How to Scan For and Remove Malware on Windows
Short answer
Run Windows Security → Virus & threat protection → Scan options → Microsoft Defender Offline scan. The PC reboots into a minimal environment and scans before Windows loads, which catches anything that evades a live scan. It takes about 15 minutes and you cannot use the machine during it. Follow with one on-demand Malwarebytes scan if symptoms persist.
On this page
Most malware removal advice starts with “run a scan”, which is correct and insufficient. A quick scan checks the places malware usually hides and takes a few minutes. A full scan reads everything and takes hours. Neither addresses the actual difficulty, which is that software already running on the machine can interfere with the software trying to detect it.
Windows ships with the tool that solves this, and almost nobody uses it. The offline scan reboots the PC into a minimal environment and scans the drive before Windows and its startup programs load. There is nothing running to hide anything.
First, decide whether this is malware at all
Worth two minutes, because the majority of “infected PC” complaints are something else, and the fix for something else is completely different.
| Symptom | Malware? | Check first |
|---|---|---|
| New toolbar, changed search engine | Yes | Browser extensions |
| Pop-up ads outside the browser | Yes | Installed programs |
| “Your PC is infected” web page | No | Close the tab |
| Fan loud, CPU pinned | Rarely | Task Manager |
| Everything slow, disk at 100% | Rarely | Storage or drive health |
| Random blue screens | Rarely | Drivers or memory |
If the only complaint is speed, start with finding what is using 100% CPU or disk rather than with a scanner. Task Manager names the process in thirty seconds, and the answer is usually Chrome, a Windows update, or a scheduled Defender scan that is itself the thing making the PC slow.
Run the offline scan
This is the main step, and on a genuinely suspect machine it should be the first one.
Save your work and close everything first — the PC reboots immediately and you cannot use it for the duration.
- Open Windows Security from the Start menu.
- Virus & threat protection → Scan options.
- Select Microsoft Defender Offline scan.
- Click Scan now and confirm the restart.
The machine reboots into the Windows Recovery Environment, shows a scanning progress screen, and restarts into Windows when it is done. Expect about fifteen minutes, longer on a mechanical drive.
Results appear in Windows Security under Protection history. Items found are quarantined rather than deleted, so a false positive can be restored from there.
If the PC is so badly affected that Windows Security will not open at all, that itself is diagnostic — some malware specifically disables it. In that case boot into Safe Mode (Settings → System → Recovery → Restart now under Advanced startup, then Troubleshoot → Advanced options → Startup Settings) and try again from there.
Then run one second-opinion scan
Different vendors maintain different detection sets, and the categories Defender treats conservatively — adware, bundled toolbars, “potentially unwanted programs” — are exactly the ones most likely to be bothering you.
Malwarebytes free is the standard choice for this. Download it from the vendor’s own site, install it, run a scan, and either uninstall it afterwards or leave the free version in place with real-time protection off.
Do not leave two real-time engines running. Defender plus another resident antivirus produces high CPU, slow file operations and worse detection than either alone. If you install something with real-time protection, Windows will usually stand Defender down automatically, which is fine — what you must avoid is forcing both to stay active.
Stop at two scanners. A third is not a third opinion; it is a list of tracking cookies presented as threats.
Clean up what the scanners leave behind
Scanners remove the malicious files. They often leave the consequences.
Check installed programs. Settings → Apps → Installed apps, sorted by install date. Uninstall anything that arrived alongside the problem, particularly “PC optimisers”, driver updaters, coupon tools and media codecs.
Check browser extensions in every browser you use, not just the default one. Remove anything you did not install deliberately.
Check the browser’s settings. Homepage, default search engine, and startup pages. Also look for a managed-by-organisation notice in Chrome’s settings on a personal PC, which indicates a policy was set by something you did not install. The full procedure is in removing a browser hijacker.
Check startup items. Task Manager → Startup apps. Disable anything unrecognised; this is reversible.
Check the proxy settings. Settings → Network & internet → Proxy. Manual proxy configuration you did not set is a sign that traffic was being routed through something. Turn it off.
Check scheduled tasks if the problem keeps returning. Run taskschd.msc and
look through Task Scheduler Library for entries with random names or tasks
pointing at files in temporary folders. A recreating infection usually has a task
rebuilding it.
Change your passwords afterwards
The part that gets skipped, and the part that matters most if the detection involved anything in the credential-stealing family.
Assume anything typed on that PC while it was compromised is known. Change the important passwords — email first, because it controls every other reset — from a different device, not from the machine you have just cleaned. Then sign out all sessions on those accounts, because a stolen session cookie keeps working after a password change.
Checking whether your password has been leaked covers how to find out which of your credentials are already circulating.
When to stop cleaning and reinstall
There is a point where cleaning is the wrong approach, and recognising it saves days.
- The same detection returns after removal and a reboot.
- A scanner reports a rootkit or bootkit.
- Windows Security, Task Manager or regedit will not open.
- Ransomware has encrypted files, in which case nothing is cleaned by scanning.
- You cannot establish what was installed or when.
In those cases, reinstall Windows. Settings → System → Recovery → Reset this PC → Remove everything, with a cloud or local reinstall. Back up your documents first, since Remove everything erases the drive, and copy documents only — not applications, and not a system image, which would restore the problem along with everything else.
Realistic expectations
On a PC with Defender enabled and software installed from ordinary sources, the offline scan usually finds nothing, and the symptom that prompted it turns out to be a browser extension or storage pressure. That is the normal result.
Where something is found, the offline scan plus one Malwarebytes pass removes it and the cleanup afterwards takes longer than the scanning did. Budget an hour for the whole job including password changes, and do the password changes even when the detection looks minor — the cost of doing them unnecessarily is twenty minutes, and the cost of skipping them when they mattered is considerably higher.