Virus & Malware Removal · 9 min read
Malware Removal Guide: A Complete Step-by-Step Process
This is the full removal process, in the order that works. Skipping steps is what causes an infection to come back a day later.
Published 2026-08-09 · Last updated 2026-08-09
Step 1 — Disconnect and stop making it worse
Disconnect from the network if you suspect an active infostealer or ransomware. Stop logging into accounts from the machine, and do not enter payment details on it until it is clean.
Step 2 — Back up your data, not your programs
Copy documents, photos and other irreplaceable files to external storage before removal work begins, and keep that copy offline afterwards. Do not back up executables or installers from the infected machine.
Step 3 — Boot into safe mode with networking
Safe mode prevents most malicious components from starting, which makes them far easier to delete. Hold Shift while selecting Restart, then choose Troubleshoot, Advanced options, Startup Settings, Restart, and press the safe mode with networking option.
Step 4 — Run a full scan, then an offline scan
Run a full scan with your resident antivirus. Then run Microsoft Defender Offline, which restarts the PC and scans before Windows loads — this catches persistent items that cannot be touched while running.
Step 5 — Run a second-opinion on-demand scanner
One engine is not enough for adware and potentially unwanted programs. An on-demand scanner such as the free Malwarebytes build finds items resident suites deliberately tolerate. Never leave two resident engines installed afterwards.
Step 6 — Clean startup entries, tasks and the browser
Review Task Manager's Startup tab, scheduled tasks, installed programs sorted by install date, and every browser extension and profile. Reset the browser and re-check that search engine and homepage settings stay changed.
Step 7 — Patch, then change passwords from a clean device
Install pending Windows and browser updates, then change passwords for email, banking and any account used on the machine — from a different, known-clean device. Enable two-factor authentication where it is offered.
When to stop and reinstall Windows
If the same detection returns after two full cleaning passes, if security software cannot be reinstalled, or if the machine was used for banking during an infostealer infection, a clean Windows installation is faster and safer than continued cleanup.
Frequently asked questions
- How long does malware removal take?
- Plan on two to four hours including full scans. The scans dominate the time; the manual cleanup is usually under thirty minutes.
- Do I need to pay for removal software?
- Usually not. Microsoft Defender Offline plus a free on-demand scanner handles most consumer infections.