Common causes
- Downloading cracked software, key generators, or game cheats, which are a common way trojans and password stealers reach home PCs.
- Opening attachments or links in phishing emails that impersonate delivery companies, banks, or Microsoft support.
- Installing free software from download sites that bundle adware and potentially unwanted programs into their installers.
- Clicking fake download buttons, fake browser update prompts, or 'your PC is infected' pop-ups on compromised or ad-heavy websites.
- Running outdated versions of Windows, browsers, or apps with known security holes that attackers can exploit automatically.
- Allowing a malicious browser extension or site notification permission that later injects ads or redirects searches.
- Plugging in USB drives or opening files shared from another computer that is already infected.
- Turning off Microsoft Defender or letting a third-party antivirus subscription expire, leaving the PC without active real-time protection.
Advertisement
Step-by-step fixes
Step 1
Disconnect from the internet and stop signing in
If you see signs of an active infection, such as a ransom note, the mouse moving on its own, remote-access software you didn't install, or unexpected password-reset emails, disconnect right away. Turn on Airplane mode from Quick Settings (press Windows key + A) or unplug the Ethernet cable. This cuts off any remote control and stops more data from leaving the PC. Don't sign in to email, banking, or other accounts on this computer until it's clean, because some malware records keystrokes and steals saved browser sessions. When you need to download updates or a scanner, reconnect only briefly, or download the tool on another device and copy it across on a USB drive. Success looks like a PC that's offline and can't be reached by anyone else while you work.
Step 2
Update Microsoft Defender and run a Full scan
Open Windows Security from the Start menu, or go to Settings > Privacy & security > Windows Security in Windows 11 (Settings > Update & Security > Windows Security in Windows 10). Select Virus & threat protection, then Protection updates > Check for updates to download the latest security intelligence; reconnect briefly if needed. Go back, select Scan options, choose Full scan, and select Scan now. A full scan can take an hour or more on a large drive, so keep a laptop plugged in. When it finishes, open Protection history and make sure each detected threat shows as removed or quarantined, and take action on any that need it. If Windows Security says you're using another antivirus, run a full scan in that product instead. Success is a completed scan with no active threats remaining.
Step 3
Run a Microsoft Defender Offline scan
Some malware hides itself or blocks removal while Windows is running. The offline scan restarts the PC into a trusted environment and scans before Windows fully loads. Save your work, then in Windows Security go to Virus & threat protection > Scan options, select Microsoft Defender Antivirus (offline scan), which some versions call Microsoft Defender Offline scan, and select Scan now. The PC restarts, runs the scan, and boots back into Windows when it's done. Afterward, open Virus & threat protection > Protection history to see what was found and removed. If Windows Security won't open, you can start the same scan from an administrator PowerShell window by running Start-MpWDOScan. Success is a clean offline scan, or any detections listed as removed or quarantined in Protection history.
Advertisement
Step 4
Boot into Safe Mode with Networking and run a second-opinion scanner
Safe Mode loads only essential drivers and services, so most malware can't start and defend itself. In Windows 11, go to Settings > System > Recovery and select Restart now next to Advanced startup (Windows 10: Settings > Update & Security > Recovery). Choose Troubleshoot > Advanced options > Startup Settings > Restart, then press 5 or F5 for Safe Mode with Networking. You may be asked for your BitLocker recovery key, so find it in your Microsoft account beforehand. Download a second-opinion scanner from its official site, such as Malwarebytes or Emsisoft Emergency Kit, and run a full scan. If a tool won't run in Safe Mode, restart normally and run it there. Quarantine anything flagged as malware and review 'potentially unwanted' items before removing them. Success is a second tool that finds nothing further.
Step 5
Remove suspicious apps, startup items, and scheduled tasks
Scanners don't always remove the program that brought the malware in. In Windows 11, open Settings > Apps > Installed apps and sort by Date installed (Windows 10: Settings > Apps > Apps & features, sorted by install date). Uninstall anything you don't recognize or didn't mean to install, especially system optimizers, driver updaters, PDF converters, and search tools that appeared around when problems started. Next, press Ctrl + Shift + Esc, open Startup apps (the Startup tab in Windows 10), and disable unfamiliar entries. Finally, open Task Scheduler, select Task Scheduler Library, and look for tasks with random-looking names that run files from AppData or Temp folders, or run PowerShell scripts. Search a task's name online before deleting it, and leave Microsoft's tasks alone. Success is a startup list you recognize entry by entry.
Step 6
Remove unknown browser extensions and reset your browsers
Malware often leaves behind browser extensions, a changed search engine, notification spam, and forced policies. In Chrome, open chrome://extensions and remove anything you don't recognize, then go to Settings > Reset settings > Restore settings to their original defaults. In Edge, use edge://extensions, then Settings > Reset settings > Restore settings to their default values. In Firefox, open about:support and select Refresh Firefox. These resets keep bookmarks and saved passwords but restore your startup page and search engine and disable or remove extensions. Also review each browser's site notification permissions and remove any sites you don't trust. If a browser says it's 'managed by your organization' on a personal PC, follow our browser hijacker guide to remove the policies. Success is a browser that opens to your chosen homepage and search engine.
