What malware is and why it matters
Malware is software designed to harm your computer or steal your information. It includes viruses, spyware, ransomware, and adware — each works differently, but all run without your permission. Malware can slow your computer, display unwanted ads, steal passwords, lock your files for ransom, or send your personal data to criminals.
Removing malware is different from a regular software uninstall. Malware hides itself, runs in the background, and often resists deletion. The steps you take depend on what type of malware you have and how deeply it has embedded itself in your system. Some you can remove yourself; others require professional help or a full system reinstall.
Key Takeaways
- Start by restarting your computer in Safe Mode with Networking, which loads only essential programs and makes malware easier to find and remove.
- Use a dedicated malware scanner like Malwarebytes or Windows Defender (built into Windows) to detect and remove infections — do not rely on your antivirus alone.
- If your computer will not start normally or malware blocks your tools, boot from a USB drive with a recovery tool like Kaspersky Rescue Disk or Windows installation media.
- After removal, change all your passwords from a different device, monitor your bank and credit accounts for fraud, and update your operating system and software.
Restart in Safe Mode to limit what malware can do
Safe Mode loads only the bare minimum programs your computer needs to run — the operating system, drivers, and essential services. Malware often cannot load in Safe Mode, which makes it visible and easier to remove. Restart your computer and enter Safe Mode before you scan.
On Windows 10 or 11: Hold Shift and click the power button in the Start menu, then select Restart. When the blue screen appears, go to Troubleshoot → Advanced Options → Startup Settings → Restart. When the menu appears, press 4 for Safe Mode or 5 for Safe Mode with Networking. Use Safe Mode with Networking if you need internet access to download removal tools.
On Mac: Restart your computer and hold the Shift key immediately after you hear the startup sound, until you see the login window. This boots into Safe Mode. Release Shift when you see the login screen.
Scan with a dedicated malware removal tool
Antivirus software and malware scanners are not the same thing. Antivirus programs (like Norton or McAfee) run constantly in the background to prevent infection. Malware scanners (like Malwarebytes or Windows Defender) search your entire system for existing infections. You need both, but a scanner is what actually removes malware that is already there.
Malwarebytes is one of the most reliable dedicated scanners. Download it on a clean computer or phone, transfer it to an infected computer via USB drive if you cannot download directly, and run a full system scan. The free version scans and removes malware; the paid version adds real-time protection. Let the scan finish completely — it can take 30 minutes to an hour — and remove everything it finds.
Windows Defender (called Windows Security in Windows 10 and 11) is built into Windows and is free. Open Windows Security, go to Virus & Threat Protection, click Scan Options, select Full Scan, and run it. Windows Defender is less aggressive than Malwarebytes but catches most common infections. If Defender finds nothing but you still suspect malware, run Malwarebytes as well.
Run the scan in Safe Mode if possible. If malware blocks the scanner from opening, restart in Safe Mode with Networking and download the tool from there.
Remove malware that blocks your tools
Some malware prevents you from opening antivirus software, downloading files, or accessing Windows settings. If your scanner will not start or your browser redirects you to fake warning pages, you need to boot from outside Windows.
Create a bootable USB drive with a recovery tool. On a different computer, download Kaspersky Rescue Disk (free, works on Windows and Mac) or the Windows installation media from Microsoft's website. Follow the tool's instructions to write it to a USB drive. Insert the USB into your infected computer, restart, and boot from the USB (usually by pressing F12, F2, or Del during startup — the key varies by computer). Run the malware scanner from the USB. This bypasses Windows entirely and gives the scanner full access to your hard drive.
If you are not comfortable with this process, this is the point to take your computer to a repair shop. Technicians have tools and experience to handle stubborn infections.
Check for browser hijackers and unwanted extensions
Browser hijackers change your home page, search engine, or add toolbars without your permission. They are often bundled with free software you download. Check your browser settings even after you run a malware scan, because some hijackers hide from scanners.
In Chrome: Open Settings, go to On Startup, and check what page loads first. Go to Search Engine and verify Google is selected. Go to Extensions and remove anything you do not recognize. Look for extensions with generic names or no publisher listed.
In Firefox: Open Settings, go to Home, and check your homepage and new tab settings. Go to Extensions & Themes and remove unfamiliar add-ons. Check the Search section to confirm your search engine is what you chose.
In Edge: Open Settings, go to Startup, and check your home page. Go to Privacy, Search, and Services and verify your search engine. Go to Extensions and remove anything suspicious.
If you cannot change these settings or they revert after restart, malware is still active. Run another full system scan or restart in Safe Mode and try again.
Protect yourself after removal
Malware often steals passwords and financial information before you notice it is there. After you remove it, assume your passwords are compromised and change them.
Change your passwords from a different device — a phone, tablet, or another computer — not the one you just cleaned. Start with email and banking passwords, then move to social media, shopping sites, and work accounts. Use a password manager like Bitwarden or 1Password to generate strong, unique passwords for each site.
Monitor your accounts for fraud. Check your bank and credit card statements for charges you did not make. If you see fraud, contact your bank immediately. Consider placing a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, TransUnion) — this makes it harder for criminals to open accounts in your name.
Update your operating system and software. Malware often enters through security holes in outdated programs. After removal, turn on automatic updates for Windows or macOS, and update your browser, Java, Adobe Reader, and any other software you use regularly.
Prevent malware from returning
Most malware spreads through email attachments, fake download sites, or bundled with free software. A few habits reduce your risk significantly.
Do not open email attachments from people you do not know, and be cautious with attachments from people you do know if the message seems out of character. Malware spreads by hijacking email accounts and sending itself to contacts. Download software only from official websites or trusted app stores — not from random download sites that bundle malware with the program you want. When installing free software, read each screen carefully and uncheck boxes for toolbars, search engine changes, or "recommended" programs.
Keep your antivirus software running at all times, even if you think you are careful. Windows Defender is sufficient for most users; if you want additional protection, Bitdefender and Kaspersky are reliable paid options. Run a full system scan once a month, or whenever your computer behaves strangely.
Frequently Asked Questions
How do I know if my computer has malware?
Common signs include unexpected slowness, programs opening on their own, constant pop-up ads, your browser homepage changing without permission, or your antivirus software being disabled. If your computer behaves strangely, run a full scan with Malwarebytes or Windows Defender. Slow performance alone can have many causes, but combined with other signs, it usually points to malware.
Is it safe to use my computer while malware is on it?
No. Malware can steal passwords, financial information, and personal data while you use your computer. Avoid logging into banking or email accounts until after you have scanned and removed infections. If you must use your computer, do it from a different device if possible.
What if malware keeps coming back after I remove it?
Malware sometimes reinstalls itself if the source is still on your computer — an infected email attachment, a compromised website you visit regularly, or a program that downloads it automatically. After removal, check your Downloads folder and Desktop for suspicious files, uninstall any programs you do not recognize, and scan again. If it persists, a full Windows reinstall may be necessary.
Do I need both antivirus and a malware scanner?
Yes. Antivirus software runs constantly and blocks new infections. Malware scanners search for existing infections. They work differently and catch different things. Windows Defender covers antivirus; Malwarebytes covers scanning. Together they provide solid protection.
Should I pay for malware removal software?
No. Malwarebytes free version, Windows Defender, and Kaspersky Rescue Disk are all free and effective. Paid versions add features like real-time protection or priority support, but for one-time removal, free tools work fine. Avoid paying for "malware removal services" advertised in pop-ups — these are often scams.