The fastest way to remove malware depends on what kind you have
Malware removal usually works in this order: restart your computer in safe mode, run a dedicated malware scanner, delete the files it finds, then restart normally. Most people can do this themselves using free tools like Malwarebytes or Windows Defender. If your computer won't start, won't connect to the internet, or keeps reinfecting itself after removal, you may need to take it to a technician or reinstall Windows entirely.
The method changes slightly depending on whether you're using Windows or Mac, and whether the malware is actively running or dormant. A computer that's actively infected — showing pop-ups, running slowly, or displaying ransomware messages — needs immediate isolation from the internet before you attempt removal.
Key Takeaways
- Restart your computer in safe mode before running any malware scanner, because malware cannot defend itself when Windows is running only essential services.
- Malwarebytes and Windows Defender are both free and can remove most common infections without paying for premium versions.
- If your computer won't start or keeps reinfecting itself, the malware has likely embedded itself in the system files, and you may need to reinstall Windows or seek professional help.
- Disconnect from the internet immediately if you see a ransom message or notice your files are encrypted, because some malware spreads to other devices on your network.
How to restart in safe mode and run a malware scan
Safe mode loads Windows with only the drivers and services it absolutely needs to run. Malware cannot hide or defend itself in safe mode the way it can in normal Windows, which makes it the best time to scan and remove infections.
On Windows 10 or 11, restart your computer and hold down the Shift key while clicking the restart button in the power menu. This opens the boot options screen. Select Troubleshoot, then Advanced options, then Startup Settings, then Restart. When the computer restarts, press 4 or F4 to enter safe mode with networking (you need networking to download a scanner if you don't already have one).
Once in safe mode, download Malwarebytes from malwarebytes.com or Windows Defender (built into Windows). Run a full system scan — this can take 30 minutes to several hours depending on your hard drive size. When the scan finishes, review the list of detected items and click Quarantine to remove them. Restart your computer normally when done.
What to do if the malware won't let you restart or scan
Some malware locks you out of safe mode, disables Windows Defender, or prevents you from downloading a scanner. If you cannot access safe mode or download tools, you have two options: use a bootable scanner or reinstall Windows.
A bootable scanner is a malware removal tool you download on a different computer, write to a USB drive, and then boot from on your infected computer. Kaspersky Rescue Disk and Bitdefender Rescue Disk are both free. You download the ISO file on a clean computer, use a tool like Rufus (on Windows) or Etcher (on Mac) to write it to a USB drive, then plug the USB into your infected computer and restart. The computer boots from the USB instead of Windows, and the scanner runs before Windows even loads. This bypasses any malware that's blocking your access to safe mode.
If the bootable scanner doesn't work or finds malware it cannot remove, reinstalling Windows is the most reliable option. This erases everything on your hard drive and installs a fresh copy of Windows. You can reinstall from a USB drive using the Windows Media Creation Tool (available free from Microsoft). Back up any files you need first — copy them to an external drive or cloud storage on a different computer.
Removing malware on a Mac
Mac malware is less common than Windows malware, but it does exist. If your Mac is running slowly, showing unexpected pop-ups, or displaying a message that your device is infected, restart in safe mode first.
On an Intel Mac, restart and hold Shift immediately after you hear the startup sound. On an Apple Silicon Mac (M1, M2, M3), restart and hold the power button until you see the startup options screen, then select your drive and hold Shift while clicking Continue in Safe Mode. Once in safe mode, download Malwarebytes for Mac from malwarebytes.com and run a full scan. Quarantine any detected items and restart normally.
If you cannot enter safe mode or the scan finds nothing but your Mac is still behaving strangely, the problem may not be malware — it could be a browser extension, a login item, or a legitimate app using too many resources. Check System Settings > General > Login Items and remove anything you don't recognize. Then check your web browser's extension list and remove unfamiliar extensions.
Preventing reinfection after removal
Malware often comes back because the original infection vector — the way it got in — is still open. If you removed malware but it reappears within days, something is still letting it back in.
Check your browser homepage and search engine settings. Many malware variants change these to redirect you to malicious sites. In Chrome, Edge, or Firefox, go to Settings and verify that your homepage and search engine are what you expect. Remove any browser extensions you don't recognize. On Windows, open Settings > Apps > Installed apps and look for unfamiliar programs, then uninstall them.
Enable Windows Defender real-time protection if it's not already on. Go to Settings > Privacy & Security > Virus & threat protection and make sure Real-time protection is toggled on. Keep Windows and your browser updated — malware often exploits security holes in outdated software. Turn on automatic updates in Settings > Update & Security > Windows Update.
When to take your computer to a technician
If your computer won't start at all, won't connect to the internet even in safe mode, or keeps reinfecting itself after you've removed malware and closed the infection vector, the malware has likely embedded itself in the system files or boot sector. This is beyond what most people can fix themselves.
A technician can use specialized tools to remove boot-sector malware, or they can back up your files and reinstall Windows for you. This usually costs between $100 and $300 depending on your location and the severity of the infection. If your computer is very old or the repair cost approaches the price of a new one, replacing it may be more practical.
Ransomware — malware that encrypts your files and demands payment to decrypt them — is a special case. Do not pay the ransom. Contact your local police department's cybercrime unit and report it. Some ransomware variants have known decryption keys that security researchers have published; a technician can check whether yours is one of them. If you have backups of your files from before the infection, restore from those instead of paying.
Frequently Asked Questions
Can I remove malware without restarting in safe mode?
You can try, but safe mode gives you the best chance of success because malware cannot run or defend itself. If you run a scanner in normal Windows and it finds nothing, restart in safe mode and scan again — you'll often find infections the normal scan missed.
Is it safe to download Malwarebytes if my computer is already infected?
Yes. Malware cannot prevent you from downloading a scanner — it can only prevent you from running it. If you cannot run Malwarebytes in normal Windows, restart in safe mode and try again. If you still cannot run it, use a bootable scanner instead.
What's the difference between quarantine and delete?
Quarantine moves the malware file to an isolated folder where it cannot run. Delete removes it permanently. Quarantine is safer because if the scanner made a mistake and flagged a legitimate file, you can restore it. After you're confident the malware is gone, you can delete quarantined files permanently.
Will removing malware recover files that were already deleted?
No. Malware removal only stops the malware from running and deletes the malware files themselves. If malware deleted your personal files before you removed it, those files are gone. Restore them from a backup if you have one. This is why regular backups matter — they protect you if malware or hardware failure destroys your files.
Do I need to buy antivirus software after removing malware?
No. Windows Defender (built into Windows) and Malwarebytes (free version) together provide solid protection for most people. The paid versions add features like scheduled scans and real-time monitoring, but the free versions handle the core job of detecting and removing malware. Focus on keeping Windows updated and avoiding suspicious downloads instead.