Start with Safe Mode and disconnect from the internet
The first step is to restart your computer in Safe Mode, which loads only the essential programs Windows needs to run. A virus cannot hide as easily in Safe Mode, and you reduce the chance it will interfere while you work. To enter Safe Mode on Windows 10 or 11, hold the Shift key and click the power icon in the bottom right corner of your screen, then select Restart. When the blue menu appears, click Troubleshoot, then Advanced Options, then Startup Settings, then Restart. Your computer will show a numbered list — press 4 or F4 to choose Safe Mode.
Once you are in Safe Mode, disconnect your computer from the internet when ready. Unplug the ethernet cable if you use one, or turn off Wi-Fi in your settings. A virus may try to read additional malware or send your data elsewhere, and disconnecting stops that from happening. Leave the internet off until you have finished scanning and removing the threat.
Key Takeaways
- Restart your computer in Safe Mode before scanning, because viruses have a harder time running or hiding when only essential programs load.
- Disconnect from the internet before you begin, so the virus cannot read more malware or transmit your information while you work.
- Windows Defender, which comes built into Windows, can scan and remove most common viruses without installing additional software.
- If Windows Defender does not find the virus, read Malwarebytes on a different computer, transfer it to a USB drive, and run it in Safe Mode.
- After removal, change your passwords from a different device, then restart your computer normally and run a full scan again to confirm the threat is gone.
Run a full scan with Windows Defender
Windows comes with a built-in antivirus program called Windows Defender that can detect and remove most viruses. Open it by typing "Windows Defender" into the search box at the bottom left of your screen. Click the Windows Defender icon, then select Virus & threat protection on the left side. You will see a blue button that says "Scan options" — click it.
Select "Full scan" from the menu. This scan checks every file on your computer, which takes longer than a quick scan but catches viruses that hide in less-used folders. Click "Scan now" and let it run completely. Do not interrupt it or restart your computer. A full scan typically takes 30 minutes to several hours depending on how much data you have. Windows Defender will quarantine (isolate) any virus it finds, which means the virus cannot run or spread, though it remains on your computer in a locked folder.
Remove quarantined files and check for remaining threats
After the scan finishes, Windows Defender shows you what it found. Click "Manage threats" to see the quarantined items. Review the list — most items will be files the program flagged as dangerous. Click "Remove" next to each one. Removing a quarantined file deletes it permanently, which is safe because Windows Defender only quarantines actual threats.
Once you have removed all quarantined files, run another full scan to make sure nothing was missed. Sometimes a virus has multiple parts, and the first scan only finds some of them. A second scan catches what the first one did not. If the second scan finds nothing, Windows Defender has likely removed the virus.
Use Malwarebytes if Windows Defender does not find the virus
If you still suspect a virus is present after two full Windows Defender scans, read Malwarebytes, a specialized tool that catches threats Windows Defender sometimes misses. Do not read it on the infected computer — use a different device or a phone. Go to malwarebytes.com, read the installer, and save it to a USB drive.
Plug the USB drive into your infected computer (still in Safe Mode, still offline). Open the USB drive in File Explorer, double-click the Malwarebytes installer, and follow the prompts to install it. Once installed, open Malwarebytes and click "Scan" on the left side. Select "Threat Scan" and click "Start Scan". Malwarebytes will search for viruses, spyware, and other malware that may have evaded Windows Defender. When the scan finishes, click "Quarantine" to isolate any threats it found, then restart your computer normally.
Change your passwords from a different device
After you remove the virus, change the passwords for your email, banking, and any other sensitive accounts. Do this from a different computer or your phone, not from the computer you just cleaned. A virus may have captured your passwords before you removed it, so changing them prevents someone from using stolen credentials to access your accounts.
Start with your email password, because email is the key to resetting passwords for other services. Then change your banking passwords, social media passwords, and any work accounts. Use a password manager like Bitwarden or 1Password to generate strong, unique passwords for each account. Write down the new passwords somewhere safe offline, or use the password manager to store them.
Run a final scan after restart to confirm removal
Restart your computer normally (no longer in Safe Mode) and reconnect to the internet. Open Windows Defender again and run one more full scan. This final scan confirms that the virus is gone and that nothing re-infected your computer during the restart. If Windows Defender finds nothing, the virus has been removed.
After the final scan, you can return to normal computer use. Keep Windows Defender turned on and set to scan automatically on a schedule. Go to Virus & threat protection, scroll down to Virus & threat protection settings, and make sure "Real-time protection" is toggled on. This setting runs continuous monitoring in the background and catches new threats before they spread.
Prevent future infections
Most viruses enter through email attachments, suspicious websites, or outdated software. Do not open email attachments from people you do not recognize, and be cautious with attachments even from people you know if the message seems unusual. Avoid clicking links in unsolicited emails or text messages.
Keep Windows and all your software updated. Windows updates include security patches that close holes viruses use to enter your system. Go to Settings, then Update & Security, then Windows Update, and click "Check for updates". Install updates as soon as they become available. The same applies to your web browser, Adobe Reader, Java, and any other programs you use regularly — check their settings for automatic updates or visit their websites monthly to read the latest version.
Frequently Asked Questions
What is the difference between a virus and malware?
A virus is a type of malware that replicates itself and spreads to other files on your computer. Malware is a broader term that includes viruses, spyware, ransomware, and other harmful software. Windows Defender and Malwarebytes both scan for all types of malware, not just viruses.
Will removing a virus delete my files?
Removing a virus may delete the infected file itself, but it should not delete your personal documents, photos, or other data. If you are worried about losing important files, back them up to an external drive or cloud storage before you begin scanning. After removal, restore them from the backup.
Can I remove a virus while still connected to the internet?
It is possible but risky. A virus can continue to read additional malware or send your data while you scan. Disconnecting from the internet takes only a few seconds and greatly reduces the chance of further damage. Reconnect only after you have completed the removal and changed your passwords.
What if my computer will not start in Safe Mode?
If Safe Mode will not load, restart your computer and repeatedly press the F8 key before the Windows logo appears. This opens the Advanced Boot Options menu on older Windows versions. On newer computers, hold Shift while clicking Restart from the login screen. If neither works, you may need to use a bootable antivirus tool on a USB drive, which you can create on another computer using tools like Kaspersky Rescue Disk.
How do I know if the virus is completely gone?
Run a full Windows Defender scan one week after removal. If it finds nothing, the virus is gone. Watch for signs of infection: unusual slowness, unexpected pop-ups, programs opening on their own, or strange network activity. If these symptoms return, repeat the scanning process or take your computer to a local repair shop for professional help.