Security Guide

How to Remove Malware from Windows in 2026 (Step by Step)

By Aqui Tem Achadinhos Editorial · Updated September 20, 2026
How to Remove Malware from Windows in 2026 (Step by Step)

Malware removal fails most often because people skip steps or run tools in the wrong order. The sequence below matters as much as the tools.

Step 1: identify the infection type

Different symptoms point to different families, and they need different handling:

SymptomLikely typeNotes
Browser homepage/search changedBrowser hijacker / PUPOften bundled with "free" software
Ads on every site, even ones that don't run adsAdware / browser extensionCheck extensions first — very common
Files encrypted, ransom noteRansomwareStop immediately. Disconnect from network and do not pay
Constant CPU use, fan always loudCryptominerOften hidden as a "system helper"
Antivirus disabled or greying outRootkit / advanced threatMay require booting from external media
Pop-ups pretending to be security alertsScareware / tech-support scamDo not call any number shown

Step 2: disconnect from the network

Before anything else, cut the internet connection. This stops data exfiltration, halts command-and-control communication, and prevents ransomware from reaching network drives. For ransomware especially, this is urgent.

Step 3: boot into Safe Mode

Safe Mode loads Windows with minimal drivers and no startup programs, which stops most malware from running — and therefore from defending itself while you remove it.

Hold Shift while selecting Restart, then navigate: Troubleshoot → Advanced options → Startup Settings → Restart → 4.

Step 4: remove suspicious browser extensions first

This is the single most commonly overlooked step. Many "virus" symptoms are actually a malicious extension with permissions to read and change data on every site.

Go through extensions in every browser you have installed and remove anything you do not recognise or no longer use. Be strict — a disabled extension is still worth deleting.

Step 5: uninstall unknown programs

Sort installed programs by install date and work backwards. Anything you do not recognise — especially with vague names like "System Optimizer", "Web Helper", "Search Assistant" — is a candidate. Look up anything uncertain before removing it, but be decisive about obvious junk.

Step 6: run a reputable scanner

Built-in Windows Defender is genuinely good now, but for an active infection a dedicated second opinion helps. Run a full scan, not a quick scan — quick scans check common locations and frequently miss things.

After the first scan, reboot and scan again. Malware often has multiple components; removing one triggers another to reinstall it. Repeat until two consecutive scans come back clean.

⚠️ What not to do

Step 7: fix the entry point

Malware rarely arrives by chance. The common entry points, in order:

  1. Unpatched software — especially the browser, Windows Update and anything with a known CVE. Patch everything, including rarely-updated utilities like PDF readers and media players.
  2. Bundled installers — "custom install" screens hiding pre-ticked boxes. Always choose custom and decline extras.
  3. Phishing links and attachments — the single most common delivery route for serious infections.
  4. Pirated software and "key generators" — a reliable infection vector, no exceptions.

When to stop trying and reinstall

Reinstall Windows when: the machine will not boot properly, malware returns immediately after every clean, a rootkit is suspected, or antivirus cannot stay enabled. A clean install takes an hour and gives certainty that removal does not. Back up your personal files first, and remember that documents can carry macro-based malware — scan the backup before restoring.

See Malwarebytes options →

Check current protection plans · Affiliate link — we may earn a commission at no extra cost to you.