Not every infection requires a full OS reinstall. For common threats like adware, browser hijackers, PUPs, and many trojans, a methodical scan-and-clean process can get your machine back to healthy without losing your files or programs. This guide walks you through it — no technical experience required.
Unplug your Ethernet cable and turn off Wi-Fi. This prevents the malware from downloading additional payloads, sending your data out, or receiving remote commands while you clean it. You can reconnect briefly later to download tools — just disconnect again before scanning.
Safe Mode loads Windows with only essential drivers, which prevents most malware from running and hiding. Hold Shift while clicking Start → Power → Restart. Choose Troubleshoot → Advanced Options → Startup Settings → Restart. Press 5 to select "Safe Mode with Networking." You'll see "Safe Mode" in the screen corners confirming it worked.
Open Windows Security (search in Start menu) → Virus & threat protection → Scan options → select Full scan → Scan now. This checks every file on your computer, not just common locations. It may take 30–60 minutes. Let it finish completely — don't cancel early.
Some malware hides in areas that can't be scanned while Windows is running. Go to Windows Security → Virus & threat protection → Scan options → select Microsoft Defender Offline scan → Scan now. Your computer restarts into a special environment that scans before Windows loads — catching rootkits and boot-sector malware. It restarts back to normal when done.
Reconnect briefly and go to malwarebytes.com. Download the free version — you don't need Premium. Install it, disconnect from internet again, then run a Threat Scan. Malwarebytes catches adware, spyware, PUPs, and browser hijackers that Defender sometimes misses. Review results and click Quarantine on everything flagged.
Malware adds itself to startup so it runs every boot. Press Ctrl + Shift + Esc → click the Startup tab. Disable anything you don't recognize, especially entries with no publisher or random-character names. If unsure, Google the name first — but when in doubt, disable it. You can re-enable later.
Many infections target your browser specifically. For each browser you use, check three things: Extensions — remove anything you didn't install. Homepage & search engine — verify they haven't been changed to something unfamiliar. Reset if needed — if your browser still acts strange, use the built-in "Reset settings" option (found in Settings under "Reset" or "Restore defaults"). This clears everything except bookmarks.
Go to Settings → Apps → Installed apps and sort by install date (newest first). Look for anything you didn't intentionally install — toolbars, "system optimizers," "driver updaters," or programs with names you don't recognize. Uninstall them. These are a common way malware maintains a foothold on your system.
If you found a suspicious file but aren't sure about it, go to virustotal.com and upload it. VirusTotal scans with 70+ antivirus engines and shows how many flag it. If most say clean, it probably is. If multiple engines flag it, delete it. You can also paste suspicious URLs to check if a website is malicious before visiting it.
Once scans are clean and your system is behaving normally: 1) Run Windows Update and install everything. 2) Update your browsers. 3) Change passwords for any accounts you logged into while infected — the malware may have captured them. Start with email, then banking, then social media. Use your password manager to generate new unique passwords.
If the infection keeps coming back or you're not sure your computer is truly clean, a one-on-one session lets us dig deeper — checking persistence mechanisms, hidden scheduled tasks, and areas most guides don't cover.