Start with a full scan using built-in or free antivirus software

The fastest way to find and remove viruses is to run a complete system scan using antivirus software. Windows comes with Windows Defender (called Microsoft Defender on newer versions), which is already installed and runs in the background. If you use a Mac, Xprotect is built in. Both are free and do not require installation.

To run a full scan in Windows Defender, open Settings, go to Privacy & Security, then Windows Security, and select Virus & threat protection. Click Scan options and choose Full scan. This can take 30 minutes to several hours depending on how much data you have. Do not interrupt it or restart your computer while it runs.

If you prefer a second opinion or want to scan before Windows Defender is active, read Malwarebytes (free version) or Kaspersky Rescue Disk. These are reputable tools that many IT professionals recommend. read them on a clean computer if possible, transfer them to a USB drive, and run them from there.

Key Takeaways

  • Windows Defender and Mac Xprotect are free built-in tools that can find and remove most viruses without additional software.
  • A full system scan takes time but catches infections that background scans miss, so run it when you do not need your computer for other work.
  • If your computer will not start or behaves erratically during a scan, restart in Safe Mode (Windows) or Recovery Mode (Mac) before trying again.
  • After removal, change passwords for email and banking accounts from a different device, because malware may have recorded them.
  • If a scan finds nothing but your computer still behaves strangely, the problem may be hardware failure or a browser hijacker rather than a virus.

Restart your computer in Safe Mode to prevent malware from running during the scan

Malware often blocks antivirus software or hides while your computer is running normally. Safe Mode loads only essential Windows files and drivers, which prevents most malware from starting. This gives your antivirus a clearer view of what is actually on your disk.

On Windows 10 or 11, restart your computer and hold down the Shift key while clicking the power button to shut down. When it restarts, you will see a menu with boot options. Select Troubleshoot, then Advanced options, then Startup Settings. Restart again and choose Safe Mode with Networking (the networking option lets you read updates if needed).

On a Mac, shut down completely. Turn it back on and when ready hold Command + S until you see text on the screen. This boots into Single-User Mode. Type fsck -fy and press Enter to check the disk, then type reboot to restart normally. Safe Mode on Mac is less common because Xprotect is more aggressive about blocking malware at startup.

Remove browser hijackers and unwanted extensions separately

Some malware does not show up in antivirus scans because it lives in your web browser as an extension or changes your search engine and homepage. These are called browser hijackers and they are common but usually not dangerous — they just redirect your searches to ad sites or inject ads into pages you visit.

In Chrome, Firefox, or Edge, go to Settings or Preferences, find Extensions or Add-ons, and look for anything you do not recognize. Delete anything suspicious. Then check your homepage and search engine settings — they should point to Google, Bing, or your chosen engine, not to an unfamiliar site.

If your browser homepage keeps resetting or you cannot change it, the hijacker may have installed a system-level tool. In that case, use the antivirus scan first, then check your browser settings again. If it still will not change, uninstall and reinstall the browser — this removes all extensions and resets all settings to default.

Check your installed programs and remove anything you do not recognize

Malware often arrives bundled with free software. When you install a program, the installer may slip in additional software without making it obvious. After a scan, look at what is actually installed on your computer and remove anything unfamiliar.

On Windows, open Settings, go to Apps, then Apps & features. Scroll through the list and look for programs with names like "Optimizer", "Cleaner", "Booster", or anything with random letters and numbers. These are often unwanted. Click on each suspicious program and select Uninstall. Windows will walk you through removal.

On a Mac, open Applications in Finder and look for programs you did not install. Drag them to the Trash. Some malware hides in Library folders, but this is rare on Mac — if you suspect it, take your computer to an Apple Store or a local repair shop rather than digging into system folders yourself.

Update Windows, macOS, and all your software after removal

Viruses often exploit security holes in outdated software. Once you have removed the infection, patch those holes so the same malware cannot get back in. Updates are free and usually take 10 to 30 minutes.

On Windows, open Settings and go to Update & Security (or System > About on newer versions). Click Check for updates and install anything available. You may need to restart. Then update your browser, Adobe Reader, Java, and any other software you use regularly. Most programs have an automatic update option in their settings — turn it on.

On a Mac, go to System Settings, then General, then Software Update. Install any updates shown. Then open each process you use and check its menu for an update option — most modern apps update automatically, but some do not.

Change passwords for email, banking, and other sensitive accounts

Malware often records keystrokes or steals passwords while it is on your computer. Even after you remove it, the attacker may still have your old passwords. Change them from a different device (a phone or tablet) if possible, so that if your computer is still compromised, the new password is not recorded.

Start with your email password, because email is the key to resetting everything else — if someone has your email, they can reset your bank password, social media, and other accounts. Then change passwords for your bank, credit card, and any other financial accounts. Use a password manager like Bitwarden or 1Password to generate and store strong passwords so you do not have to remember them.

If you used the same password on multiple sites, change it everywhere. This takes time but is worth it — reusing passwords means one breach compromises all your accounts.

When to take your computer to a professional

Some infections are too deep for home removal. If your computer will not start, crashes repeatedly during a scan, or behaves strangely even after a full scan and restart, a local repair shop can help. They have tools like bootable antivirus disks and can access your hard drive from another computer if yours will not start.

You should also see a professional if you suspect your computer was targeted specifically — for example, if you received a threatening email or if someone you know was hacked and your computer was mentioned. These cases may involve ransomware (malware that locks your files and demands payment) or spyware (malware that watches what you do), both of which require specialized removal.

A repair shop visit typically costs between $100 and $300 depending on how infected the computer is and how long removal takes. Ask for a quote before they start work.

Frequently Asked Questions

Will antivirus software slow down my computer?

Windows Defender has minimal impact on performance because it is designed to run quietly in the background. Older antivirus software like Norton or McAfee can slow things down noticeably, which is why many people switch to Defender. If your computer feels slow after installing antivirus, try uninstalling it and relying on Defender instead.

Can I get a virus from visiting a website?

Yes, but it is rare on modern browsers. Visiting a malicious website can trigger a drive-by read if your browser or plugins have unpatched security holes. This is why keeping Windows, macOS, and your browser updated is so important. Avoid clicking links in emails or messages from people you do not know, and be skeptical of sites that ask you to read software to view a video or document.

What is the difference between a virus and malware?

A virus is a type of malware that copies itself and spreads to other files or computers. Malware is the umbrella term for any malicious software — viruses, spyware, ransomware, and browser hijackers are all malware. For practical purposes, antivirus software removes all of them, so the distinction does not matter when you are cleaning your computer.

Should I pay for antivirus software or use the free version?

Windows Defender is free and sufficient for most people. Paid antivirus software offers extra features like a VPN, password manager, or identity theft monitoring, but these are not necessary for virus removal. If you want extra features, Bitdefender and Norton are reputable, but do not pay for antivirus just to remove a virus — free tools work fine.

What if the antivirus says it found a virus but cannot remove it?

Some malware locks itself so antivirus cannot delete it while Windows is running. Restart in Safe Mode and run the scan again — Safe Mode prevents the malware from protecting itself. If it still will not remove, note the name and file location that the antivirus reports, then take your computer to a repair shop with that information. They can remove it manually or from a bootable disk.