A computer that suddenly becomes slow, displays constant pop-ups, redirects searches, or opens unfamiliar programs may be infected with malware. The problem can be frightening, particularly when the device contains personal photographs, work documents, saved passwords, or financial information. Acting calmly and following the right sequence can reduce further damage.
Malware is a broad term for malicious software designed to disrupt a computer, steal information, gain unauthorized access, or perform unwanted actions. It includes computer viruses, spyware, adware, ransomware, worms, Trojan programs, browser hijackers, keyloggers, and other harmful code. Different infections require different levels of cleanup and recovery.
Not every slow computer or browser pop-up proves that malware is present. Performance problems can also come from limited storage, damaged software, excessive startup programs, browser notification permissions, or outdated hardware. However, unexpected security warnings, disabled protection, unknown applications, and unauthorized account activity should always be investigated.
This guide explains how to remove malware from a computer using safe, practical steps for Windows PCs and Macs. It covers device isolation, malware scans, suspicious program removal, browser cleanup, password protection, data recovery, factory resets, ransomware response, and effective ways to prevent another computer infection.
Common Signs That Your Computer May Have Malware
One warning sign is an unexpected decline in performance. The computer may take much longer to start, programs may freeze repeatedly, or the fan may run heavily when you are not completing demanding work. Malware can consume processor, memory, storage, or network resources while operating silently in the background.
Unwanted browser activity is another common symptom. New tabs may open automatically, searches may redirect to unfamiliar websites, advertisements may appear outside normal webpages, or unknown extensions may return after being deleted. Google identifies persistent pop-ups, unwanted toolbars, recurring extensions, and fake virus messages as possible signs of unsafe software.
You may also notice unfamiliar applications, changed system settings, or disabled security features. Some infections attempt to prevent antivirus software from opening, change the browser homepage, alter proxy settings, or add programs that start automatically. These changes can allow the malware to remain active after the computer restarts.
More serious warning signs include unauthorized payments, password-reset emails you did not request, messages sent from your accounts, encrypted files, or a ransom demand. These symptoms may indicate credential theft, spyware, or ransomware rather than simple adware. Disconnect the device and treat the situation as a possible security incident.
Step 1: Disconnect the Infected Computer from the Internet
Disconnect the computer from Wi-Fi, Ethernet, Bluetooth, and any shared network as soon as you reasonably suspect a serious infection. Isolation can prevent some malware from communicating with its operator, downloading additional components, sending stolen information, or spreading to other devices on the same network.
For Wi-Fi, use the computer’s network menu to turn off the connection. For a wired connection, remove the Ethernet cable. Also disconnect external storage devices, shared drives, and network-attached backups that do not need to remain connected, especially when files are being renamed, encrypted, or deleted unexpectedly.
CISA recommends immediately isolating systems affected by ransomware to help limit movement and further damage. If several business devices appear affected, an organization may need to isolate larger parts of the network rather than handling each computer individually.
Do not continue signing in to email, banking, social media, or business platforms from the infected computer. Use a known-clean phone or another trusted device for urgent communication. Disconnecting the internet does not remove malware, but it creates a safer environment in which to assess and clean the computer.
Step 2: Record What Happened Before Starting Cleanup
Write down the symptoms, approximate time they began, and anything unusual that happened beforehand. This might include opening an attachment, installing free software, downloading a cracked program, allowing a browser notification, connecting an unknown USB drive, or responding to a fake technical-support warning.
Take photographs of ransom messages, antivirus alerts, suspicious filenames, payment instructions, or unusual account activity when it is safe to do so. Avoid repeatedly opening unknown files merely to collect evidence. A photograph taken with a separate phone may be safer than creating screenshots on a heavily compromised device.
This information can help identify the likely infection source and determine whether professional assistance is necessary. It is especially valuable when the computer belongs to an employer, contains regulated information, or may be part of a wider attack. Business users should contact their IT or security team before deleting files or reinstalling the operating system.
Do not contact telephone numbers displayed in unexpected virus pop-ups. Legitimate security alerts generally do not pressure users to call an unknown technician, provide remote access, purchase gift cards, or transfer cryptocurrency. Close the browser when possible and begin cleanup through trusted operating-system tools.
