How to Remove Malware From Your PC
To remove malware from a Windows PC, disconnect it from the internet, boot into Safe Mode with Networking, then run a full scan with the built-in Microsoft Defender followed by a second-opinion scan with Malwarebytes. For threats that hide, run a Microsoft Defender Offline scan to catch rootkits, then remove suspicious programs, browser extensions, and startup items, and reset any hijacked browser. Once every scan reports a clean system, change your important passwords from a device you know is clean. If the infection survives all of this, a clean reinstall of Windows is the only sure cure.
This guide removes malware from a Windows PC and returns it to a clean state, stopping the infection from spreading or stealing data. Malware is malicious software, including viruses, trojans, spyware, ransomware, and cryptominers, that runs without consent; the full category is covered in what is malware. The steps below name the exact Windows tool involved at each stage, from Windows Security and Microsoft Defender Offline to Task Manager and the browser reset option, alongside Malwarebytes as a second scanner, and they explain when a clean reinstall of Windows is the right response. Start by confirming the PC actually shows the signs of an infection.
What Are the Signs of a Malware Infection?
Malware reveals itself through changes in performance, browsing, and system behavior that you did not cause. The cards below group the most common signs; several together point to an infection far more strongly than any one alone.
Performance signs
Browser signs
Security signs
A single slow session can have ordinary causes, but redirects combined with disabled security indicate malware. If the only symptom is a sluggish machine, rule out an overloaded CPU first before assuming an infection.
How Do You Remove Malware From a PC?
Removing malware follows a fixed order, and the order matters: isolate the PC, disable the malware, scan, clear what scans leave behind, then secure your accounts. The sequence below is the full removal path.
- Disconnect from the network. Turn off Wi-Fi or unplug the Ethernet cable so the malware cannot reach its command server.
- Boot into Safe Mode with Networking. This loads only essential drivers, so most malware never starts and is easier to remove.
- Run a full Microsoft Defender scan. The built-in engine checks every file on the drive and quarantines what it finds.
- Run a second-opinion Malwarebytes scan. A second engine catches adware and unwanted programs the first may miss.
- Run a Microsoft Defender Offline scan. A pre-boot scan exposes rootkits that hide while Windows is running.
- Remove suspicious programs and extensions. Clear unknown startup items, installed apps, and browser add-ons so nothing relaunches.
- Change passwords from a clean device. Once every scan is clean, replace any credential a keylogger could have captured and turn on two-factor authentication.
Each step is detailed below in the order you should run it. Do not skip ahead to changing passwords until the scans confirm a clean system, because a keylogger that is still active will simply capture the new ones.
How Do You Disconnect the PC From the Internet?
Disconnecting from the internet cuts the malware off from its server, which stops data theft and further downloads while you clean the PC. The steps below isolate the machine.

- Unplug the Ethernet cable if the PC uses a wired connection.
- Turn off Wi-Fi from the taskbar network icon, or enable Airplane mode.
- Keep the PC offline throughout scanning so the malware cannot contact its command server.
- Reconnect only after the scans report a clean system and you are ready to change passwords.
Many malware types send stolen data or pull down additional payloads over the network. Isolating the PC halts both while the cleaning steps run, and it prevents the infection from reaching other devices on the same network.
How Do You Boot Into Safe Mode With Networking?
Safe Mode with Networking loads only essential drivers, which stops most malware from running and makes it easier to remove. The steps below enter Safe Mode.

- Open Settings, then System, then Recovery, and select Restart now under Advanced startup.
- After the restart, choose Troubleshoot, then Advanced options, then Startup Settings, then Restart.
- Press 5 or F5 to select Safe Mode with Networking.
- Sign in to Windows, which now loads with minimal drivers and most malware inactive.
- Confirm the desktop shows Safe Mode in the corners before continuing.
Safe Mode with Networking keeps the network driver active so a scanner can update its definitions, while blocking most startup malware. Anything set to launch on a normal boot does not load in this mode, which is what makes the scans below more effective.
How Do You Run a Full Microsoft Defender Scan?
