The fastest way to remove a virus depends on whether your computer still starts
If your computer boots normally, run a full scan with Windows Defender (built into Windows) or a free tool like Malwarebytes. If it won't start or starts but freezes immediately, you'll need to boot from a USB drive with antivirus software on it. The reason: malware that runs at startup can block your regular antivirus from working.
Before you start, disconnect from the internet if possible — unplug the ethernet cable or turn off Wi-Fi. This stops the malware from sending your data elsewhere or downloading more threats while you're removing it.
Key Takeaways
- Windows Defender (already on your computer) can remove most viruses if your computer still starts normally — run a full scan and restart.
- If your computer won't start or freezes at startup, create a bootable USB with Kaspersky Rescue Disk or Bitdefender Rescue Tool on another computer, then boot from it.
- Disconnect from the internet before scanning to prevent the malware from spreading or communicating with attackers.
- After removal, change your passwords from a different device, then check your bank and email accounts for unauthorized activity.
Removing a virus when Windows starts normally
Open Windows Defender by typing "Windows Defender" into the search box at the bottom left of your screen. Click "Virus & threat protection," then "Scan options." Select "Full scan" and click "Scan now." This will take 30 minutes to several hours depending on how much is on your drive.
While it scans, do not use the computer. When the scan finishes, Windows Defender will show you what it found. Click "Remove" or "Quarantine" on anything it flags. Then restart your computer.
If Windows Defender finds nothing but your computer still behaves strangely (programs crashing, constant pop-ups, slow performance), download Malwarebytes from malwarebytes.com on the same computer. Install it, run a full scan, and let it remove anything it finds. Restart again.
Removing a virus when your computer won't start
You need a second computer and a USB drive (at least 4 GB). Go to kaspersky.com/downloads/rescue-disk on the working computer. Download Kaspersky Rescue Disk, which is free. Follow the instructions to write it to the USB drive — the website will walk you through it.
Plug the USB into the infected computer. Restart it and hold down the key that opens the boot menu — usually F12, F2, or Delete, depending on your computer's brand. (The key appears briefly on the screen as it starts; if you miss it, restart and try again.) Select the USB drive from the menu.
Kaspersky Rescue Disk will load from the USB. Select "Run Kaspersky Rescue Disk" and let it scan your entire drive. When it finishes, it will show you what it found. Select everything and click "Remove." Then restart the computer and remove the USB.
If Kaspersky doesn't work, try Bitdefender Rescue Tool the same way — download it from bitdefender.com/downloads/rescuetool, write it to a USB, and boot from it.
What to do after the virus is removed
Change your passwords, but do it from a different device — a phone, tablet, or the second computer you used to create the rescue disk. Do not change passwords on the infected computer until you're confident it's clean. Start with email (Gmail, Outlook, Yahoo, or whatever you use), then your bank, then any other accounts with sensitive information.
Log into your email and bank accounts from the other device and look for suspicious activity — unfamiliar login locations, password reset requests you didn't make, or transactions you don't recognize. If you see anything odd, contact your bank and email provider immediately.
After a week of normal operation on the infected computer, run another full scan with Windows Defender or Malwarebytes to make sure nothing came back.
Preventing reinfection
Turn on Windows Defender's real-time protection. Type "Windows Defender" into the search box, click "Virus & threat protection," then "Manage settings." Make sure "Real-time protection" is on. This scans files as you download them.
Keep Windows itself updated. Click the Windows logo in the bottom left, type "Update," and click "Check for updates." Install anything it offers and restart if prompted. Malware often exploits holes in older versions of Windows.
Do not download software from random websites. Stick to the official website of the program you want, or the Microsoft Store, Apple App Store, or Google Play if you're on a phone. Pirated software and "free" versions of paid programs are common sources of malware.
When to take your computer to a technician
If you've run Windows Defender and Malwarebytes and your computer still won't start, or if it starts but immediately shows a blue screen with an error code, the malware may have damaged Windows itself. A local computer repair shop can reinstall Windows, which removes everything on the drive but also removes all malware. This costs between $100 and $300 depending on where you live.
If you're not comfortable creating a bootable USB or running scans yourself, a technician can do it for you. Many shops offer remote support — they log into your computer over the internet and do the work while you watch.
Understanding how you got infected
Most viruses arrive through email attachments, fake download buttons on websites, or software you thought was legitimate. If you remember what you clicked before the problems started, avoid it in the future. If you don't remember, just be more cautious: don't open email attachments from people you don't know, and don't click "Download" buttons that look like ads.
Some malware comes from USB drives someone else plugged into your computer. If that happened, ask that person to scan their computer too.
Frequently Asked Questions
Will removing the virus delete my files?
Windows Defender and Malwarebytes remove the malware but leave your files alone. If you use Kaspersky Rescue Disk or Bitdefender Rescue Tool and choose to remove everything they flag, they may delete infected files, but your documents, photos, and other data stay. Only a full Windows reinstall deletes everything.
How do I know if the virus is actually gone?
Run a full scan with Windows Defender or Malwarebytes a week after removal. If it finds nothing, the virus is likely gone. If your computer behaves normally (no crashes, no pop-ups, normal speed) for two weeks, you can be fairly confident. If problems return, the malware may have hidden itself — take it to a technician.
Can I get a virus from visiting a website?
Yes, but it's rare on legitimate websites. Malicious websites sometimes try to trick your browser into downloading malware, but modern browsers block most of these attempts. The bigger risk is clicking a fake download button that looks like part of the website but actually downloads malware.
Should I buy antivirus software after this?
Windows Defender is free and sufficient for most people. Paid antivirus software like Norton or McAfee offers extra features, but they're not necessary if you're careful about what you download and don't open suspicious email attachments. Windows Defender plus common sense is enough.
What if I think my password was stolen?
Change it immediately from a different device. Then monitor your email and bank accounts for the next few months. If you see charges you didn't make, contact your bank right away — they can reverse fraudulent transactions. Consider placing a fraud alert with the credit bureaus (Equifax, Experian, TransUnion) so someone can't open accounts in your name.