Step 3: Back Up Important Personal Files Carefully
Before performing a factory reset or complete operating-system reinstallation, consider whether you need to preserve documents, photographs, videos, or other irreplaceable files. Copying data can reduce the risk of permanent loss, but an infected backup can also carry unsafe files into the cleaned computer.
Back up personal data rather than copying every program and system folder. Avoid unknown installers, cracked applications, script files, suspicious archives, and files that appeared around the time of infection. Documents containing macros or embedded code should be treated cautiously and scanned before being opened again.
Use a clean external drive only for the files you genuinely need. Disconnect it after copying the data so it is not continuously exposed to ransomware or other malware. After the computer has been cleaned, scan the backup with updated security software before restoring anything to the system.
Apple warns that restoring an entire backup after suspected malicious tampering may reinstall the software you were trying to remove. For serious or persistent infections, restoring selected personal files to a newly installed operating system can be safer than restoring the complete previous environment.
Step 4: Update Your Security Software and Operating System
A malware scanner works best when its security intelligence recognizes current threats. When possible, update the operating system, browser, and antivirus definitions before running the final scan. If reconnecting the infected computer seems unsafe, use a clean device to obtain recovery instructions or approved tools from official sources.
Only download security software from its developer’s official website or the operating system’s built-in application store. Fake antivirus tools are commonly promoted through frightening pop-ups and misleading advertisements. Never install a cleaner merely because an unknown webpage claims it has detected hundreds of viruses.
Modern versions of Windows include Microsoft Defender Antivirus within Windows Security, while macOS includes built-in protections such as XProtect. Apple states that XProtect receives threat-signature updates automatically and blocks the execution of known malware.
An updated operating system is also an important defense. Windows 10 reached the end of free security support on October 14, 2025, so computers still using an unsupported installation may no longer receive routine free security fixes. Moving to a supported system can reduce exposure to unpatched vulnerabilities.
Step 5: Run a Full Malware Scan on Windows
Open Windows Security, select Virus & threat protection, and review the current security status. Begin with a quick scan when you need an immediate check of common infection locations. A quick scan can identify many active threats, but it should not be the only scan when strong malware symptoms are present.
Next, open Scan options and select Full scan. A full antivirus scan examines more files, applications, and running areas of the computer than a quick scan, so it may take considerably longer. Keep the computer connected to power and avoid using it for banking or confidential work during the process.
Follow Microsoft Defender’s recommended action for every confirmed detection. The threat may be blocked, quarantined, or removed depending on its type and current status. Windows Security also provides Protection History, where users can review recent detections and the actions taken against them.
Do not restore a quarantined file simply because a program stops working without it. The application may have depended on the malicious component, or the file may genuinely be unsafe. Restore an item only when you have strong evidence of a false positive from a trusted developer or qualified security professional.
Step 6: Use Microsoft Defender Offline for Persistent Malware
Some malware attempts to hide while Windows is running or starts before normal antivirus processes can inspect it. Microsoft Defender Offline addresses this problem by restarting the computer and scanning from the Windows Recovery Environment, where many active threats have less opportunity to interfere.
Save all open files before starting because the computer will restart. In Windows Security, open Virus & threat protection, choose Scan options, select Microsoft Defender Offline scan, and begin the scan. The computer will restart automatically and return to Windows after the process finishes.
Microsoft explains that Defender Offline runs outside the usual Windows environment and can be useful when malware is persistent or difficult to remove during normal operation. After the computer restarts, review Protection History to see whether threats were found, quarantined, or removed.
Run another full scan after returning to Windows. A second scan helps confirm that the detected components are no longer present. When security tools continue reporting the same infection after removal, the malware may have a persistence mechanism or the system may require professional analysis or reinstallation.
Step 7: Start Windows in Safe Mode When Necessary
Safe Mode starts Windows with a limited collection of drivers and services. It can be helpful when a suspicious program launches automatically, prevents the antivirus tool from working, or makes normal Windows operation unstable. Safe Mode is a diagnostic environment rather than a complete malware-removal solution.
To enter it, open Windows Recovery Environment and select Troubleshoot, Advanced options, Startup Settings, and Restart. After the computer restarts, choose Safe Mode or Safe Mode with Networking only when internet access is genuinely required for a trusted update or support process.
