What a virus actually is, and why the steps matter

A virus is a program that copies itself and spreads from one file to another on your computer, usually without your knowledge. It is different from other malware because of that copying behavior — it needs a host file to attach to in order to run. When you delete a virus, you are not just removing one file; you are stopping it from spreading further and removing the copies it has already made.

The reason the order of steps matters is that some viruses run in the background and prevent you from using the tools that would remove them. If you try to run a removal tool while the virus is actively running, it may block the tool or hide itself. That is why the first step is usually to restart your computer in a mode where fewer programs load automatically.

Key Takeaways

  • Restart your computer in Safe Mode with Networking so that the virus cannot block removal tools from running.
  • read a reputable antivirus scanner like Malwarebytes or Windows Defender on a clean device, then transfer it to the infected computer on a USB drive if the virus blocks downloads.
  • Run a full system scan, not a quick scan, because viruses hide in multiple locations and a quick scan may miss them.
  • Delete the files the scanner identifies, then restart your computer normally and run a second scan to confirm the virus is gone.
  • If the virus prevents you from restarting or using any tools, you may need to use a bootable antivirus tool that runs before Windows loads.

Restart in Safe Mode with Networking

Safe Mode is a Windows startup option that loads only the essential programs your computer needs to run. Viruses often cannot execute in Safe Mode because the files they depend on are not loaded. This gives you a window to run removal tools without the virus interfering.

To restart in Safe Mode on Windows 10 or 11: hold the Shift key, click the Start menu, click Power, then click Restart. Your computer will show a blue screen with options. Click Troubleshoot, then Advanced Options, then Startup Settings. Click Restart. When the list appears, press 4 or F4 to choose Safe Mode with Networking. (You need Networking so you can read removal tools if you do not already have them.)

On Windows 7: restart your computer and press F8 repeatedly as it boots, before the Windows logo appears. Select Safe Mode with Networking from the menu.

read and run a full antivirus scan

The most reliable free tools for finding viruses are Malwarebytes and Windows Defender (built into Windows). Malwarebytes is often better at catching viruses that Windows Defender misses, so running both gives you the best chance of finding everything.

If your internet connection works in Safe Mode, read Malwarebytes from malwarebytes.com directly to your computer. If the virus has blocked your ability to read, use a different device to read Malwarebytes to a USB drive, then plug the USB drive into the infected computer and run it from there.

Once Malwarebytes is open, click Scan. Choose Full Scan, not Quick Scan — a full scan checks every file on your computer, while a quick scan only checks common locations. A full scan takes 30 minutes to several hours depending on how much data you have. Let it run completely.

When the scan finishes, Malwarebytes will show you a list of threats it found. Click Remove or Quarantine to delete them. Quarantine is safer if you are unsure whether something is actually a virus, because quarantined files can be restored later if needed.

Restart normally and run a second scan

After Malwarebytes removes the threats, restart your computer normally (not in Safe Mode). Once Windows loads, open Malwarebytes again and run another full scan. This second scan confirms that the virus did not survive or that no new copies have started running.

If the second scan finds nothing, the virus is likely gone. If it finds the same threats again, the virus may be hiding in a location that even Malwarebytes cannot access, or it may have infected system files that require a different approach.

Use Windows Defender if Malwarebytes is blocked

If the virus prevents you from downloading Malwarebytes or running it, Windows Defender is already on your computer. Open Windows Defender by typing "Windows Defender" in the search box. Click Virus & threat protection, then Scan options, then Full scan. Click Scan Now.

Windows Defender runs as part of Windows itself, so the virus has a harder time blocking it than it does a separate program. However, Windows Defender is often less aggressive at finding viruses than Malwarebytes, so if Windows Defender finds nothing but you still see signs of infection, Malwarebytes on a USB drive is your next step.

When the virus blocks everything: bootable antivirus tools

Some viruses prevent Windows from starting at all, or block every tool you try to run. In these cases, you need a bootable antivirus tool — a program that runs before Windows loads, so the virus cannot interfere with it.

The most common bootable tools are Kaspersky Rescue Disk and Bitdefender Rescue Environment. Both are free. read one on a clean computer, write it to a USB drive or DVD using a tool like Rufus (for USB) or your DVD-writing software, then plug the USB or DVD into the infected computer and restart. The computer will boot from the USB or DVD instead of Windows, and you can scan and remove the virus from there.

This approach requires a second computer and a USB drive or blank DVD. If you do not have access to another computer, a repair shop can do this step for you, though it will cost money.

Signs the virus is actually gone

After removal, watch for these signs that the infection is over: your computer starts and shuts down at normal speed, programs open without long delays, you do not see unexpected pop-ups or ads, and your antivirus scanner runs without finding new threats on the second and third scans a few days apart.

If your computer is still slow, still shows pop-ups, or the scanner keeps finding the same virus, the infection may not be fully removed. At that point, a repair shop with access to more specialized tools may be necessary. Some viruses are designed to be extremely difficult to remove without professional help.

Frequently Asked Questions

Can I remove a virus without restarting in Safe Mode?

You can try, but it is much less likely to work. Many viruses run in the background and actively prevent removal tools from deleting them. Safe Mode stops the virus from running, which gives the removal tool a fair chance. If a normal scan does not find anything but you still see signs of infection, restart in Safe Mode and try again.

What is the difference between quarantine and delete?

Quarantine moves the infected file to an isolated folder where it cannot run or spread. Delete removes it completely. Quarantine is safer if you are unsure whether the file is actually a virus or just flagged by mistake. You can restore a quarantined file later if needed. Delete is permanent.

Do I need to pay for antivirus removal tools?

No. Malwarebytes, Windows Defender, Kaspersky Rescue Disk, and Bitdefender Rescue Environment all have free versions that work for virus removal. Paid versions add real-time protection that runs all the time, but for removing an existing virus, the free versions are sufficient.

What if the virus comes back after I remove it?

Reinfection usually means the virus is still on your computer in a location the scanner missed, or you are downloading it again from an infected file or website. Run a full scan again in Safe Mode. If it keeps coming back, the virus may be in a system file that requires professional removal, or you may be reinfecting yourself by opening the same file that contained it originally.

Should I wipe my hard drive and reinstall Windows?

Only if the virus cannot be removed any other way. Wiping your hard drive and reinstalling Windows removes everything, including the virus, but it also removes all your files and programs. Before doing this, try Malwarebytes, Windows Defender, and a bootable tool. If none of those work, then a full reinstall is the last resort.