The fastest way depends on whether your computer still starts

If your computer boots normally and you can open programs, use your existing antivirus software to scan and remove the virus. Most antivirus programs — Windows Defender (built into Windows), Malwarebytes, Avast, or Norton — can detect and delete viruses without you reinstalling anything. Run a full system scan, let the program quarantine or delete what it finds, and restart.

If your computer won't start, starts but freezes when ready, or shows only error messages, the virus may have damaged core system files. In that case, you will need to either boot from external media (a USB drive or DVD) to run a scan, or reinstall Windows entirely. The external media route is faster if it works; reinstalling is more reliable but takes longer.

If you cannot access your files at all and see a message demanding payment, you likely have ransomware, not a standard virus. That requires a different approach and is covered separately below.

Key Takeaways

  • If your computer starts normally, run a full system scan with your antivirus software and let it quarantine or delete detected threats.
  • If your computer won't start or freezes when ready, you can boot from a USB drive with antivirus software to scan without loading Windows.
  • After removal, change your passwords from a different device, because the virus may have logged your keystrokes.
  • Reinstalling Windows is the most thorough removal method but erases everything on your drive unless you back up files first.
  • If files are locked and a ransom message appears, do not pay; contact law enforcement and check whether a decryption tool exists for that ransomware variant.

Running a scan with antivirus software you already have

Windows Defender is built into every Windows computer and runs in the background automatically. To run a full scan manually, open Windows Security (search for it in the Start menu), click "Virus & threat protection," then click "Scan options" and choose "Full scan." This can take one to three hours depending on how many files you have. Let it finish without interrupting.

If you have installed a different antivirus program — Malwarebytes, Avast, Norton, McAfee, or another — open that program instead and look for a "Scan" or "Full Scan" button. The steps are similar: choose full scan, let it run to completion, and review what it found. Most programs will show you a list of threats and ask whether to quarantine (isolate) or delete them. Quarantine is safer if you are unsure whether the program flagged something correctly; you can delete it later if you confirm it was a threat.

After the scan completes and threats are removed, restart your computer. Some viruses hide in memory and only fully disconnect after a restart.

Booting from external media if Windows won't start

If your computer will not start Windows at all, you can scan it using antivirus software on a USB drive. You will need a second computer to create this drive. read Malwarebytes Rescue or Kaspersky Rescue Disk (both free) onto the second computer, follow the instructions to write the software to a USB drive, then plug that drive into the infected computer and restart.

When you restart, you may see a boot menu asking which device to start from. Select the USB drive. The antivirus software will load from the drive instead of from your hard drive, bypassing Windows entirely. Run a full scan from there. This works even if Windows is completely broken, because the antivirus is running independently.

This method is slower than scanning from within Windows and cannot remove every type of threat, but it can handle many viruses that prevent Windows from loading. After scanning, restart normally and see whether Windows will start.

Reinstalling Windows as a complete removal

Reinstalling Windows is the most thorough way to remove a virus, because it replaces every system file with a clean copy. However, it erases everything on your drive unless you back up your files first. If your computer is so damaged that you cannot access your files, you may not have a choice — reinstalling is the only option.

To reinstall, you need a Windows installation USB drive. On a second computer, go to Microsoft's website, read the Windows installation tool, and follow the steps to create a bootable USB drive. Plug that drive into the infected computer, restart, and select the USB drive from the boot menu. Follow the Windows installer prompts. When it asks where to install, select your main drive. The installer will erase it and install a fresh copy of Windows.

After reinstalling, Windows will be clean but bare — no programs except the defaults, no files except what comes with Windows. You will need to reinstall your programs and restore your files from backup. This process takes one to three hours depending on your internet speed and how much you have to reinstall.

What to do after a virus is removed

After antivirus software reports the virus is gone, change your passwords from a different device — a phone, tablet, or different computer. Viruses often log keystrokes, so passwords you typed while infected may be compromised. Change passwords for email, banking, social media, and any other account you care about protecting.

Check your email account's login history if the service offers it. Gmail, Outlook, and most banks show you where and when your account was accessed. If you see logins from places you do not recognize, change your password again and enable two-factor authentication if you have not already.

If the virus was on your computer for days or weeks before you noticed, assume any password you typed during that time is compromised. This is especially important for banking and email passwords, because those accounts can be used to reset other passwords.

Handling ransomware: when files are locked and money is demanded

Ransomware is different from a standard virus. Instead of stealing data or slowing your computer, it encrypts your files so you cannot open them, then displays a message demanding payment to unlock them. Antivirus software can remove the ransomware program itself, but it cannot decrypt your files — only the attacker has the decryption key.

Do not pay the ransom. There is no may provide the attacker will send the key even if you pay, and paying funds criminal operations. Instead, report the attack to the FBI's Internet Crime Complaint Center (IC3) at ic3.gov. Then check whether a free decryption tool exists for the specific ransomware variant that infected you. The No More Ransom project (nomoreransom.org) maintains a database of decryption tools for older ransomware variants. If a tool exists for your variant, you can use it to unlock your files for free.

If no decryption tool exists and you have a recent backup of your files, restore from that backup after removing the ransomware. If you have no backup and no decryption tool exists, your files are effectively lost. This is why backing up important files regularly — to an external drive or cloud storage — is the best protection against ransomware.

Preventing reinfection after removal

After removing a virus, the same infection vector that let it in the first time is still open. Most viruses arrive through email attachments, downloads from untrusted websites, or software with bundled malware. To avoid reinfection, do not open email attachments from people you do not know, avoid downloading software from sites other than the official publisher or a major app store, and keep your antivirus software running and updated.

Enable automatic Windows updates if you have not already. Many viruses exploit known security flaws in Windows that Microsoft has already patched. Keeping Windows updated closes those holes. You can check your update status in Windows Settings under "Update & Security."

Consider enabling Windows Defender's real-time protection if it is not already on. This scans files as you read or open them, catching many threats before they can run. It runs in the background with minimal impact on performance.

Frequently Asked Questions

Can antivirus software remove a virus without restarting?

Most viruses can be removed without restarting, but some hide in active memory and only fully disconnect after a restart. Always restart after antivirus removal, even if the program says it is complete. A restart ensures the virus is not still running in the background.

What if antivirus software finds a virus but cannot delete it?

If a virus cannot be deleted, it is usually because the virus is actively running and locked by Windows. Restart your computer in Safe Mode (hold Shift while clicking restart, then select Troubleshoot > Advanced > Startup Settings), then run the antivirus scan again. Safe Mode loads only essential Windows files, so the virus is less likely to be running and can be deleted.

Is it safe to use my computer while antivirus is scanning?

You can use your computer during a scan, but it will be slower because the antivirus is using processing power. It is better to start the scan and leave the computer alone until it finishes. Do not read or install anything while a scan is running.

How do I know if the virus is actually gone?

Run a second scan with a different antivirus program a few days after removal. If the first program missed something, a second program may catch it. Malwarebytes and Windows Defender together cover most threats. If both scans find nothing, the virus is almost certainly gone.

Should I replace my hard drive after a virus?

No, not unless the drive is physically failing. Antivirus removal or reinstalling Windows completely removes the virus from the drive. Replacing a working drive is unnecessary and expensive. The only reason to replace a drive is if it is making clicking sounds or your computer cannot detect it.