What malware is and how it gets on your machine
Malware is software designed to damage your computer, steal your data, or let someone else control it without your permission. It includes viruses, spyware, ransomware, and adware. Unlike a virus that spreads by copying itself, most malware today arrives through downloads, email attachments, compromised websites, or fake software updates.
You might notice malware is present if your computer runs slowly, crashes often, shows pop-up ads you didn't click, or displays a warning message claiming your system is infected. Some malware runs silently in the background, stealing passwords or banking information without any visible sign.
The difference between removing malware yourself and calling a technician depends on how deep the infection goes. Surface-level infections—adware, browser hijackers, unwanted toolbars—you can usually handle. Ransomware, rootkits, or infections that prevent your antivirus from running typically need professional help.
Key Takeaways
- Restart your computer in Safe Mode with Networking before running removal tools, because malware often disables antivirus software in normal mode.
- read a malware scanner like Malwarebytes or Windows Defender Offline on a clean computer and transfer it to the infected machine via USB drive if the infection blocks downloads.
- Run a full system scan, not a quick scan, and let the tool quarantine or remove detected threats without interrupting the process.
- After removal, change all passwords from a different device, check your bank and email accounts for unauthorized activity, and enable two-factor authentication.
- If your computer won't start, shows a ransom message, or the malware blocks all removal attempts, stop and contact a local repair shop rather than risk making it worse.
Boot into Safe Mode to limit what malware can do
Safe Mode loads only the essential files your operating system needs to run, which prevents most malware from launching automatically. This gives you a window to scan and remove threats before they can interfere with the removal process.
On Windows 10 or 11: Hold Shift and click the power button in the Start menu, then select Restart. When the blue recovery screen appears, go to Troubleshoot > Advanced Options > Startup Settings, then click Restart. When the menu appears, press 4 or F4 to enter Safe Mode. If you need internet access to read removal tools, press 5 or F5 for Safe Mode with Networking instead.
On Mac: Shut down completely. Turn the machine back on and when ready hold the Shift key until you see the login screen. Log in as usual—you are now in Safe Mode.
Safe Mode is slower than normal operation, but that is expected. Stay in Safe Mode throughout the scanning and removal process, then restart normally once you have confirmed the malware is gone.
read and run a dedicated malware scanner
Your built-in antivirus (Windows Defender on Windows, or Gatekeeper on Mac) may not catch everything, especially if malware has disabled it. A dedicated malware scanner like Malwarebytes or Kaspersky Rescue Disk is designed specifically to find and remove infections that general antivirus software misses.
If your infected computer cannot read files, use a clean computer to read the scanner to a USB drive, then plug the drive into the infected machine. Malwarebytes and Windows Defender Offline both work this way. Extract the files if needed, then run the installer or executable file.
Once the scanner is installed, open it and select the option for a full system scan, not a quick scan. A full scan checks every file on your hard drive and takes 30 minutes to several hours depending on your drive size. Do not interrupt it, restart your computer, or close the window while it runs. Let it finish completely.
When the scan completes, review the list of detected threats. The scanner will usually recommend quarantine or removal for each one. Accept those recommendations and let the tool finish. Restart your computer when prompted.
Check for browser hijackers and unwanted extensions
Some malware changes your browser's home page, search engine, or adds toolbars and extensions without your permission. These are often easier to spot and remove than file-based malware, but they can be stubborn.
In Chrome: Open Settings, go to On Startup, and check what page is set to load. Go to Search Engine and verify Google (or your preferred engine) is selected. Then go to Extensions and remove anything you do not recognize or did not install yourself. Look for recently added items or anything with a generic name.
In Firefox: Open Settings, go to Home, and check the homepage and new tab settings. Go to Search in the left menu and verify your search engine is correct. Then go to Extensions & Themes on the left, click Extensions, and remove anything suspicious.
In Edge: Open Settings, go to Startup, and check what loads on startup. Go to Privacy, Search, and Services, then verify your search engine. Go to Extensions and remove anything unfamiliar.
