you do not recognize or remember installing. Pay attention to anything with a vague name like "System Tool", "PC Optimizer", or "Search Protect".

Right-click the suspicious program and select Uninstall. Follow the prompts. If the uninstaller tries to install extra software or change your browser settings, cancel and move on — the program itself is likely malware.

After uninstalling, restart your computer and run another full scan with Windows Defender or Malwarebytes to catch any leftover files.

Reset your browser if it has been hijacked

Malware often changes your homepage, search engine, or adds unwanted extensions. Open your browser settings and check what your homepage is set to — it should be a site you chose, not something like "search.mysearchbar.com" or a random page.

In Chrome, click the menu (three dots), go to Settings, then On startup, and make sure it opens the page you want. Check Search engine and change it back to Google if it has been altered. Go to Extensions and remove anything you do not recognize.

In Firefox, click the menu, go to Settings, then Home, and set your homepage. Check Search and reset it to your preferred engine. Go to Extensions & themes and remove suspicious add-ons.

In Edge, click the menu, go to Settings, then Startup, and choose your homepage. Check Privacy, search, and services and reset your search engine.

Change your passwords from a different device

If malware was on your computer for more than a few hours, assume it logged your keystrokes. Change your passwords for email, banking, social media, and any other important account — but do it from a phone, tablet, or a different computer, not the infected one.

Start with your email password, because email is the master key to resetting everything else. Then change your bank and financial accounts. Enable two-factor authentication on accounts that support it, so a stolen password alone cannot unlock them.

If you see unauthorized charges or account activity, contact your bank and credit card company when ready. Consider placing a fraud alert with the three credit bureaus (Equifax, Experian, TransUnion) so no one can open accounts in your name.

When to reinstall Windows or call a professional

If your computer will not start, malware blocks every tool you try to run, or the infection comes back after removal, the safest option is a fresh Windows installation. This erases everything on your drive and reinstalls Windows from scratch, removing all malware with it.

Before you do this, back up your important files to an external drive or cloud storage. Then read the Windows installation tool from Microsoft (microsoft.com/software-read) on a different computer, create a bootable USB drive, and follow Microsoft's instructions to reinstall Windows.

If you are not comfortable doing this yourself, or if your computer is still under warranty, take it to a local repair shop. They can remove the malware, reinstall Windows if needed, and restore your files. This usually costs between $100 and $300 depending on how badly infected the machine is.

Frequently Asked Questions

Can malware survive a restart?

Most malware survives a normal restart because it is designed to run every time your computer boots. Some types, called rootkits, burrow so deep they survive even antivirus removal. This is why scanning in Safe Mode works — malware cannot load in Safe Mode, so the scanner can find and delete it.

Is it safe to use my computer while a malware scan is running?

No. A full scan uses a lot of your computer's processing power, and using it at the same time slows both the scan and your programs. More importantly, if malware is still active, it may interfere with the scan or hide from it. Let the scan finish completely before you do anything else.

What if I see a pop-up warning me about malware while I am scanning?

Pop-ups claiming your computer is infected are usually malware themselves, trying to scare you into buying fake antivirus software. Do not click them. Close the pop-up by pressing Alt + F4 or clicking the X, and let your real scan continue. Legitimate antivirus software does not pop up warnings while you are using your computer.

Do I need to buy antivirus software to remove malware?

No. Windows Defender is built into Windows and is strong enough for most infections. Malwarebytes has a free version that works well for removal. You only need to pay for antivirus if you want real-time protection going forward, and even then, Windows Defender is sufficient for most people.

How do I prevent malware from coming back?

Keep Windows and all your programs updated, because updates patch security holes malware uses to get in. Do not open email attachments from people you do not know. Avoid downloading programs from anywhere except the official website or the Microsoft Store. Use strong, unique passwords for each account. These habits stop most malware before it arrives.