Malware removal fails most often because people skip steps or run tools in the wrong order. The sequence below matters as much as the tools.
Different symptoms point to different families, and they need different handling:
| Symptom | Likely type | Notes |
|---|---|---|
| Browser homepage/search changed | Browser hijacker / PUP | Often bundled with "free" software |
| Ads on every site, even ones that don't run ads | Adware / browser extension | Check extensions first — very common |
| Files encrypted, ransom note | Ransomware | Stop immediately. Disconnect from network and do not pay |
| Constant CPU use, fan always loud | Cryptominer | Often hidden as a "system helper" |
| Antivirus disabled or greying out | Rootkit / advanced threat | May require booting from external media |
| Pop-ups pretending to be security alerts | Scareware / tech-support scam | Do not call any number shown |
Before anything else, cut the internet connection. This stops data exfiltration, halts command-and-control communication, and prevents ransomware from reaching network drives. For ransomware especially, this is urgent.
Safe Mode loads Windows with minimal drivers and no startup programs, which stops most malware from running — and therefore from defending itself while you remove it.
Hold Shift while selecting Restart, then navigate: Troubleshoot → Advanced options → Startup Settings → Restart → 4.
This is the single most commonly overlooked step. Many "virus" symptoms are actually a malicious extension with permissions to read and change data on every site.
Go through extensions in every browser you have installed and remove anything you do not recognise or no longer use. Be strict — a disabled extension is still worth deleting.
Sort installed programs by install date and work backwards. Anything you do not recognise — especially with vague names like "System Optimizer", "Web Helper", "Search Assistant" — is a candidate. Look up anything uncertain before removing it, but be decisive about obvious junk.
Built-in Windows Defender is genuinely good now, but for an active infection a dedicated second opinion helps. Run a full scan, not a quick scan — quick scans check common locations and frequently miss things.
After the first scan, reboot and scan again. Malware often has multiple components; removing one triggers another to reinstall it. Repeat until two consecutive scans come back clean.
Malware rarely arrives by chance. The common entry points, in order:
Reinstall Windows when: the machine will not boot properly, malware returns immediately after every clean, a rootkit is suspected, or antivirus cannot stay enabled. A clean install takes an hour and gives certainty that removal does not. Back up your personal files first, and remember that documents can carry macro-based malware — scan the backup before restoring.
See Malwarebytes options →Check current protection plans · Affiliate link — we may earn a commission at no extra cost to you.