How to check your computer for malware right now

The fastest way to find malware is to run a full scan with Windows Defender, which comes built into Windows 10 and 11. Open Windows Security (search for it in your Start menu), click "Virus & threat protection," then "Scan options," select "Full scan," and click "Scan now." This takes 30 minutes to several hours depending on how much is on your drive, but it checks every file.

If you suspect something is actively wrong — your computer is slow, programs are crashing, or you see pop-ups you didn't click — run the scan in Safe Mode. Restart your computer, and as it boots, press F8 repeatedly (on some newer machines, hold Shift while clicking restart, then choose "Troubleshoot" > "Advanced options" > "Startup Settings"). Safe Mode loads only essential programs, so malware has fewer places to hide and fewer ways to interfere with the scan.

Windows Defender catches most common threats, but if you want a second opinion, Malwarebytes (free version) is designed specifically to find things Windows Defender might miss. Download it from malwarebytes.com, install it, and run a scan. Do not pay for the premium version unless you want real-time monitoring — the free scan is thorough enough for a one-time check.

Key Takeaways

  • Windows Defender's full scan is your first step and requires no download — it is already on your computer.
  • Run the scan in Safe Mode if your computer is behaving strangely, because it prevents malware from interfering with the scan itself.
  • Malwarebytes free scan can find threats Windows Defender misses, but the free version does not protect you going forward.
  • If a scan finds malware, quarantine it rather than deleting it immediately — quarantine lets you restore it if the removal breaks something.
  • After removal, change passwords for email and banking from a different device, because malware may have logged your keystrokes.

What malware actually does on your PC

Malware is software designed to harm you or steal from you. The main types are viruses (which copy themselves and spread), worms (which spread over networks), trojans (which pretend to be something else), ransomware (which locks your files until you pay), and spyware (which watches what you do). You do not need to know which type you have — the scan will find it regardless.

The reason you notice malware is usually one of these: your computer is much slower than normal, programs crash or freeze, you see ads or pop-ups you did not click, your browser homepage changed without you changing it, or your antivirus software is disabled. Some malware is silent — it steals passwords or watches your screen — so you might have it without noticing anything wrong.

Understanding what the scan results mean

When a scan finishes, it shows you a list of threats it found. Each one has a name (like "Trojan.Generic" or "PUP.Optional.Conduit") and a location (the file path where it lives). Do not panic if you see a long list — many of these are low-risk, and some are false positives (the scanner thought something was malware when it was not).

Windows Defender automatically quarantines anything it finds, which means it moves the file to an isolated folder where it cannot run. You can see what was quarantined by opening Windows Security, clicking "Virus & threat protection," scrolling down to "Quarantine," and clicking "Manage quarantine." If the scan broke something (a program stopped working), you can restore the file from here.

If Malwarebytes finds something, it will ask what you want to do. Choose "Quarantine" unless you are certain the file is malware. Quarantine is safer than delete because you can undo it if you made a mistake.

Why your antivirus might be turned off

If Windows Defender is disabled, malware usually did it. Some malware specifically turns off your antivirus so it can keep running without being detected. Check whether it is on by opening Windows Security and looking at the "Virus & threat protection" section — if it says "No security provider found" or shows a red X, it is off.

To turn it back on, click "Manage settings" and toggle "Real-time protection" to on. If the toggle is greyed out or will not stay on, you have malware that is actively preventing you from enabling it. In that case, restart in Safe Mode (as described above) and try again — malware cannot interfere as easily in Safe Mode.

If you still cannot turn it on, you may need to use Windows Defender Offline, which is a bootable scanner that runs before Windows even loads. Open Windows Security, click "Virus & threat protection," scroll down to "Virus & threat protection settings," and click "Manage settings." Scroll to "Virus & threat protection settings" and click "Scan options," then select "Windows Defender Offline scan" and click "Scan now." Your computer will restart and scan before Windows loads.

