How to Completely Remove a Trojan, Virus, Worm or Other Malware From Your Computer
In 2026, malware threats like Trojans, viruses, worms, and ransomware continue to target individuals and businesses. Removing such infections requires a systematic approach, including disconnecting from the internet, running updated anti-malware tools, uninstalling suspicious programs, deleting temporary files, resetting browser settings, updating all software, changing passwords, and restoring from clean backups if needed. This blog provides an easy-to-follow, step-by-step guide suitable for beginners and cybersecurity students, ensuring complete malware removal and system recovery while sharing essential prevention tips.
Quick answer: To remove malware: disconnect the computer from the network, back up your personal files, boot to Safe Mode or a rescue disk, run a full scan with an updated antivirus and an offline scan, remove suspicious start-up items and programs, reset browsers, then change passwords from a clean device. If malware returns or it was ransomware, back up data and reinstall the operating system.
Key takeaways
- Disconnect from the internet first to stop the malware spreading or sending data.
- Back up documents and photos only, not programs or system files.
- Scan from Safe Mode or an offline or rescue scan, because some malware hides while Windows is running.
- Change passwords from a different, clean device after cleaning.
- A wipe and reinstall is the only certain fix when the infection is deep, repeats, or involves ransomware or banking theft.
How do you know your computer has malware?
Common signs are sudden slowness, programs you did not install, pop-ups or fake antivirus warnings, a browser home page that keeps changing, security tools that turn off, unexpected network activity, or files that are missing or locked. None of these alone proves infection, so check for a failing disk or a full drive too.
| Type | What it does | Typical sign |
|---|---|---|
| Trojan | Disguised as useful software, gives access or steals data | Unknown programs, remote activity |
| Virus | Attaches to files and spreads when they run | Crashes, damaged files |
| Worm | Spreads by itself across networks or USB drives | Slow network, many copies of files |
| Ransomware | Encrypts files and demands payment | Locked files and a ransom note |
| Spyware / infostealer | Copies passwords, cookies and keystrokes | Account alerts, unknown logins |
Step-by-step malware removal on Windows
- Disconnect. Turn off Wi-Fi or unplug the Ethernet cable. This stops data theft and spread. Remove USB drives.
- Back up your files. Copy only documents, photos and other personal data to an external drive. Do not back up programs. Scan the backup later before you open it.
- Boot into Safe Mode. Hold Shift while clicking Restart, then Troubleshoot, Advanced options, Startup Settings, and choose Safe Mode with Networking only if you need to download tools. On modern Windows the old F8 key usually does not work.
- Run a full scan. Update and run your antivirus. In Windows Security, choose Scan options and run Microsoft Defender Offline scan, which restarts the PC and scans before Windows loads. Details are in Microsoft Learn.
- Use a second opinion scanner from a reputable vendor, downloaded on a clean device. Do not run two real-time antivirus products together.
- Check for persistence. Open Task Manager's Startup tab, Task Scheduler and Services. Remove unknown start-up entries and uninstall unknown programs. Advanced users can use Sysinternals Autoruns to see everything that starts with Windows.
- Reset your browsers. Remove unknown extensions, reset settings and clear notification permissions granted to unknown sites.
- Check system integrity. In an administrator command prompt run
sfc /scannow, thenDISM /Online /Cleanup-Image /RestoreHealthto repair damaged Windows files. - Update everything. Install Windows updates, and update browsers and apps to close the hole that was used.
- Change passwords from a clean device. Start with email, banking and work accounts. Turn on multi-factor authentication and sign out other sessions. Tell your bank if financial accounts were used on the infected machine.
When should you reinstall instead?
Cleaning cannot prove a computer is safe. Wipe and reinstall when:
- It was ransomware (see how to deal with ransomware). Keep the encrypted files in case a free decryptor becomes available.
- The malware keeps coming back after removal.
- Security tools are disabled and cannot be turned on.
- You suspect a rootkit or boot-level infection.
- The computer holds banking, business or work credentials.
To reinstall, create Windows installation media on another computer, boot from it, delete all partitions on the system disk and install fresh. Restore your files after scanning them, and reinstall programs from official sources.
How to prevent reinfection
- Keep Windows, browsers and apps updated.
- Use a standard user account for daily work, not an administrator account.
- Do not use cracked software or open unexpected attachments.
- Keep offline or cloud versioned backups.
- Use a password manager and MFA.
To understand the types, see our posts on viruses versus worms and what a virus is. If it is a work device, report to your IT or security team, and in India serious incidents can be reported to CERT-In.
Common mistakes
- Changing passwords before cleaning the machine.
- Paying for a "cleaner" that a pop-up advertised, which is often malware itself.
- Restoring a full system backup that contains the malware.
- Deleting files without a backup.
Next steps
Next steps: to learn how analysts investigate infections, see our CHFI course, or read about ransomware recovery.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0