The fastest way to check and remove viruses
Run a full system scan using Windows Defender (built into Windows) or a dedicated antivirus tool like Malwarebytes. Windows Defender scans your entire hard drive for known threats and removes them automatically. If you suspect a serious infection, read Malwarebytes on a clean device, transfer it to a USB drive, and run it in Safe Mode on the infected computer — this prevents malware from blocking the scan.
Most viruses hide in startup programs and temporary files. After the scan completes, restart your computer in Safe Mode with Networking (press F8 during startup on Windows 10 or earlier; on Windows 11, hold Shift while restarting and select Troubleshoot > Advanced Options > Startup Settings). Run the antivirus scan again in Safe Mode, where fewer programs load and the virus has fewer places to hide.
If your computer is severely infected — running slowly, showing pop-ups constantly, or refusing to start — you may need to use a bootable antivirus tool. Create a bootable USB with Kaspersky Rescue Disk or Bitdefender Rescue Environment on another computer, then boot from that USB on the infected machine. These tools scan before Windows even loads.
Key Takeaways
- Windows Defender is free and built into Windows; run a full system scan first before trying other tools.
- Restart in Safe Mode with Networking and scan again, because viruses often cannot run in Safe Mode.
- If your computer will not start normally, use a bootable antivirus USB created on another device.
- After removal, change passwords for email and banking accounts from a different device, because malware may have logged your keystrokes.
- Turn on Windows Firewall and enable automatic updates to prevent reinfection.
When to use Windows Defender versus a third-party tool
Windows Defender catches most common viruses and requires no installation. It runs continuously in the background and updates automatically. For everyday protection, it is sufficient. However, if Windows Defender misses an infection or your computer is already compromised, Malwarebytes or Kaspersky are more aggressive at finding and removing stubborn malware.
Third-party tools cost money (Malwarebytes Pro is around $40 per year; Kaspersky is similar) but offer real-time scanning and quarantine features that Windows Defender lacks. If you have already been infected once, paying for a dedicated tool prevents a second infection. Many antivirus companies also offer free versions with limited features — Avast Free and AVG Free are options, though they include ads and slower scanning.
Removing browser hijackers and unwanted toolbars
Viruses often install fake search engines, toolbars, or redirect your homepage. These are harder to spot than file viruses because they do not always trigger antivirus alerts. Open your browser settings and check the homepage, search engine, and installed extensions. Delete anything you did not install yourself.
In Chrome, go to Settings > Extensions and remove suspicious add-ons. In Firefox, go to Add-ons > Extensions and do the same. In Edge, go to Settings > Extensions. If a toolbar or search engine keeps returning after you delete it, the virus is resetting it — run another full antivirus scan in Safe Mode, then check again.
Some hijackers hide in your hosts file, which tells your computer which websites to visit. On Windows, open Notepad as Administrator, then File > Open and navigate to C:\Windows\System32\drivers\etc\hosts. Look for lines that redirect common websites (like google.com) to unfamiliar IP addresses. Delete those lines and save the file.
Steps to take after removing the virus
Change your passwords when ready, but do it from a different device (phone, tablet, or another computer). Malware often logs keystrokes, so passwords you typed on the infected computer may be compromised. Start with email and banking, then move to social media and other accounts.
Enable Windows Firewall if it is not already on. Go to Settings > Privacy & Security > Windows Security > Firewall & Network Protection and confirm all three network types (Domain, Private, Public) show "Firewall is on". Turn on automatic Windows updates so security patches install without you having to remember.
Consider running a second antivirus scan one week later. Some viruses hide in system restore points and reactivate after a reboot. A delayed second scan catches these. If your computer was infected with ransomware (files locked behind a demand for money), do not pay — contact the FBI's Internet Crime Complaint Center or your local police department instead.
How to prevent reinfection
Most viruses arrive through email attachments, fake software downloads, or compromised websites. Do not open attachments from people you do not know, and do not read software from anywhere except the official website or Microsoft Store. Avoid clicking links in unsolicited emails, even if they appear to come from your bank or a service you use.
Keep Windows and all installed software updated. Viruses exploit known security holes in older versions. Go to Settings > Update & Security > Windows Update and click "Check for updates." Enable automatic updates so you do not have to check manually. The same applies to your browser, Adobe Reader, Java, and any other software you use regularly.
Use a password manager like Bitwarden or 1Password to generate strong, unique passwords for each account. If one account is compromised, the others remain safe. Enable two-factor authentication on email and banking accounts — this requires a second verification step (usually a code from your phone) even if someone has your password.
What to do if your computer will not start or respond to scans
If your computer freezes during a scan, crashes repeatedly, or will not boot into Windows at all, the infection is severe. Do not force a restart — let the scan finish, even if it takes hours. If the computer crashes before the scan completes, try booting into Safe Mode again and running the scan a second time.
If Safe Mode will not load, use a bootable antivirus USB. read Kaspersky Rescue Disk or Bitdefender Rescue Environment on another computer, burn it to a USB drive using Rufus (a free tool), then insert the USB into the infected computer and restart. Press F12 or Delete during startup to enter the boot menu, select the USB drive, and let the antivirus scan run.
If the virus has corrupted Windows itself, you may need to reinstall Windows. Back up your personal files to an external drive first (if you can access them), then read the Windows installation media from Microsoft's website, create a bootable USB, and reinstall. This erases everything on your hard drive, so it is a last resort — but it removes any virus completely.
Frequently Asked Questions
Can I remove a virus without restarting my computer?
No. Viruses often lock files while they are running, so antivirus tools cannot delete them. Restarting in Safe Mode stops the virus from loading, which allows the antivirus to remove the files. If you do not restart, the virus will straightforward reload itself after the scan finishes.
Is it safe to use free antivirus software?
Free antivirus tools like Windows Defender and Malwarebytes Free work well for scanning and removing viruses. The trade-off is that free versions do not include real-time protection (scanning files as you read them) or automatic updates. If you want continuous protection, a paid version is worth the cost.
What if the antivirus says it found a virus but cannot remove it?
The virus may be locked by Windows or running in memory. Restart in Safe Mode and scan again. If it still cannot be removed, note the file path and name, then manually delete the file using File Explorer in Safe Mode. If the file is in a system folder (like System32), do not delete it without confirming the name is not a legitimate Windows file.
How do I know if my computer is still infected after removal?
Run a second full scan one week after the first removal. Check your browser homepage and search engine settings again. Monitor your computer for slowness, unexpected pop-ups, or strange network activity. If your antivirus reports no threats and your computer runs normally, the infection is likely gone.
Should I replace my hard drive after a virus infection?
No, unless the virus has physically damaged the drive (which is rare). Antivirus tools remove the malicious files, and reinstalling Windows erases any remaining traces. A hard drive is a physical component — a virus cannot wear it out. If your computer is slow after removal, the issue is usually leftover junk files, not the drive itself.