Skip to main content
FixMyTech

How to Scan For and Remove Malware on Windows

By

Published

8 min read

Share

Short answer

Run Windows Security → Virus & threat protection → Scan options → Microsoft Defender Offline scan. The PC reboots into a minimal environment and scans before Windows loads, which catches anything that evades a live scan. It takes about 15 minutes and you cannot use the machine during it. Follow with one on-demand Malwarebytes scan if symptoms persist.

On this page

Most malware removal advice starts with “run a scan”, which is correct and insufficient. A quick scan checks the places malware usually hides and takes a few minutes. A full scan reads everything and takes hours. Neither addresses the actual difficulty, which is that software already running on the machine can interfere with the software trying to detect it.

Windows ships with the tool that solves this, and almost nobody uses it. The offline scan reboots the PC into a minimal environment and scans the drive before Windows and its startup programs load. There is nothing running to hide anything.

First, decide whether this is malware at all

Worth two minutes, because the majority of “infected PC” complaints are something else, and the fix for something else is completely different.

Symptom Malware? Check first
New toolbar, changed search engine Yes Browser extensions
Pop-up ads outside the browser Yes Installed programs
“Your PC is infected” web page No Close the tab
Fan loud, CPU pinned Rarely Task Manager
Everything slow, disk at 100% Rarely Storage or drive health
Random blue screens Rarely Drivers or memory

If the only complaint is speed, start with finding what is using 100% CPU or disk rather than with a scanner. Task Manager names the process in thirty seconds, and the answer is usually Chrome, a Windows update, or a scheduled Defender scan that is itself the thing making the PC slow.

Run the offline scan

This is the main step, and on a genuinely suspect machine it should be the first one.

Save your work and close everything first — the PC reboots immediately and you cannot use it for the duration.

  1. Open Windows Security from the Start menu.
  2. Virus & threat protection → Scan options.
  3. Select Microsoft Defender Offline scan.
  4. Click Scan now and confirm the restart.

The machine reboots into the Windows Recovery Environment, shows a scanning progress screen, and restarts into Windows when it is done. Expect about fifteen minutes, longer on a mechanical drive.

Results appear in Windows Security under Protection history. Items found are quarantined rather than deleted, so a false positive can be restored from there.

If the PC is so badly affected that Windows Security will not open at all, that itself is diagnostic — some malware specifically disables it. In that case boot into Safe Mode (Settings → System → Recovery → Restart now under Advanced startup, then Troubleshoot → Advanced options → Startup Settings) and try again from there.

Then run one second-opinion scan

Different vendors maintain different detection sets, and the categories Defender treats conservatively — adware, bundled toolbars, “potentially unwanted programs” — are exactly the ones most likely to be bothering you.

Malwarebytes free is the standard choice for this. Download it from the vendor’s own site, install it, run a scan, and either uninstall it afterwards or leave the free version in place with real-time protection off.

Do not leave two real-time engines running. Defender plus another resident antivirus produces high CPU, slow file operations and worse detection than either alone. If you install something with real-time protection, Windows will usually stand Defender down automatically, which is fine — what you must avoid is forcing both to stay active.

Stop at two scanners. A third is not a third opinion; it is a list of tracking cookies presented as threats.

Clean up what the scanners leave behind

Scanners remove the malicious files. They often leave the consequences.

Check installed programs. Settings → Apps → Installed apps, sorted by install date. Uninstall anything that arrived alongside the problem, particularly “PC optimisers”, driver updaters, coupon tools and media codecs.

Check browser extensions in every browser you use, not just the default one. Remove anything you did not install deliberately.

Check the browser’s settings. Homepage, default search engine, and startup pages. Also look for a managed-by-organisation notice in Chrome’s settings on a personal PC, which indicates a policy was set by something you did not install. The full procedure is in removing a browser hijacker.

Check startup items. Task Manager → Startup apps. Disable anything unrecognised; this is reversible.

Check the proxy settings. Settings → Network & internet → Proxy. Manual proxy configuration you did not set is a sign that traffic was being routed through something. Turn it off.

Check scheduled tasks if the problem keeps returning. Run taskschd.msc and look through Task Scheduler Library for entries with random names or tasks pointing at files in temporary folders. A recreating infection usually has a task rebuilding it.

Change your passwords afterwards

The part that gets skipped, and the part that matters most if the detection involved anything in the credential-stealing family.

Assume anything typed on that PC while it was compromised is known. Change the important passwords — email first, because it controls every other reset — from a different device, not from the machine you have just cleaned. Then sign out all sessions on those accounts, because a stolen session cookie keeps working after a password change.

Checking whether your password has been leaked covers how to find out which of your credentials are already circulating.

When to stop cleaning and reinstall

There is a point where cleaning is the wrong approach, and recognising it saves days.

  • The same detection returns after removal and a reboot.
  • A scanner reports a rootkit or bootkit.
  • Windows Security, Task Manager or regedit will not open.
  • Ransomware has encrypted files, in which case nothing is cleaned by scanning.
  • You cannot establish what was installed or when.

In those cases, reinstall Windows. Settings → System → Recovery → Reset this PC → Remove everything, with a cloud or local reinstall. Back up your documents first, since Remove everything erases the drive, and copy documents only — not applications, and not a system image, which would restore the problem along with everything else.

Realistic expectations

On a PC with Defender enabled and software installed from ordinary sources, the offline scan usually finds nothing, and the symptom that prompted it turns out to be a browser extension or storage pressure. That is the normal result.

Where something is found, the offline scan plus one Malwarebytes pass removes it and the cleanup afterwards takes longer than the scanning did. Budget an hour for the whole job including password changes, and do the password changes even when the detection looks minor — the cost of doing them unnecessarily is twenty minutes, and the cost of skipping them when they mattered is considerably higher.

Frequently asked questions

How long does a Defender offline scan take?
Usually around 15 minutes, though it can run longer on a mechanical hard drive or a very full drive. The PC restarts on its own when it finishes and shows the results in Windows Security.
Does the offline scan delete my files?
No. It quarantines files it identifies as malicious, which can be reviewed and restored from Protection history in Windows Security. Your documents, photos and installed programs are untouched.
Can I run Malwarebytes alongside Microsoft Defender?
Yes, provided Malwarebytes real-time protection is off and you use it as an on-demand scanner. Two real-time engines running together cause high CPU and missed detections, which is a well-known problem rather than a theoretical one.
What if the scan finds nothing but the PC still behaves oddly?
Then malware is probably not the cause. Browser extensions, a failing drive, a bad driver update and simple storage pressure produce most of the symptoms people attribute to infection, and each is diagnosed differently.
Should I reinstall Windows if something is found?
Not for ordinary adware or a browser hijacker, which clean up reliably. Reinstalling is the correct response to a detection involving credential theft or a rootkit, or to anything that keeps returning after removal, because at that point you cannot trust what else is still there.

All Security guides