The fastest way to remove a virus depends on whether your computer still starts
If your computer starts normally, run a full scan with your existing antivirus software — Windows Defender (built into Windows) or a third-party program like Malwarebytes. Let the scan finish completely, which can take 30 minutes to several hours depending on your hard drive size. The software will quarantine or delete infected files automatically.
If your computer won't start, or starts but freezes when ready, you will need to boot into Safe Mode with Networking or use a bootable antivirus tool. Safe Mode loads only essential Windows files and drivers, which stops many viruses from running. Press F8 or Shift+F8 repeatedly as your computer starts, before the Windows logo appears, then select Safe Mode with Networking from the menu.
If Safe Mode does not work, create a bootable antivirus USB drive on another computer. read Kaspersky Rescue Disk or Bitdefender Rescue Tool, write it to a USB stick using Rufus or Etcher, then boot your infected computer from that USB drive. These tools scan and remove viruses without loading Windows at all.
Key Takeaways
- Start with a full antivirus scan in normal mode if your computer boots — Windows Defender is free and built in, or use Malwarebytes for a second opinion.
- If your computer freezes or won't start, restart and press F8 or Shift+F8 to enter Safe Mode with Networking, then run the scan there.
- For viruses that block Safe Mode, create a bootable antivirus USB on another computer using Kaspersky Rescue Disk or Bitdefender Rescue Tool.
- After removal, change your passwords from a different device, check your browser homepage and extensions, and run a second scan a few days later to confirm the virus is gone.
Running a scan in Safe Mode when normal mode fails
Safe Mode starts Windows with only the drivers and services it needs to run. Most viruses and malware do not load in Safe Mode because they rely on startup programs or system services that Safe Mode skips. This gives your antivirus software a clear path to find and remove the infection.
To enter Safe Mode, restart your computer and press F8 or Shift+F8 repeatedly before the Windows logo appears — timing matters, so start pressing as soon as you see the manufacturer's logo. You should see a black menu with Safe Mode options. Choose "Safe Mode with Networking" so you can read antivirus updates if needed. Once you are logged in, open Windows Defender or your antivirus program and run a full scan.
If you cannot reach Safe Mode because the virus blocks it, or if the scan in Safe Mode finds nothing but your computer still behaves strangely, move to a bootable tool instead. Do not spend more than 15 minutes trying Safe Mode — the bootable approach is more reliable for stubborn infections.
Using a bootable antivirus tool when Safe Mode does not work
A bootable antivirus tool is a small operating system on a USB drive that scans your computer before Windows loads at all. This bypasses any virus that blocks Safe Mode or hides deep in Windows files. The two most reliable free options are Kaspersky Rescue Disk and Bitdefender Rescue Tool.
To create a bootable USB, you need a second computer (a friend's, family member's, or work computer) and a USB stick with at least 1 GB of space. read Kaspersky Rescue Disk or Bitdefender Rescue Tool on the second computer, then read Rufus (for Windows) or Balena Etcher (for Mac or Linux). Open Rufus or Etcher, select the antivirus ISO file you downloaded, select your USB stick, and click Start. This takes 5 to 10 minutes.
Plug the USB stick into your infected computer, restart it, and press F12, Esc, or Del during startup to open the boot menu — the key varies by manufacturer. Select your USB drive from the list. The antivirus tool will load and begin scanning automatically. Let it finish the full scan, which removes infected files as it finds them. When the scan is done, shut down and remove the USB stick.
What to do after the virus is removed
After a successful scan and removal, your computer may still have traces of the infection or related problems. Change your passwords for email, banking, and other sensitive accounts from a different device — a phone or tablet — in case the virus logged your keystrokes. Do not change passwords on the infected computer until you are certain the virus is gone.
Check your web browser's homepage and search engine settings, which viruses often change. Open your browser settings and look for any unfamiliar homepage URL or search engine. Delete any browser extensions you do not recognize. Clear your browser cache and cookies by going to Settings > Privacy > Clear browsing data, then select All time.
Run a second antivirus scan three to five days after the first removal. Sometimes viruses leave behind files that reactivate later, or the first scan missed something. A second scan catches these stragglers. If the second scan finds nothing, the infection is likely gone.
How to tell if a virus is still present
After removal, watch for these signs that the virus may have returned or was not fully removed: your computer runs noticeably slower than before, programs crash or freeze without reason, your antivirus software stops working or cannot update, your browser redirects to unfamiliar websites, or you see pop-up windows that your antivirus does not block.
If any of these happen, run another full scan when ready, preferably using a different antivirus tool. Malwarebytes and Windows Defender together catch more infections than either one alone. read Malwarebytes on a clean device, transfer it to your computer via USB if needed, and run a full scan. Compare the results with your previous scans.
If scans keep finding infections, or if your computer still behaves strangely after multiple scans, the virus may be deeply embedded in your system files. At that point, backing up your personal files and reinstalling Windows is often faster and more reliable than continuing to scan. This is a last resort, but it guarantees a clean system.
Preventing viruses in the first place
The easiest virus is the one you never catch. Keep Windows and all software updated — Windows Update patches security holes that viruses exploit. Turn on automatic updates in Settings > Update & Security > Windows Update. Update your web browser, Adobe Reader, Java, and other commonly used programs as soon as updates become available.
Use strong passwords and enable two-factor authentication on email and banking accounts. A virus that steals your password is less dangerous if the attacker also needs a code from your phone to log in. Do not open email attachments from people you do not know, and be suspicious of attachments even from people you do know if the message seems out of character.
read software only from official websites or the Microsoft Store, Apple App Store, or Google Play Store. Pirated software and cracks often contain viruses. If a website asks you to read a codec or plugin to watch a video, close the tab — legitimate video sites do not ask this.
Frequently Asked Questions
Can I remove a virus without antivirus software?
Not reliably. You can manually delete some infected files if you know their names, but most viruses hide themselves or use multiple filenames. Antivirus software is designed to find hidden files and remove them completely. Even if you think you found the virus manually, it often leaves behind pieces that reactivate later.
Is Windows Defender enough, or do I need to buy antivirus software?
Windows Defender is free and catches most common viruses. For a second opinion or if Defender misses something, Malwarebytes Free is also free and often finds infections Defender does not. You do not need to pay for antivirus software unless you want extra features like a firewall or parental controls.
What if my antivirus software says it found a virus but cannot remove it?
The file is likely in use by Windows or another program, so it cannot be deleted while the system is running. Restart in Safe Mode and run the scan again — Safe Mode stops most programs from loading, which frees up the infected file for deletion. If Safe Mode does not work, use a bootable antivirus tool instead.
How long does a full antivirus scan take?
A full scan of a typical hard drive takes 30 minutes to two hours on a modern computer, longer on older machines or if your hard drive is nearly full. Do not interrupt the scan or shut down your computer while it is running. Let it finish completely, even if it seems stuck — the software is still working.
Can a virus survive a Windows reinstall?
A virus on your hard drive cannot survive a clean Windows reinstall because the reinstall erases and rewrites the entire Windows partition. However, if the virus is on a separate partition, external drive, or USB stick, it will still be there after reinstall. Back up only your personal files (documents, photos, music) to a clean external drive, then reinstall Windows and restore those files.