Microsoft notes that if a problem does not occur in Safe Mode, basic Windows drivers and default services are less likely to be the cause. This can help you determine whether a third-party application, startup item, or service is contributing to the problem.
While in Safe Mode, uninstall clearly suspicious software, run a trusted malware scan, and review recently installed applications. Do not randomly delete files from Windows system folders or the registry. Removing the wrong component can prevent the computer from starting without actually eliminating the infection.
Step 8: Uninstall Suspicious Programs and Startup Items
Open the installed-apps list and sort applications by installation date when that option is available. Look for software installed immediately before the symptoms began, programs you do not remember approving, fake system optimizers, unknown download managers, or applications with misleading names and publishers.
Research an unfamiliar program from a separate clean device before removing it. Some legitimate hardware drivers, security components, and manufacturer utilities have names that ordinary users may not recognize. Deleting them without checking can disable essential functions or create additional system problems.
Review startup applications as well. A suspicious program that launches during sign-in may recreate browser settings, display advertisements, or reinstall extensions after every restart. Disable unknown entries first, restart the computer, and observe whether the behavior changes before permanently deleting uncertain components.
Use the application’s normal uninstaller or the operating system’s installed-app controls whenever possible. Avoid third-party registry cleaners and aggressive “one-click optimization” tools. They may delete unrelated settings, generate false warnings, or introduce additional unwanted software without addressing the actual infection.
Step 9: Remove Malware and Suspicious Apps from a Mac
Keep macOS updated so Apple’s built-in protections can receive current security improvements. macOS uses technologies including XProtect to detect and block known malicious software. If the system warns that an application will damage the computer or contains known malware, do not override the alert to force it open.
Delete the suspicious application and empty the Trash. Also inspect the Applications and Downloads folders for unfamiliar installers, fake updates, modified software, or items downloaded shortly before the symptoms began. Apple recommends obtaining applications from reliable sources and avoiding unlicensed or pirated software.
Review System Settings, General, and Login Items & Extensions. Remove unfamiliar applications from the items that open automatically, and disable questionable background permissions. Apple provides controls in this area for removing login items and managing software allowed to run in the background.
Restart the Mac and check whether the pop-ups, redirects, or unfamiliar processes return. Persistent symptoms may require a reputable security scan, professional help, or a clean macOS reinstallation. Avoid manually deleting protected system files based on unverified forum instructions.
Step 10: Clean the Browser and Remove Unwanted Extensions
Browser hijackers can change your homepage, default search engine, new-tab page, notification permissions, and extension list. Open the browser’s extensions or add-ons manager and remove anything you do not recognize, no longer use, or did not intentionally install.
Review site notification permissions because some alarming “virus warnings” are actually browser notifications from websites that were accidentally allowed. Remove permission for suspicious websites, block intrusive pop-ups, and clear browsing data if unwanted redirects or advertisements continue.
In Chrome, Google recommends removing problematic programs, checking site settings, and resetting browser settings when unwanted advertisements or malware-related behavior continues. Restoring the original defaults can undo changes to search, startup pages, and other browser settings without necessarily deleting bookmarks.
Synchronised browser data can sometimes restore an unwanted extension or setting to a cleaned computer. Review extensions and settings on other devices connected to the same browser account. When the problem repeatedly returns, temporarily disable synchronization until every connected browser has been checked.
Step 11: Check Whether the Malware Has Been Removed
Restart the computer normally and observe its behavior before returning to sensitive tasks. Confirm that unfamiliar pop-ups are gone, searches are no longer redirected, security software remains enabled, and unknown applications do not relaunch during startup.
Run another complete malware scan with updated definitions. A clean follow-up result is more reassuring than relying on the first removal message alone. Also review Windows Protection History or the reports provided by your trusted security application for unresolved or repeatedly detected threats.
Check the browser, startup applications, installed programs, and network settings again. If a deleted item has returned, a second component may be reinstalling it. Repeated reappearance is a strong sign that the infection has not been completely removed.
Monitor the computer for several days. Unusual processor usage, unauthorized account activity, disabled updates, and recurring security alerts may reveal ongoing compromise. Do not consider the problem resolved merely because the visible pop-up disappeared after one restart.
