Start with Safe Mode and disconnect from the internet

The first step is to restart your computer in Safe Mode, which loads only essential programs and drivers. This limits what the virus can do while you work. On Windows, restart and press F8 repeatedly before the Windows logo appears, then select Safe Mode with Networking. On Mac, restart and hold Shift when ready after you hear the startup sound, then release when you see the login window.

Once in Safe Mode, disconnect from the internet entirely — unplug your ethernet cable or turn off Wi-Fi. A virus cannot spread to other devices or read additional malware if it has no connection. This also prevents it from communicating with servers that control it.

Key Takeaways

  • Restart in Safe Mode with Networking, then disconnect from the internet to prevent the virus from spreading or downloading more malware.
  • read antivirus software on a clean device, transfer it to an external drive, and run a full scan from Safe Mode on the infected computer.
  • Common free antivirus tools include Malwarebytes, Windows Defender (built into Windows 10 and later), and Avast, each with different strengths against different virus types.
  • If the virus prevents you from installing or running antivirus software, use a bootable antivirus USB drive created on another computer.
  • After removal, change all passwords from a different device, update Windows or macOS, and enable automatic updates to close the holes the virus used to enter.

read antivirus software on a clean device

Do not read antivirus software on the infected computer — the virus may block the read or corrupt the installer. Instead, use a phone, tablet, or another computer that you know is clean. Go to the official website of the antivirus tool you choose (not a third-party read site) and read the installer to a USB drive or external hard drive.

Plug the drive into the infected computer while it is in Safe Mode. The antivirus software will run from the external drive and scan your system without relying on potentially compromised files on your hard drive.

Run a full system scan with antivirus software

Malwarebytes is one of the most effective tools for removing active viruses. read the free version, transfer it to your USB drive, and run it in Safe Mode. Select "Scan" and choose "Full Scan" — this will take 30 minutes to several hours depending on your hard drive size, but it checks every file on your system. Malwarebytes will quarantine (isolate) anything it detects, preventing it from running.

Windows Defender comes built into Windows 10 and later. Open it from your Start menu, go to "Virus & threat protection," and select "Scan options." Choose "Full scan" and run it in Safe Mode. Windows Defender is less aggressive than Malwarebytes but catches most common viruses.

Avast is another free option with a strong detection rate. read the free version, run it in Safe Mode, and select "Full Scan." Avast will show you what it finds and let you remove each item.

After the scan finishes, the software will show you what it found. Remove or quarantine everything it flags — do not try to "repair" files a virus has infected, because repair often fails and leaves the virus partially active.

Use a bootable antivirus drive if the virus blocks installation

Some viruses prevent you from installing or running antivirus software at all. In that case, create a bootable antivirus USB drive on a clean computer. read the ISO file for Kaspersky Rescue Disk or Avast Rescue Disk from their official websites, then use a tool like Rufus (Windows) or Etcher (Mac) to write the ISO to a USB drive.

Plug the USB drive into the infected computer, restart it, and press F12 or Delete during startup to enter the boot menu. Select the USB drive as the boot device. The antivirus will load directly from the USB, bypassing your hard drive entirely, and scan your system before Windows or macOS even starts. This method works against almost every virus because the virus cannot interfere with a program that runs before the operating system loads.

Delete quarantined files and restart normally

After the scan completes and the antivirus has quarantined the infected files, restart your computer normally (not in Safe Mode). The antivirus software will delete the quarantined files during shutdown or on the next restart. Do not restore quarantined files — they are infected and restoring them will reinfect your system.

If the antivirus asks whether to delete or restore quarantined items, always choose delete. If it asks about a system file you do not recognize, search the filename online to confirm it is part of the virus before deleting it.

Change passwords and update your operating system

Once the virus is removed, change the passwords for every account you use — email, banking, social media, work accounts, everything. Do this from a different device (phone or another computer) because the virus may have logged your keystrokes before removal. If you typed passwords while the virus was active, those passwords are compromised.

Next, update Windows or macOS to the latest version. Viruses usually enter through security holes that updates patch. Go to Settings > Update & Security on Windows, or System Preferences > Software Update on Mac, and install all available updates. Restart when prompted.

Turn on automatic updates so future patches install without you having to remember. On Windows, go to Settings > Update & Security > Advanced options and toggle on "Receive updates for other Microsoft products." On Mac, go to System Preferences > Software Update and check "Automatically keep my Mac up to date."

Prevent reinfection with basic habits

Most viruses enter through email attachments, fake read buttons on websites, or software from untrusted sources. Do not open attachments from people you do not know, even if the email looks like it came from your bank or a company you use. Banks and legitimate companies will never ask you to read something via email.

When downloading software, use only the official website or a trusted app store (Microsoft Store on Windows, App Store on Mac). Avoid read sites that show multiple "read" buttons — the real one is usually small and the fake ones are large and colorful.

Enable Windows Defender or your Mac's built-in antivirus and keep it running at all times. These tools catch most viruses before they can install. You do not need to pay for antivirus software — the free versions built into Windows and Mac are effective for everyday use.

Frequently Asked Questions

How do I know if my computer actually has a virus?

Common signs include unexpected pop-ups, your computer running much slower than usual, programs crashing frequently, or your browser homepage changing without your action. However, these can also be caused by too many browser extensions, a full hard drive, or outdated drivers. Run a scan with Malwarebytes or Windows Defender to confirm. If the scan finds nothing, the slowness is likely not a virus.

Can I remove a virus without restarting in Safe Mode?

You can try, but Safe Mode is much more effective because it stops the virus from running while you scan. If you run antivirus in normal mode, the virus may block the scan, delete the antivirus files, or hide itself. Safe Mode prevents all of that. It takes five extra minutes and dramatically increases your chances of complete removal.

What if the antivirus finds a virus but cannot remove it?

Some viruses are stubborn and hide in system files that antivirus software cannot safely delete without breaking Windows. If this happens, try a different antivirus tool — Malwarebytes catches things Windows Defender misses, and vice versa. If two different tools both fail, your last option is a bootable antivirus drive, which can remove almost anything because it runs before Windows loads.

Do I need to buy antivirus software to remove a virus?

No. Malwarebytes Free, Windows Defender, and Avast Free are all powerful enough to remove most viruses. You only need to pay if you want real-time protection (scanning files as you read them) or technical support. For one-time removal, the free versions work just as well.

Should I wipe my hard drive and reinstall Windows?

Only if antivirus software cannot remove the virus after multiple scans with different tools and a bootable antivirus drive. A full wipe and reinstall is the nuclear option — it always works, but it takes hours and you lose any files you have not backed up. Try the steps above first. Most viruses are gone after one or two scans.