Step 7
Change your passwords from a clean device
If the malware could have seen what you typed or copied saved browser data, treat your passwords and signed-in sessions as exposed. Use a different device you trust, such as your phone or another computer, and change your email password first, because email controls password resets for everything else. Then change banking, shopping, social media, and password manager passwords. Use each service's option to sign out of all devices, turn on two-factor authentication with an authenticator app or passkey where available, and check your email settings for forwarding rules or recovery details you didn't add. Watch bank and card statements for unfamiliar charges. Success is every important account secured with a new, unique password and two-factor sign-in, with old sessions ended.
Step 8
Reset Windows if the infection keeps coming back
Warning: a reset removes your installed apps and, with Remove everything, your files, so back up first. If malware returns after cleanup, scanners keep finding new detections, or the infection involved ransomware, remote-access tools, or a rootkit, a reset is the safest way to be sure. Copy only personal files, such as documents and photos, to an external drive, not programs or installers, and scan that drive before reusing it. In Windows 11, go to Settings > System > Recovery > Reset PC (Windows 10: Settings > Update & Security > Recovery > Reset this PC > Get started). Choose Remove everything, then Cloud download for a fresh copy of Windows. Afterward, install all updates, confirm Defender is on, and reinstall apps from official sources. Success is a clean PC that stays clean.
How to prevent it
- Keep Windows, your browser, and your apps updated, and leave Microsoft Defender or your chosen antivirus running with real-time protection on.
- Download software only from official vendor sites or the Microsoft Store, and never install cracked software, key generators, or game cheats.
- Turn on Potentially unwanted app blocking in Windows Security > App & browser control > Reputation-based protection settings.
- Use a password manager, unique passwords, and two-factor authentication so one stolen password can't unlock your other accounts.
- Keep a regular backup on an external drive or cloud service that isn't permanently connected, so ransomware can't encrypt it too.
Tools that can help
Microsoft Defender's full and offline scans are free and remove most common infections, so start there. A second-opinion scanner is worth adding when Defender comes up clean but symptoms continue, or when adware and unwanted programs keep coming back.
Best for cleanup
Malwarebytes
The free Malwarebytes scanner is a strong second opinion for malware, adware, and unwanted programs, while Premium adds real-time, ransomware, and web protection that can run alongside Microsoft Defender.
Visit MalwarebytesTop pick
Bitdefender
Bitdefender combines top-tier malware and ransomware protection with web filtering across browsers and a secure banking browser, with extras such as unlimited VPN and identity monitoring on higher tiers.
Visit BitdefenderBest portable scanner
Emsisoft Emergency Kit
A free, portable dual-engine scanner that runs from a folder or USB drive without installation, which helps when malware blocks installers or your regular antivirus.
Get Emsisoft Emergency KitTechyLeakz may earn a commission if you buy through these links, at no extra cost to you. Affiliate disclosure
What to do next if this fails
- Move to the next fix instead of repeating the same step multiple times.
- Check the related guides in this cluster before attempting a full reset.
- If startup, update, and corruption symptoms overlap, widen the diagnosis instead of treating one error in isolation.
Advertisement
FAQ
Can Microsoft Defender remove malware on its own?
In many cases, yes. A full scan followed by a Microsoft Defender Offline scan removes most common malware. A second-opinion scanner is still worth running because no single engine catches everything, and tools like Malwarebytes and AdwCleaner are especially good at adware and unwanted programs. If Defender keeps finding the same threat after removal, something is reinstalling it, usually a startup item, scheduled task, or leftover program.
How do I know if my PC has malware?
Common signs include new toolbars, extensions, or a changed search engine; pop-up ads when no browser is open; programs you didn't install; antivirus that has been switched off; heavy CPU, disk, or network activity while the PC is idle; friends receiving messages you didn't send; and password-reset emails you didn't request. One sign alone proves little, but several together are a strong reason to scan.
Should I call the number in a pop-up that says my PC is infected?
No. Browser pop-ups that claim your PC is infected, lock the screen, or show a Microsoft support number are tech support scams, and Microsoft doesn't put phone numbers in error messages. If the browser won't close, press Ctrl + Shift + Esc, select it, and choose End task. Don't install anything the page suggests or let a caller connect remotely. If you already did, follow every step in this guide.
Will resetting Windows remove all malware?
A reset with Remove everything and Cloud download reinstalls Windows from scratch and removes almost all malware, including persistent infections that survive scans. Keep my files is less thorough, because files in your user folders stay. The main risk afterward is reinfection from your backup, so restore only personal documents and photos, scan them first, and don't reinstall programs from the same questionable source.
Do I need Safe Mode to remove malware?
Not always. Many infections come off with a normal full scan and a Microsoft Defender Offline scan. Safe Mode helps when malware restarts itself, blocks your scanner, or stops files from being deleted, because it loads only essential Windows components. If you use BitLocker or device encryption, have your recovery key ready before entering Safe Mode, since Windows may ask for it.
What should I do if ransomware has encrypted my files?
Disconnect the PC from the network immediately and unplug any backup drives. Don't pay the ransom; it funds criminals and doesn't guarantee you'll get files back. Note the details in the ransom message, then check the No More Ransom project and Emsisoft's free decryptors for a matching tool. Afterward, reset Windows with Remove everything, restore files from a clean backup, and change passwords from another device.