Most "virus" complaints are not viruses in the classic sense. They are adware, browser hijackers, fake optimiser tools or unwanted bundled programs. The distinction matters because they are removed in different ways and have different urgency.
Start by identifying which one you have.
1. Match your symptom to the infection type
| What you see | Most likely | Urgency |
|---|---|---|
| Pop-ups you cannot close, ads inside normal websites | Adware / PUP | Medium |
| Homepage and default search engine change back after you reset them | Browser hijacker | Medium |
| Fan runs constantly, laptop hot even when idle | Crypto miner | High |
| Files encrypted, a note demanding payment | Ransomware | Critical |
| Windows Defender disabled itself and will not turn back on | Rootkit / advanced malware | High |
| Friends receive messages from your account | Account compromise, often via browser | High |
2. If it is ransomware, stop immediately
Ransomware keeps encrypting files on mapped drives and network shares. Disconnecting limits the damage. Then:
- Do not pay. Payment frequently does not produce a working key, and it funds the next attack.
- Do not keep using the machine — every write overwrites recoverable data.
- Check whether the encrypted files are recoverable from a shadow copy or a backup. Sometimes the encryption succeeded only partially.
- Bring the drive to a specialist before wiping it. Once it is wiped, nothing is recoverable.
3. Disconnect, then work offline
For every other infection type, the first steps are the same:
- Disconnect from Wi-Fi and unplug any network cable. This stops data being sent out and stops further downloads.
- Unplug USB drives until you can scan them separately — malware spreads to them.
- Change the passwords for your email and bank from a different device, and turn on two-factor authentication.
4. Remove the obvious culprits
Open Settings → Apps → Installed apps and look for anything you do not recognise, especially:
- Anything with "optimiser", "cleaner", "driver updater", "speed up" or "PC booster" in the name
- Toolbars, search protectors and shopping assistants
- Programs installed on the same day the problem started
Sort by install date. That single trick finds the culprit more often than any scanner.
5. Clean the browser
Browser hijackers live in three places: the homepage setting, the default search engine, and the extensions list. Removing only one leaves it able to restore itself.
- Settings → Search engine → set it back to a search engine you trust.
- Settings → On startup → remove any pinned or forced pages.
- Extensions → remove anything you did not deliberately install.
- Settings → Reset → "Restore settings to their original defaults". This keeps your bookmarks and passwords but clears hijacks.
chrome.exe. Delete it.6. Scan properly
A normal antivirus scan runs inside Windows, where sophisticated malware can hide itself. Use these in order:
- Microsoft Defender Offline Scan. Windows Security → Virus & threat protection → Scan options → Microsoft Defender Antivirus (Offline Scan). The machine restarts into a clean environment and scans before Windows loads.
- A second opinion scanner. Malwarebytes Free is the standard second-opinion tool and is safe to install alongside Defender.
- Safe Mode scan. If malware keeps restarting itself, boot into Safe Mode (hold Shift while clicking Restart) and run the scan there, so non-essential services cannot run.
7. When common malware removal is not enough
Some malware installs as a service, a scheduled task or a driver, and comes back after every scan. Signs:
- Defender turns itself off again within minutes
- A new user account appears that you did not create
- Unknown scheduled tasks run every few minutes
- The same pop-up returns the day after a successful clean
At that point the honest engineering answer is to back up your documents — not your programs — and reinstall Windows cleanly. Reinfection from a persistent rootkit is more work than a clean install and never fully certain. See our installation guide.
Professional removal uses the same boot-time approach but with better tools and the ability to image the disk first, so a bad scan never costs you data. That is what our virus removal service includes.
8. Do not get infected again
- Keep Windows and your browser updated — most real infections arrive through unpatched software.
- Never install a "crack", keygen or pre-activated copy of paid software. This is where the majority of serious infections come from.
- Turn on Defender's real-time protection and leave it on.
- Use an ad blocker. Malvertising through ad networks is a genuine infection route.
- Back up to an external drive that you unplug afterwards. Ransomware encrypts connected backups too.
- Be sceptical of calls or messages claiming to be Microsoft support. They never call you first.
Parts, drives and tools
Tools and parts we use and recommend for this kind of work. Prices and availability change often — check the current listing before ordering.
Affiliate disclosure: some links above are affiliate links. If you buy through them we may earn a small commission at no extra cost to you. It never changes what we recommend or what we write.
Frequently asked questions
Can I remove a virus myself?
Yes for adware, bundled programs and browser hijackers — uninstall, clean the browser, then run a Defender Offline scan. Rootkits, persistent miners and ransomware need imaging the drive first, so bring those in.
Will removing a virus delete my files?
A standard cleanup does not touch your documents. Ransomware and some aggressive infections may already have damaged files; we check what is recoverable before wiping anything.
My antivirus says the PC is clean but I still get pop-ups. Why?
The pop-ups are usually coming from browser notifications you allowed, or from an adware extension. Check site notification permissions in the browser and remove suspicious extensions.
Is Malwarebytes safe to use alongside Windows Defender?
Yes. Free Malwarebytes runs as an on-demand scanner and does not conflict with Defender. You do not need to pay for two real-time antivirus products — that causes conflicts.
How do I know if I have ransomware?
Your files gain unfamiliar extensions such as .locked or a random string, a text file with payment instructions appears on the desktop, and many programs stop opening.
Not sure what is on your computer?
We image the disk first, then remove the infection — so a bad scan can never cost you your files. Free diagnosis, fixed price.
Get the next guide by email
One practical computer or online-earning guide a month. No spam, unsubscribe anytime.