Start with safe mode and a full system scan

The fastest way to remove a virus is to restart your computer in safe mode, then run a full antivirus scan. Safe mode loads only the essential programs your computer needs to run, which prevents most viruses from starting up alongside Windows or macOS. Once you are in safe mode, a complete scan of your hard drive takes 30 minutes to several hours depending on your drive size, but it catches infections that a regular scan might miss.

To enter safe mode on Windows 10 or 11, restart your computer and press F8 repeatedly as it boots, or hold Shift while clicking the restart button in the power menu. On macOS, restart and hold Command+S until you see the login screen. After you log in, open your antivirus program and select the option for a full or complete system scan — not a quick scan.

Key Takeaways

  • Safe mode prevents most viruses from running, making them easier for antivirus software to detect and remove.
  • Windows Defender (built into Windows) and Malwarebytes are both free options that work without paying for a subscription.
  • A full system scan can take several hours but finds infections that quick scans miss.
  • If your antivirus cannot remove a file, you may need to delete it manually or use a specialized removal tool from the virus publisher.
  • After removal, change your passwords and check your bank and email accounts for unauthorized activity.

Use Windows Defender if you do not have antivirus software

Windows 10 and 11 come with Windows Defender built in, and it runs automatically in the background. If you have never installed a separate antivirus program, Defender is already protecting your computer. To run a manual scan, open Windows Security (search for it in the Start menu), click Virus & threat protection, then click Scan options and choose Full scan.

If you prefer a different program, Malwarebytes offers a free version that works alongside Defender. Download it from malwarebytes.com, install it, and run a full scan. The free version scans and removes threats but does not provide real-time protection — Defender handles that part. On macOS, Malwarebytes is also free and works the same way.

Remove files your antivirus cannot delete

Sometimes an antivirus program detects a virus but cannot remove it because the file is locked or in use. When this happens, the scan report will show the file path and name. Write down the exact location — for example, C:\Users\YourName\AppData\Local\Temp\virus.exe — and restart in safe mode again.

In safe mode, open File Explorer, navigate to that folder, and delete the file manually. If Windows says the file is in use or you do not have permission, right-click the file, select Properties, go to the Security tab, click Edit, select your username, check Full Control, and click Apply. Then try deleting it again. If the file is still locked, restart your computer and the file should delete on the next boot.

Check for browser hijackers and unwanted extensions

Some viruses change your browser's home page, search engine, or add unwanted toolbars and extensions. Open your browser settings and look at the home page and search engine — if they are not what you set them to, change them back. In Chrome, go to Settings > On startup and make sure "Open the New Tab page" is selected. In Firefox, go to Home and set your preferred home page.

Next, check your installed extensions. In Chrome, go to Settings > Extensions and remove anything you do not recognize. In Firefox, go to Add-ons > Extensions and do the same. On Safari, go to Safari > Settings > Extensions. Delete any extension you did not install yourself, especially ones with generic names or no publisher information.

Scan for rootkits and hidden malware

A rootkit is a type of malware that hides itself from antivirus programs by running at a deeper level of your operating system. Standard scans often miss rootkits. If your computer still behaves strangely after a full scan — programs crashing, unexpected pop-ups, or slow performance — download a specialized rootkit scanner.

Kaspersky Rescue Disk is a free tool that scans your computer before Windows even starts, which catches rootkits that hide from Windows-based scanners. Download it on a different computer, burn it to a USB drive using the Kaspersky tool, then boot your infected computer from that USB. The scan takes 30 to 60 minutes and removes threats it finds. Alternatively, Bitdefender Rescue Environment offers the same approach and is also free.

Change passwords and monitor your accounts

After you remove the virus, change the passwords for your email, banking, and social media accounts. Use a computer you know is clean, or wait until after you have completed all scans and removed all threats. A virus may have captured your passwords while it was running, so changing them prevents an attacker from using old credentials to access your accounts.

Check your email's login history and connected apps. In Gmail, scroll to the bottom of any email and click Details, then Review all devices. Remove any sessions or apps you do not recognize. In your bank's website, look for a login history or active sessions page and log out any sessions that are not yours. Watch your bank and credit card statements for the next month for unauthorized charges.

Prevent reinfection with these habits

Most viruses arrive through email attachments, malicious websites, or fake software downloads. Do not open attachments from people you do not know, even if the email looks like it came from someone you trust — attackers spoof email addresses. Avoid downloading software from anywhere except the official website or a trusted app store like the Microsoft Store or Apple App Store.

Keep Windows and macOS updated by turning on automatic updates. Go to Settings > Update & Security on Windows or System Preferences > Software Update on macOS and make sure updates are set to install automatically. Outdated operating systems have security holes that viruses exploit. Also keep your browser and antivirus software up to date — they update automatically by default, but you can check manually if you want to be sure.

Frequently Asked Questions

How do I know if my computer has a virus?

Common signs include unexpected pop-ups, programs crashing or running slowly, your browser home page changing without your permission, or your antivirus program alerting you. If you see any of these, run a full antivirus scan in safe mode to check.

Is it safe to use my computer while a virus scan is running?

Yes, but the scan will run slower and may miss some threats if programs are actively running. It is better to start the scan and leave your computer alone until it finishes, or run the scan overnight.

What if my antivirus program itself is infected?

Download Malwarebytes or another antivirus on a USB drive from a clean computer, then plug the USB into your infected computer and run the scan from there. This bypasses any virus that might be blocking your installed antivirus.

Do I need to pay for antivirus software to remove a virus?

No. Windows Defender is free and built in, and Malwarebytes has a free version that removes threats. You only need to pay if you want real-time protection and extra features, which are optional.

Should I wipe my hard drive and reinstall Windows?

Only if the virus is still present after multiple full scans and rootkit scans. A complete wipe and reinstall removes everything, including the virus, but also deletes all your files. Back up important documents first if you choose this route.