Step 12: Change Passwords and Secure Important Accounts
Assume that passwords entered while the computer was infected may have been exposed, especially when spyware, a keylogger, or an information-stealing Trojan is suspected. Change important credentials from a separate device that you know is clean rather than using the potentially compromised computer.
Begin with the primary email account because it can often be used to reset other passwords. Continue with banking, cloud storage, social media, shopping, business, cryptocurrency, and password-manager accounts. Use a unique password for every service instead of modifying one reused password.
Sign out of unfamiliar sessions and review recent account activity, recovery addresses, forwarding rules, linked applications, and trusted devices. Attackers sometimes retain access through an active session, additional recovery method, malicious email-forwarding rule, or authorized third-party application even after the password changes.
Enable multifactor authentication wherever possible. For high-value accounts, an authenticator application, security key, or passkey can provide stronger protection than a password alone. CISA incident-response guidance includes credential resets and secret rotation when account or system compromise is suspected.
Step 13: Check Financial and Personal Information
Review bank, card, shopping, and payment-service activity for transactions you do not recognize. Contact the relevant financial institution immediately when suspicious charges appear. Do not use contact information shown in a pop-up or unexpected message; use the number printed on the card or listed in the institution’s official application.
Check your email account for password-reset messages, security alerts, new forwarding rules, or deleted notifications. An attacker with mailbox access may hide evidence of purchases or account changes. Restore any altered security settings only after changing the email password from a clean device.
Businesses should determine whether customer, employee, or confidential company information may have been accessed. A malware incident involving regulated or sensitive data may trigger contractual, legal, insurance, or reporting requirements. Preserve relevant evidence and consult qualified security and legal professionals.
Continue monitoring important accounts after the computer appears clean. Stolen credentials may be used later rather than immediately. Fraud alerts, transaction notifications, and account-login warnings can provide early notice if someone attempts to misuse compromised information.
Step 14: Handle Ransomware Differently
Ransomware may encrypt documents, rename files, lock the screen, or display payment instructions. Disconnect the affected computer immediately and isolate connected drives or network shares. Do not continue opening files or restarting multiple systems without a response plan, as the incident may involve more than one device.
Take a photograph of the ransom note and record any extension added to encrypted filenames. This information can help qualified responders identify the ransomware family. Do not delete encrypted files simply because they cannot currently be opened; a legitimate recovery option may become available later.
For a workplace device, contact the organization’s security or IT team immediately. Home users can report the incident to their national cybercrime or law-enforcement authority. CISA’s ransomware guidance recommends identifying affected systems, isolating them, preserving information, and following an organized response and recovery process.
Do not trust anyone who guarantees file recovery after receiving cryptocurrency or remote access. Payment, recovery, insurance, and legal decisions can be complex, particularly for businesses. Seek advice from reputable incident-response professionals and relevant authorities before taking irreversible action.
Step 15: Reset or Reinstall the Operating System When Cleanup Fails
A factory reset or clean installation may be the safest option when malware repeatedly returns, security tools cannot run, system files appear altered, or the infection involved unauthorized administrative access. Reinstallation is also worth considering when you cannot confidently determine what the attacker changed.
Windows offers reset options that either preserve personal files while removing applications and settings or remove everything. For suspected persistent malware, a clean installation using official installation media is generally more thorough than simply keeping the existing environment. Microsoft specifically lists Windows reinstallation as a recovery option when infection is suspected.
Mac users can erase the startup disk and reinstall macOS through macOS Recovery. Apple provides separate procedures depending on whether the device uses Apple silicon, an Apple T2 Security Chip, or an older Intel configuration. Follow the instructions intended for the exact Mac model.
After reinstalling, apply all operating-system updates before restoring files. Reinstall applications from their official sources and copy back only scanned personal data. Avoid restoring questionable software, full system images, browser extensions, or installers connected to the original infection.
How to Prevent Malware from Returning
Keep the operating system, web browser, applications, router, and security software updated. Security patches correct vulnerabilities that attackers may use to install malware. Enable automatic updates where practical and remove old software that no longer receives support from its developer.
Download applications only from trusted publishers and official stores. Avoid pirated software, cracks, key generators, unofficial browser extensions, fake video codecs, and unexpected update prompts. Apple specifically advises users not to download unlicensed software and to use known, trusted sources.