What to do after malware is removed

After the scan and quarantine, change your passwords. Use a different device if you have one — a phone or tablet — because if malware was logging your keystrokes, it might still be watching your keyboard on the infected computer. Change passwords for email first (because email is the key to resetting everything else), then banking, then social media and other accounts.

Check your email forwarding rules and recovery email address. Malware sometimes sets up a forwarding rule so it can read your email, or changes your recovery email so you cannot regain access if your password is stolen. In Gmail, click the gear icon, go to "Forwarding and POP/IMAP," and check the forwarding address. In Outlook, go to Settings > Mail > Forwarding. Delete any forwarding rules you did not create.

Run the scan again a week later. Sometimes malware comes back, or you missed an infection the first time. If it comes back repeatedly, the malware may be in your browser extensions or startup programs. Check your browser extensions (in Chrome, go to Settings > Extensions; in Edge, go to Settings > Extensions) and uninstall anything you do not recognize. Check your startup programs by opening Task Manager (Ctrl+Shift+Esc), clicking the "Startup" tab, and disabling anything suspicious.

When to consider a clean Windows install

If malware keeps coming back after you have removed it and checked your extensions and startup programs, or if your computer is so slow that it is unusable, a clean Windows install may be your best option. This means erasing everything on your drive and reinstalling Windows from scratch.

Before you do this, back up any files you need. Use an external drive or cloud storage (Google Drive, OneDrive, or Dropbox). Do not back up executable files (.exe, .bat, .msi) or system folders — only back up documents, photos, and other personal files. Malware can hide in backups.

To reinstall Windows, go to microsoft.com/software-download/windows11 (or windows10 if you have Windows 10), download the installation tool, and follow the prompts. This is a legitimate Microsoft tool and is free. The process takes about an hour and will erase your drive, so make sure your backup is complete first.

How to avoid malware in the first place

Most malware arrives through email attachments, fake download sites, or malicious ads. Do not open attachments from people you do not know, even if the email looks official. Banks and PayPal will never ask you to confirm your password by email — if an email asks you to, it is fake.

Download software only from official websites or the Microsoft Store. If you search for "free video player download" and click the first result, you might get malware instead of a video player. Go directly to the publisher's website instead — for example, vlc.videolan.org for VLC media player, not a third-party download site.

Keep Windows and your browser updated. Updates patch security holes that malware uses to get in. Turn on automatic updates: in Windows, go to Settings > Update & Security > Windows Update and make sure "Automatic" is selected. In your browser, updates usually happen automatically, but you can check by clicking the menu (three dots in Chrome or Edge) and looking for an update notification.

Frequently Asked Questions

Can malware survive a Windows reinstall?

Malware on your hard drive will be erased by a clean Windows install, but malware in your BIOS (the firmware that runs before Windows loads) could theoretically survive. This is extremely rare — it requires sophisticated malware that most people will never encounter. If you are worried, update your BIOS from the manufacturer's website before reinstalling Windows.

Is it safe to use my computer while a scan is running?

Yes, but it will be slow. The scan uses a lot of your processor and disk, so other programs will run sluggishly. If you need to use your computer, you can let the scan run in the background, but it will take longer. Closing other programs speeds up the scan.

What if I see malware in a file I actually use?

This is usually a false positive — the scanner thought a legitimate file was malware. Before you restore it, search the filename online to see if others have reported it as malware. If it seems legitimate, restore it from quarantine. If the restored file causes problems again, the scan probably flagged it correctly and you should delete it and find an alternative program.

Do I need both Windows Defender and Malwarebytes running at the same time?

No. Running two antivirus programs simultaneously can slow your computer and cause conflicts. Use Windows Defender for real-time protection (it runs all the time), and run Malwarebytes as a second opinion once a month. Do not install the paid version of Malwarebytes unless you want it to run in the background.

What does "PUP" mean in a scan result?

PUP stands for "Potentially Unwanted Program." These are programs that are not quite malware but are annoying — toolbars, search hijackers, or programs that came bundled with something else you installed. You can quarantine them safely. They are less dangerous than viruses, but they slow your computer and spy on your browsing.