A full Windows Security scan checks every file on the drive using the built-in Microsoft Defender Antivirus engine. The steps below run it.
- Open Windows Security from the Start menu and select Virus and threat protection.
- Click Scan options.
- Select Full scan, which examines every file and running program.
- Click Scan now and let it finish; a full scan can take an hour or more.
- Review the detections and choose Remove or Quarantine for each threat found.
Microsoft Defender Antivirus is the antivirus engine built into Windows 10 and Windows 11. A full scan reaches files a quick scan skips, so it is the correct choice for an active infection rather than a routine check.
How Do You Run a Second-Opinion Malwarebytes Scan?
A Malwarebytes scan adds a second engine that catches adware and potentially unwanted programs the first scan may miss. The steps below run it.
- Download Malwarebytes from the official site, on the infected PC in Safe Mode with Networking or from a clean device.
- Install it and let it update its detection database.
- Open Malwarebytes and click Scan to start a threat scan.
- Wait for the scan to finish and review the detected items.
- Click Quarantine to isolate every detection, then restart if prompted.
Running a second scanner improves detection because each engine recognizes different threats. The free version of Malwarebytes is an on-demand scanner designed to coexist with Microsoft Defender, which is enough for a one-time cleanup; a full scan typically takes around half an hour depending on drive size.
How Do You Run a Microsoft Defender Offline Scan for Rootkits?
A Microsoft Defender Offline scan runs before Windows fully loads, catching rootkits and persistent malware that hide during a normal scan. The steps below run it.
- Save any open work, since this scan restarts the PC.
- Open Windows Security, select Virus and threat protection, then Scan options.
- Select Microsoft Defender Offline scan and click Scan now.
- Allow the PC to restart into the offline scanning environment.
- Let the scan complete, after which Windows restarts and shows the results in Windows Security.
A rootkit hides deep in the system and can survive a standard scan by loading before the antivirus does. The offline scan runs outside the normal Windows environment, so the rootkit cannot conceal itself, which is why this step is essential for any stubborn infection.
How Do You Remove Suspicious Programs and Extensions?
Removing malicious startup entries, installed programs, and browser extensions stops the malware from relaunching after each restart. The steps below clear them and reset any hijacked browser.
- Open Task Manager, select the Startup apps tab, and disable any unfamiliar entry.
- Open Settings, then Apps, then Installed apps, and uninstall any program you did not install deliberately.
- Open each browser Extensions or Add-ons page and remove unknown extensions.
- In Chrome or Edge, open Settings and use Reset settings to restore the defaults, which clears a hijacked homepage or search engine.
- Restart the PC and confirm the unwanted entries do not return.
Malware adds startup entries and extensions so it reloads after a restart. A browser reset clears modified search engines, startup pages, and permissions without deleting saved bookmarks, removing the hijack settings that uninstalling an extension can leave behind. Re-enable only the extensions you recognize and need.
How Do You Change Passwords Safely After Cleaning?
Changing passwords after the system is clean replaces any credential the malware may have captured. The steps below reset them safely.
- Confirm every scan reports a clean system before changing any password.
- Change passwords from a separate device you know is clean, especially if any doubt remains about the cleaned PC.
- Reset email and banking passwords first, then other important accounts.
- Make each new password long and unique; the steps to create a strong password apply to every one.
- Enable two-factor authentication on each account so a stolen password alone cannot be reused.
When Should You Reinstall Windows?
A clean reinstall of Windows is the correct response when scans cannot fully remove the infection. The conditions below call for a reinstall.
- Threats return after every scan. Malware that reappears after removal points to a persistent infection a reinstall clears.
- A rootkit resists the offline scan. A rootkit that survives the offline scan calls for wiping the drive and reinstalling.
- Ransomware encrypted the files. A reinstall is required when ransomware has locked data and no decryption tool exists.
- The system stays unstable. Continued crashes or disabled security after cleaning indicate deep damage.
