Security

How to Remove a Virus or Malware from Your Computer

Pop-ups you cannot close, a browser homepage that changed itself, or files that vanished — here is how to tell what you have and remove it without losing your data.

Most "virus" complaints are not viruses in the classic sense. They are adware, browser hijackers, fake optimiser tools or unwanted bundled programs. The distinction matters because they are removed in different ways and have different urgency.

Start by identifying which one you have.

1. Match your symptom to the infection type

What you seeMost likelyUrgency
Pop-ups you cannot close, ads inside normal websitesAdware / PUPMedium
Homepage and default search engine change back after you reset themBrowser hijackerMedium
Fan runs constantly, laptop hot even when idleCrypto minerHigh
Files encrypted, a note demanding paymentRansomwareCritical
Windows Defender disabled itself and will not turn back onRootkit / advanced malwareHigh
Friends receive messages from your accountAccount compromise, often via browserHigh

2. If it is ransomware, stop immediately

Critical: unplug the network cable and switch off Wi-Fi now.

Ransomware keeps encrypting files on mapped drives and network shares. Disconnecting limits the damage. Then:

  • Do not pay. Payment frequently does not produce a working key, and it funds the next attack.
  • Do not keep using the machine — every write overwrites recoverable data.
  • Check whether the encrypted files are recoverable from a shadow copy or a backup. Sometimes the encryption succeeded only partially.
  • Bring the drive to a specialist before wiping it. Once it is wiped, nothing is recoverable.

3. Disconnect, then work offline

For every other infection type, the first steps are the same:

  1. Disconnect from Wi-Fi and unplug any network cable. This stops data being sent out and stops further downloads.
  2. Unplug USB drives until you can scan them separately — malware spreads to them.
  3. Change the passwords for your email and bank from a different device, and turn on two-factor authentication.

4. Remove the obvious culprits

Open Settings → Apps → Installed apps and look for anything you do not recognise, especially:

  • Anything with "optimiser", "cleaner", "driver updater", "speed up" or "PC booster" in the name
  • Toolbars, search protectors and shopping assistants
  • Programs installed on the same day the problem started

Sort by install date. That single trick finds the culprit more often than any scanner.

5. Clean the browser

Browser hijackers live in three places: the homepage setting, the default search engine, and the extensions list. Removing only one leaves it able to restore itself.

  1. Settings → Search engine → set it back to a search engine you trust.
  2. Settings → On startup → remove any pinned or forced pages.
  3. Extensions → remove anything you did not deliberately install.
  4. Settings → Reset → "Restore settings to their original defaults". This keeps your bookmarks and passwords but clears hijacks.
Check the shortcut too. A hijacker can append a URL to the browser shortcut's target so the bad page loads even after you fix settings. Right-click the shortcut → Properties → look for anything after chrome.exe. Delete it.

6. Scan properly

A normal antivirus scan runs inside Windows, where sophisticated malware can hide itself. Use these in order:

  1. Microsoft Defender Offline Scan. Windows Security → Virus & threat protection → Scan options → Microsoft Defender Antivirus (Offline Scan). The machine restarts into a clean environment and scans before Windows loads.
  2. A second opinion scanner. Malwarebytes Free is the standard second-opinion tool and is safe to install alongside Defender.
  3. Safe Mode scan. If malware keeps restarting itself, boot into Safe Mode (hold Shift while clicking Restart) and run the scan there, so non-essential services cannot run.

7. When common malware removal is not enough

Some malware installs as a service, a scheduled task or a driver, and comes back after every scan. Signs:

  • Defender turns itself off again within minutes
  • A new user account appears that you did not create
  • Unknown scheduled tasks run every few minutes
  • The same pop-up returns the day after a successful clean

At that point the honest engineering answer is to back up your documents — not your programs — and reinstall Windows cleanly. Reinfection from a persistent rootkit is more work than a clean install and never fully certain. See our installation guide.

Professional removal uses the same boot-time approach but with better tools and the ability to image the disk first, so a bad scan never costs you data. That is what our virus removal service includes.

8. Do not get infected again

  • Keep Windows and your browser updated — most real infections arrive through unpatched software.
  • Never install a "crack", keygen or pre-activated copy of paid software. This is where the majority of serious infections come from.
  • Turn on Defender's real-time protection and leave it on.
  • Use an ad blocker. Malvertising through ad networks is a genuine infection route.
  • Back up to an external drive that you unplug afterwards. Ransomware encrypts connected backups too.
  • Be sceptical of calls or messages claiming to be Microsoft support. They never call you first.

Parts, drives and tools

Tools and parts we use and recommend for this kind of work. Prices and availability change often — check the current listing before ordering.

Affiliate disclosure: some links above are affiliate links. If you buy through them we may earn a small commission at no extra cost to you. It never changes what we recommend or what we write.

Frequently asked questions

Can I remove a virus myself?

Yes for adware, bundled programs and browser hijackers — uninstall, clean the browser, then run a Defender Offline scan. Rootkits, persistent miners and ransomware need imaging the drive first, so bring those in.

Will removing a virus delete my files?

A standard cleanup does not touch your documents. Ransomware and some aggressive infections may already have damaged files; we check what is recoverable before wiping anything.

My antivirus says the PC is clean but I still get pop-ups. Why?

The pop-ups are usually coming from browser notifications you allowed, or from an adware extension. Check site notification permissions in the browser and remove suspicious extensions.

Is Malwarebytes safe to use alongside Windows Defender?

Yes. Free Malwarebytes runs as an on-demand scanner and does not conflict with Defender. You do not need to pay for two real-time antivirus products — that causes conflicts.

How do I know if I have ransomware?

Your files gain unfamiliar extensions such as .locked or a random string, a text file with payment instructions appears on the desktop, and many programs stop opening.

Not sure what is on your computer?

We image the disk first, then remove the infection — so a bad scan can never cost you your files. Free diagnosis, fixed price.

Disclosure: some links on this page may be affiliate links. If you buy through them we may earn a small commission at no extra cost to you. We only recommend tools and services we would use ourselves.

Get the next guide by email

One practical computer or online-earning guide a month. No spam, unsubscribe anytime.

Keep reading

Related articles

WhatsApp