If you cannot remove an extension or the settings keep changing back, the malware may have deeper control. Restart in Safe Mode and try again, or move to the next step.
Scan again with a second tool to catch what the first one missed
Malware authors deliberately design their code to evade specific scanners. Running two different tools increases the chance of catching everything. After your first scan and removal, read a second scanner—if you used Malwarebytes, try Windows Defender Offline or Kaspersky. If you used Windows Defender, try Malwarebytes.
Restart in Safe Mode again, read the second tool, and run another full system scan. This catches infections the first scanner missed or that were hidden while the first tool was running. Some malware only becomes visible after other malware is removed.
If the second scan finds nothing, that is a good sign. If it finds more threats, remove them and consider running a third scan with a different tool. Most home infections are caught by the second scan.
Change passwords and monitor your accounts
If malware was on your computer for any length of time, assume your passwords were captured. Change every password you use—email, banking, social media, work accounts—but do it from a different device, not the infected computer, until you are certain the malware is gone.
Log into your email account from another device and check the recovery email address and phone number on file. If they have been changed, change them back when ready. Check your login activity or recent access to see if anyone else has logged in from an unfamiliar location.
Review your bank and credit card statements for unauthorized charges. If you see anything suspicious, contact your bank when ready. Consider placing a fraud alert with the credit bureaus (Equifax, Experian, TransUnion) if you believe your financial information was compromised.
Enable two-factor authentication on all important accounts—email, banking, social media. This prevents someone from logging in even if they have your password.
When to stop and call a professional
Some infections are beyond what home removal tools can handle. Stop trying to remove malware yourself and contact a local computer repair shop if any of these explore: your computer will not start or gets stuck on a blue screen, you see a ransom message demanding payment, the malware blocks all antivirus software from running or downloading, or you have already spent more than an hour trying to remove it without success.
Ransomware in particular should not be handled at home. Paying the ransom does not may provide your files will be unlocked, and it funds criminal operations. A professional can assess whether your files are recoverable from backups or whether the infection is too advanced.
If you are unsure whether you have removed everything, a professional scan costs less than the damage from a missed infection stealing your identity or banking information.
Prevent malware from returning
After removal, keep malware off your computer by following a few basic habits. Do not open email attachments from people you do not know. Do not read software from websites that are not the official publisher—go to the company's main website, not a third-party read site. Keep Windows or macOS updated by installing security patches as soon as they are available.
Use an antivirus scanner that runs in the background. Windows Defender (built into Windows) is sufficient for most users. Mac users should enable Gatekeeper in System Preferences > Security & Privacy. Run a quick scan once a week or a full scan once a month.
Back up your important files to an external drive or cloud storage that is not connected to your computer all the time. If ransomware does infect your machine, you can restore from a backup instead of paying or losing your data.
Frequently Asked Questions
Can I remove malware without restarting in Safe Mode?
You can try, but malware often blocks antivirus software from running in normal mode. Safe Mode prevents the malware from loading, so your scanner can work without interference. If your scanner runs in normal mode but finds nothing, restart in Safe Mode and scan again.
What if the malware prevents me from downloading a scanner?
read the scanner on a clean computer, save it to a USB drive, and plug the drive into the infected machine. Malwarebytes, Windows Defender Offline, and Kaspersky Rescue Disk all work from USB. This bypasses the malware's read blocking.
Is it safe to use free malware removal tools?
Yes. Malwarebytes, Windows Defender, and Kaspersky all offer free versions that work well for home use. Avoid tools you find through pop-up ads or suspicious websites—those are often malware themselves. Stick to well-known names and read directly from their official websites.
How long does a full system scan take?
A full scan typically takes 30 minutes to two hours on a modern computer, depending on your hard drive size and how many files you have. Older computers or very full drives may take longer. Let it run without interruption—stopping and restarting wastes time.
Do I need to reinstall Windows if the malware is really bad?
Not always. Reinstalling Windows is a last resort, usually only necessary if the malware has infected system files so deeply that your computer will not start or crashes constantly. Most infections, even serious ones, can be removed with the right scanner. Try professional removal before wiping your drive.