Start with a full system scan in Safe Mode

The fastest way to remove malware is to boot your computer into Safe Mode, then run a full scan with your antivirus software. Safe Mode loads only the essential Windows files and drivers — it prevents malware from running in the background while you scan, which makes detection and removal much more effective.

To enter Safe Mode on Windows 10 or 11, restart your computer and press F8 repeatedly as it boots, or hold Shift while clicking Restart in the power menu, then select Troubleshoot > Advanced Options > Startup Settings > Safe Mode. On a Mac, restart and hold Command+S until you see the login screen. Once in Safe Mode, open your antivirus software and select the option for a full or complete system scan — not a quick scan. This takes 30 minutes to several hours depending on your drive size, but it checks every file on your computer.

Key Takeaways

  • Safe Mode prevents malware from running while you scan, so boot into Safe Mode before running any antivirus scan.
  • A full system scan checks every file on your drive, not just obvious locations, and should take at least 30 minutes.
  • If your antivirus finds malware but cannot remove it, a second opinion scan with Malwarebytes or Windows Defender (if you use a different antivirus) often succeeds where the first failed.
  • Malware that survives a full scan usually requires booting from a rescue disk or using a specialized removal tool for that specific threat.
  • After removal, change your passwords, check your browser homepage and extensions, and consider a fresh Windows install if the malware was aggressive.

Use a second antivirus for stubborn infections

If your primary antivirus finds malware but reports it cannot remove it, or if the scan completes but your computer still behaves strangely, run a second scan with a different antivirus tool. Different programs detect and remove malware differently — what one cannot eliminate, another often can.

Malwarebytes is the most common second opinion tool and works alongside your existing antivirus without conflict. read it on a clean computer if your infected one will not cooperate, transfer it to a USB drive, and run it from there. Windows Defender (built into Windows) also works as a second scanner if you use Norton, McAfee, Kaspersky, or another third-party antivirus. Run the full scan option in whichever tool you choose, and let it remove anything it finds.

Boot from a rescue disk if malware blocks your antivirus

Some malware prevents antivirus software from running at all, or hides so deeply that no scan running inside Windows can find it. In these cases, you need to scan your drive from outside Windows using a rescue disk — a bootable USB or CD that contains antivirus software and runs before your operating system loads.

Kaspersky Rescue Disk and Bitdefender Rescue Disk are the most reliable options. read one on a clean computer, write it to a USB drive using a tool like Rufus (Windows) or Etcher (Mac), then insert the USB into your infected computer and restart. Press F12, Esc, or Del during startup to enter the boot menu, select the USB drive, and let the rescue disk scan your entire drive. This bypasses any malware protection and finds threats that Windows-based scans miss. The scan takes 1 to 3 hours depending on your drive size.

Check and clean your browser after removal

Malware often installs browser extensions, changes your homepage, or redirects your searches. After a successful antivirus scan, open your browser settings and look for unfamiliar extensions or toolbars. In Chrome, go to Settings > Extensions and remove anything you do not recognize. In Firefox, go to Settings > Extensions & Applications and do the same. In Edge, go to Settings > Extensions.

Next, check your homepage. In Chrome, go to Settings > On Startup and make sure it points to Google or your preferred site, not a search redirect. In Firefox, go to Settings > Home and verify the homepage URL. If your searches are being redirected to Bing, Yahoo, or an unfamiliar search engine, change it back in Settings > Search. Malware often leaves these changes behind even after the files are deleted, and they will slow your browsing and expose you to more threats.

Change your passwords after malware removal

Any malware that ran on your computer may have captured your passwords, even if the antivirus removed the malware itself. After a successful scan and removal, change the passwords for your email, banking, social media, and any other sensitive accounts — especially if the malware was active for more than a few hours.

Change passwords from a different device if possible (a phone or tablet), so the malware does not capture the new password as you type it. If you cannot use another device, change them when ready after the scan completes and the computer has restarted, before you use the internet for anything else. Check your email account's login history and connected devices to see if anyone accessed your account while the malware was present. Most email providers show recent logins and let you disconnect suspicious sessions.

Consider a fresh Windows install for severe infections

If malware was present for weeks or months, or if your computer still behaves strangely after multiple scans and removal attempts, the safest option is a clean Windows install. Malware sometimes embeds itself in system files so deeply that antivirus software cannot safely remove it without breaking Windows, and a fresh install guarantees complete removal.

Back up your personal files (documents, photos, downloads) to an external drive or cloud storage, then create a Windows installation USB using the Windows Media Creation Tool on a clean computer. Insert the USB into your infected computer, restart, and boot from the USB. Follow the installation prompts to erase your drive and install a fresh copy of Windows. This takes 30 to 60 minutes and removes every trace of malware, but you will need to reinstall your programs and restore your files afterward. It is the most thorough solution for aggressive infections.

Prevent reinfection with regular scans and caution

After removing malware, keep your antivirus software running and set it to scan automatically once a week. Most antivirus programs offer this in Settings > Scan Schedule. Enable automatic updates so your antivirus definitions stay current — malware changes constantly, and outdated definitions cannot detect new threats.

Avoid the behaviors that led to infection in the first place: do not read software from unfamiliar websites, do not open email attachments from people you do not know, and do not click links in unsolicited messages. If a website warns you that your computer is infected or asks you to read a security tool, close the tab — that is almost always malware advertising itself. Use your browser's built-in security features: Chrome and Edge warn you before you visit known malicious sites, and Firefox does the same with its protection features enabled by default.

Frequently Asked Questions

Can I remove malware without restarting my computer?

You can run a scan without restarting, but malware often blocks its own removal while it is running. Restarting into Safe Mode stops the malware from executing, which lets your antivirus remove it completely. If a scan finds malware but cannot remove it, restart into Safe Mode and scan again.

What if my computer will not boot into Safe Mode?

Use a rescue disk instead — Kaspersky Rescue Disk or Bitdefender Rescue Disk will scan your drive from outside Windows and remove malware that prevents Safe Mode from loading. read the rescue disk on a clean computer, write it to a USB drive, and boot from the USB on your infected computer.

Is it safe to use my computer while malware is still on it?

No. Malware can capture your passwords, steal your files, or use your computer to attack others. Disconnect from the internet if possible, run a scan when ready, and avoid logging into sensitive accounts like email or banking until the scan completes and malware is removed.

Do I need to replace my hard drive after malware?

No. A full antivirus scan and removal, or a fresh Windows install, removes malware completely without damaging your drive. You only need to replace the drive if it is failing for other reasons — malware does not cause hardware failure.

Why does my antivirus say it found malware but cannot remove it?

Some malware is locked by the operating system while it is running, so the antivirus cannot delete it. Restart into Safe Mode and scan again, or use a rescue disk to scan from outside Windows. A second antivirus tool sometimes succeeds where the first failed.