Treat email attachments and links cautiously, even when they appear to come from someone you know. A compromised account can send believable malicious messages. Verify unexpected invoices, shared documents, password resets, and urgent payment requests through a separate communication channel.
Maintain regular offline or protected backups of important files. A useful backup should not remain permanently writable from the computer it protects. Test that files can be restored, and keep at least one copy separate from the main device so malware or ransomware cannot easily damage every version.
Common Malware-Removal Mistakes to Avoid
Do not install the first antivirus program promoted by an alarming pop-up. Fake security tools may exaggerate harmless issues, demand unnecessary payments, or install more malware. Navigate directly to the operating-system provider or a trusted security company rather than clicking the warning.
Avoid running several real-time antivirus products simultaneously. Competing security programs can conflict, reduce performance, generate confusing alerts, or interfere with one another’s quarantine processes. Use one main real-time protection system and only reputable on-demand tools when an additional assessment is necessary.
Do not delete random system files, registry entries, launch agents, or background processes merely because their names look unfamiliar. Modern operating systems contain many technical components. Removing the wrong item can damage Windows or macOS while leaving the malware’s actual persistence mechanism untouched.
Finally, do not assume that deleting the visible program completes the recovery. A proper cleanup includes follow-up scanning, browser inspection, password changes, account review, software updates, and continued monitoring. Malware removal is a process, not a single button.
When to Contact a Cybersecurity Professional
Seek professional help when the computer contains business records, customer information, medical data, financial documents, cryptocurrency wallets, or other highly sensitive material. The cost of an incomplete home cleanup may be much greater than the cost of qualified assistance.
Professional support is also appropriate when ransomware is involved, multiple devices are infected, antivirus tools cannot start, administrator accounts have changed, or the same threat returns after removal. These signs may indicate deeper persistence, stolen credentials, or network-level compromise.
Contact your organization’s IT team immediately when the infected device belongs to an employer or school. Do not independently wipe the computer unless instructed, because doing so may destroy evidence needed to investigate the incident and protect other users.
Choose a reputable provider with a clear business identity, written pricing, and a documented privacy process. Be cautious of unsolicited callers who claim to have detected an infection remotely. A legitimate technician should explain the proposed work and obtain informed permission before accessing personal files.
Final Thoughts on Removing Malware from a Computer
The first priorities after discovering malware are limiting further damage and protecting important information. Disconnect the affected computer, avoid entering more passwords, record the symptoms, and preserve essential files carefully before beginning destructive recovery steps.
Windows users should run an updated full scan and use Microsoft Defender Offline when the infection appears persistent. Mac users should install current security updates, respect built-in malware warnings, remove suspicious applications, and inspect login items and browser extensions.
After cleanup, change important passwords from a known-clean device, enable multifactor authentication, inspect financial activity, and continue monitoring the system. These steps are essential because removing the malicious file does not automatically reverse credential theft or unauthorized account access.
When the infection cannot be removed with confidence, erase or reinstall the operating system using official recovery tools. A careful clean installation, followed by selective restoration of scanned personal files, can provide a more trustworthy result than repeatedly fighting an infection that continues to return.
Frequently Asked Questions
1. Can I remove malware without paying for antivirus software?
Yes. Windows includes Microsoft Defender Antivirus and Microsoft Defender Offline, while macOS includes built-in malware protections. Keep the system updated and use only trusted security tools from official sources.
2. Does resetting a computer remove all malware?
A complete erase and clean operating-system installation can remove most conventional malware. However, restoring an infected backup or compromised application can reintroduce the threat, so restore files carefully.
3. Should I disconnect the internet when my computer has malware?
Yes, particularly when you suspect ransomware, spyware, credential theft, or active remote access. Disconnecting can limit communication, data theft, additional downloads, and spread to other network devices.
4. How long does a full malware scan take?
The time varies according to drive size, file count, hardware speed, and scan type. A full scan can take much longer than a quick scan, so keep the computer connected to power until it finishes.
5. Can malware steal passwords saved in my browser?
Some information-stealing malware can target credentials, browser sessions, cookies, and other stored account information. Change important passwords from a clean device and sign out of unfamiliar sessions after cleanup.