Using Reset this PC with the remove-everything option installs a clean copy of Windows. Back up important files to external storage first, then scan those files on a clean machine before restoring them, which prevents reinfection. In rare cases a firmware rootkit lives in the motherboard flash below the operating system and survives even a reinstall or a drive swap; that uncommon case needs a firmware reflash or board replacement rather than a software fix. If the reinstall leaves Windows damaged rather than infected, the steps to fix corrupt system files can repair it.
Malware Removal Tool Reference
| Tool | Purpose | When to Use |
|---|---|---|
| Windows Security (full scan) | Built-in antivirus scan | First scan on every cleanup |
| Malwarebytes | Second-engine scan | Catch adware and unwanted programs |
| Microsoft Defender Offline | Pre-boot rootkit scan | Suspected rootkit or persistent malware |
| Task Manager (Startup) | Disable persistence | Stop malware relaunching at boot |
| Browser reset | Clear hijacks | Redirects or changed search engine remain |
| Windows reset/reinstall | Wipe and restore | Infection survives all scans |
Last Thoughts on Removing Malware
Removing malware from a Windows PC follows a fixed order: disconnect from the internet, boot into Safe Mode with Networking, scan with Microsoft Defender and then Malwarebytes, run a Microsoft Defender Offline scan for rootkits, clear startup persistence, reset hijacked browsers, and change passwords from a clean device once the system is clean. The order is what makes it work, because each step disables the malware a little more before the next one runs.
A clean reinstall of Windows remains the surest cure when an infection survives every scan, with the rare firmware-rootkit exception that needs a hardware fix. Because a cleaned system still needs ongoing protection and the right follow-up, the hub of PC tutorials connects this guide to related maintenance and security walkthroughs.
Key Takeaways:
- Disconnect from the network first, because it stops data theft and further downloads during cleanup.
- Boot into Safe Mode with Networking so most malware never starts and definitions can still update.
- Scan with two engines: a full Microsoft Defender scan, then a second-opinion Malwarebytes scan.
- Run a Microsoft Defender Offline scan to catch rootkits that hide during a normal scan.
- Remove suspicious programs, startup items, and browser extensions, then reset any hijacked browser.
- Change passwords from a known-clean device after cleaning, enable two-factor authentication, and reinstall Windows if the infection survives every scan.
Frequently Asked Questions (FAQs)
How do I remove malware from my PC for free?
Disconnect from the internet, boot into Safe Mode with Networking, then run a full scan with the built-in Microsoft Defender and a second scan with the free Malwarebytes on-demand scanner. Add a Microsoft Defender Offline scan for rootkits, remove unknown startup items and browser extensions, then change passwords once the system is clean. Every tool named here is free.
Why disconnect from the internet before removing malware?
Disconnecting cuts the malware off from its command-and-control server, which stops it sending stolen data and downloading more payloads. Turn off Wi-Fi or unplug the Ethernet cable, stay offline through scanning, and reconnect only after the system is clean and you are ready to change passwords.
Is Microsoft Defender enough to remove malware?
Microsoft Defender removes many threats and is a capable built-in engine, but a single scanner can miss adware and potentially unwanted programs. Running a second on-demand scanner such as Malwarebytes catches different detections, and a Microsoft Defender Offline scan is needed separately for rootkits that hide during a normal scan.
What is a Microsoft Defender Offline scan?
A Microsoft Defender Offline scan restarts the PC and runs from a trusted environment before Windows fully loads. Because the operating system is not running, rootkits and master-boot-record malware that hide during a normal scan cannot conceal themselves, so the scanner can detect and remove them.
Should I change my passwords after removing malware?
Yes. Malware such as a keylogger records anything typed before removal, including passwords. Change them only after the system is clean, ideally from a separate device you know is safe, starting with email and banking, and enable two-factor authentication so a stolen password alone cannot be reused.
When should I reinstall Windows instead of cleaning the malware?
Reinstall when threats return after every scan, a rootkit survives the offline scan, ransomware has encrypted files with no decryptor, or the system stays unstable after cleaning. A clean reinstall is the surest cure for a deep infection. The rare exception is a firmware rootkit in the motherboard flash, which can survive a reinstall and needs a firmware reflash.


