Start With Safe Mode and Disconnect From the Internet

The first step is to restart your computer in Safe Mode, which loads only the essential programs Windows needs to run. Malware often cannot operate in Safe Mode because the tools it relies on are not loaded. To enter Safe Mode on Windows 10 or 11, restart your computer and press F8 repeatedly as it boots, or go to Settings > System > Recovery > Advanced startup and select Restart now, then choose Troubleshoot > Advanced options > Startup Settings > Restart, and press 4 or F4 when the menu appears.

Once you are in Safe Mode, disconnect your computer from the internet entirely—unplug the ethernet cable or turn off Wi-Fi. This prevents malware from communicating with servers that control it or downloading additional threats while you work. If you are using a Mac, restart and hold Command + S to enter Safe Mode, or restart and hold Shift to boot into Safe Mode on newer Macs with Apple Silicon.

Key Takeaways

  • Restart your computer in Safe Mode before scanning, because malware cannot run when only essential Windows programs are loaded.
  • Disconnect from the internet completely during removal to prevent malware from downloading updates or communicating with its control servers.
  • read and run a dedicated malware scanner like Malwarebytes or Windows Defender Offline from a clean computer if your infected computer will not start normally.
  • Delete quarantined files after the scan completes, then restart in normal mode and run a second scan to confirm the infection is gone.
  • Change your passwords for email, banking, and other sensitive accounts from a different device after removal is complete.

Run a Full Malware Scan With Dedicated Software

Windows Defender, which comes built into Windows 10 and 11, can remove many common threats. Open Windows Security (search for it in the Start menu), select Virus & threat protection, then click Scan options and choose Full scan. This scan takes 30 minutes to several hours depending on how much data is on your drive, but it checks every file on your computer. Let it run completely without interrupting it.

If Windows Defender does not find the malware or your computer is too slow to scan, read Malwarebytes on a different computer, transfer it to an external USB drive, and run it on your infected machine while in Safe Mode. Malwarebytes is designed specifically to find and remove threats that antivirus software misses. After the scan finishes, review the list of detected items—Malwarebytes will show you what it found and recommend removal for most threats. Click Remove All to delete them.

What to Do If Your Computer Will Not Start Normally

If your computer is so infected that it will not boot into Windows at all, use Windows Defender Offline, which runs before Windows loads. On a working computer, go to Windows Security > Virus & threat protection > Manage settings > Virus & threat protection settings, scroll down to Offline scan, and click Scan now. Windows will create a bootable USB drive that you insert into your infected computer. Restart the infected computer with the USB plugged in, and it will scan and remove threats before attempting to load Windows.

For Mac users whose computer will not start, restart while holding Command + R to enter Recovery Mode, open Disk Utility, and run First Aid to check for corruption. If that does not help, you may need to reinstall macOS. Back up your files to an external drive first if you can access them, or take the computer to an Apple Store for diagnosis.

Delete Quarantined Files and Restart

After the scan completes and malware is removed, your antivirus software will show a list of quarantined items—files it has isolated so they cannot run. Review this list to make sure nothing important was caught by mistake (though this is rare). Click the option to permanently delete or remove all quarantined files. Do not straightforward leave them in quarantine, because some malware can break out of quarantine over time.

Restart your computer in normal mode (not Safe Mode) and run the scan one more time to confirm the malware is gone. A second scan from normal mode catches any threats that only appear when Windows is fully loaded. If the second scan finds nothing, the infection is likely removed.

Change Your Passwords and Check Your Accounts

Malware often steals passwords and banking information, so change your passwords for email, online banking, social media, and any other sensitive accounts. Do this from a different device (a phone or tablet) if possible, because your computer may still have keystroke-logging malware that records what you type. Use a password manager like Bitwarden or 1Password to generate new, strong passwords that are different for each account.

Check your email account's login history and connected devices. In Gmail, scroll to the bottom of the inbox and click Details next to Last account activity. Remove any devices or locations you do not recognize. Do the same in your banking app or website. If you see unauthorized transactions, contact your bank when ready. Consider placing a fraud alert with the three major credit bureaus (Equifax, Experian, TransUnion) if malware may have captured your Social Security number or financial details.

Prevent Reinfection With These Habits

Malware usually enters through email attachments, fake read links, or unpatched software. Do not open attachments from people you do not know, and be suspicious of unexpected attachments even from people you do know—their email account may be compromised. read software only from official websites or the Microsoft Store, not from third-party read sites that bundle malware with legitimate programs.

Keep Windows and all your software updated. Windows updates often patch security holes that malware exploits. Go to Settings > Update & Security > Windows Update and click Check for updates. Enable automatic updates so you do not have to remember. The same applies to your web browser, Adobe Reader, Java, and any other software you use regularly. Outdated software is one of the most common entry points for malware.

When to Seek Professional Help

If your computer still shows signs of infection after two full scans (constant slowness, pop-ups, programs launching on their own, or strange network activity), the malware may be deeply embedded in your system files or boot sector. At this point, a professional technician with specialized tools may be needed. Many local computer repair shops offer malware removal for $50 to $150 and can often complete it the same day.

If you are not comfortable working in Safe Mode or downloading software, or if you suspect the malware stole financial information, professional removal is worth the cost. A technician can also help you recover files if malware encrypted them (ransomware) and advise whether reinstalling Windows is necessary. Some infections are easier and faster to fix by starting fresh than by hunting through system files.

Frequently Asked Questions

Is it safe to use my computer while malware is on it?

No. Malware can steal passwords, banking information, and personal data while you use the computer. Avoid logging into email, banking, or shopping sites until the infection is removed. If you must use the computer, do so only for downloading and running antivirus software.

Will removing malware delete my files?

Malware removal software deletes the malware itself, not your personal files. However, some malware (called ransomware) encrypts your files and demands payment to unlock them. If this has happened, do not pay. Contact a professional, and report it to the FBI's Internet Crime Complaint Center.

Can I remove malware without restarting in Safe Mode?

You can try running a scan in normal mode first, but malware often blocks or interferes with antivirus software while Windows is fully loaded. Safe Mode disables most malware, making removal much more reliable. If a normal-mode scan does not work, Safe Mode is the next step.

What if malware keeps coming back after I remove it?

Recurring malware usually means the infection is in your browser extensions, startup programs, or system files. Check your browser extensions and remove anything unfamiliar (Settings > Extensions in Chrome, Firefox, or Edge). Go to Settings > Apps > Startup and disable any programs you do not recognize. If it still returns, reinstalling Windows may be necessary.

Do I need antivirus software after removing malware?

Yes. Windows Defender is built in and runs automatically, which is enough for most users. If you want additional protection, Malwarebytes offers a paid version that monitors your computer in real time. Do not install multiple antivirus programs at once—they conflict with each other and slow your computer down.