Virus & Malware Removal · 9 min read

Malware Removal Guide: A Complete Step-by-Step Process

This is the full removal process, in the order that works. Skipping steps is what causes an infection to come back a day later.

Published 2026-08-09 · Last updated 2026-08-09

Step 1 — Disconnect and stop making it worse

Disconnect from the network if you suspect an active infostealer or ransomware. Stop logging into accounts from the machine, and do not enter payment details on it until it is clean.

Step 2 — Back up your data, not your programs

Copy documents, photos and other irreplaceable files to external storage before removal work begins, and keep that copy offline afterwards. Do not back up executables or installers from the infected machine.

Step 3 — Boot into safe mode with networking

Safe mode prevents most malicious components from starting, which makes them far easier to delete. Hold Shift while selecting Restart, then choose Troubleshoot, Advanced options, Startup Settings, Restart, and press the safe mode with networking option.

Step 4 — Run a full scan, then an offline scan

Run a full scan with your resident antivirus. Then run Microsoft Defender Offline, which restarts the PC and scans before Windows loads — this catches persistent items that cannot be touched while running.

Step 5 — Run a second-opinion on-demand scanner

One engine is not enough for adware and potentially unwanted programs. An on-demand scanner such as the free Malwarebytes build finds items resident suites deliberately tolerate. Never leave two resident engines installed afterwards.

Step 6 — Clean startup entries, tasks and the browser

Review Task Manager's Startup tab, scheduled tasks, installed programs sorted by install date, and every browser extension and profile. Reset the browser and re-check that search engine and homepage settings stay changed.

Step 7 — Patch, then change passwords from a clean device

Install pending Windows and browser updates, then change passwords for email, banking and any account used on the machine — from a different, known-clean device. Enable two-factor authentication where it is offered.

When to stop and reinstall Windows

If the same detection returns after two full cleaning passes, if security software cannot be reinstalled, or if the machine was used for banking during an infostealer infection, a clean Windows installation is faster and safer than continued cleanup.

Frequently asked questions

How long does malware removal take?
Plan on two to four hours including full scans. The scans dominate the time; the manual cleanup is usually under thirty minutes.
Do I need to pay for removal software?
Usually not. Microsoft Defender Offline plus a free on-demand scanner handles most consumer infections.