How to Completely Remove a Trojan, Virus, Worm or Other Malware From Your Computer

In 2026, malware threats like Trojans, viruses, worms, and ransomware continue to target individuals and businesses. Removing such infections requires a systematic approach, including disconnecting from the internet, running updated anti-malware tools, uninstalling suspicious programs, deleting temporary files, resetting browser settings, updating all software, changing passwords, and restoring from clean backups if needed. This blog provides an easy-to-follow, step-by-step guide suitable for beginners and cybersecurity students, ensuring complete malware removal and system recovery while sharing essential prevention tips.

Jul 15, 2025 - 15:27
Updated: 7 days ago
105.3k
How to Completely Remove a Trojan, Virus, Worm or Other Malware From Your Computer

Quick answer: To remove malware: disconnect the computer from the network, back up your personal files, boot to Safe Mode or a rescue disk, run a full scan with an updated antivirus and an offline scan, remove suspicious start-up items and programs, reset browsers, then change passwords from a clean device. If malware returns or it was ransomware, back up data and reinstall the operating system.

Key takeaways

  • Disconnect from the internet first to stop the malware spreading or sending data.
  • Back up documents and photos only, not programs or system files.
  • Scan from Safe Mode or an offline or rescue scan, because some malware hides while Windows is running.
  • Change passwords from a different, clean device after cleaning.
  • A wipe and reinstall is the only certain fix when the infection is deep, repeats, or involves ransomware or banking theft.

How do you know your computer has malware?

Common signs are sudden slowness, programs you did not install, pop-ups or fake antivirus warnings, a browser home page that keeps changing, security tools that turn off, unexpected network activity, or files that are missing or locked. None of these alone proves infection, so check for a failing disk or a full drive too.

TypeWhat it doesTypical sign
TrojanDisguised as useful software, gives access or steals dataUnknown programs, remote activity
VirusAttaches to files and spreads when they runCrashes, damaged files
WormSpreads by itself across networks or USB drivesSlow network, many copies of files
RansomwareEncrypts files and demands paymentLocked files and a ransom note
Spyware / infostealerCopies passwords, cookies and keystrokesAccount alerts, unknown logins

Step-by-step malware removal on Windows

  1. Disconnect. Turn off Wi-Fi or unplug the Ethernet cable. This stops data theft and spread. Remove USB drives.
  2. Back up your files. Copy only documents, photos and other personal data to an external drive. Do not back up programs. Scan the backup later before you open it.
  3. Boot into Safe Mode. Hold Shift while clicking Restart, then Troubleshoot, Advanced options, Startup Settings, and choose Safe Mode with Networking only if you need to download tools. On modern Windows the old F8 key usually does not work.
  4. Run a full scan. Update and run your antivirus. In Windows Security, choose Scan options and run Microsoft Defender Offline scan, which restarts the PC and scans before Windows loads. Details are in Microsoft Learn.
  5. Use a second opinion scanner from a reputable vendor, downloaded on a clean device. Do not run two real-time antivirus products together.
  6. Check for persistence. Open Task Manager's Startup tab, Task Scheduler and Services. Remove unknown start-up entries and uninstall unknown programs. Advanced users can use Sysinternals Autoruns to see everything that starts with Windows.
  7. Reset your browsers. Remove unknown extensions, reset settings and clear notification permissions granted to unknown sites.
  8. Check system integrity. In an administrator command prompt run sfc /scannow, then DISM /Online /Cleanup-Image /RestoreHealth to repair damaged Windows files.
  9. Update everything. Install Windows updates, and update browsers and apps to close the hole that was used.
  10. Change passwords from a clean device. Start with email, banking and work accounts. Turn on multi-factor authentication and sign out other sessions. Tell your bank if financial accounts were used on the infected machine.

When should you reinstall instead?

Cleaning cannot prove a computer is safe. Wipe and reinstall when:

  • It was ransomware (see how to deal with ransomware). Keep the encrypted files in case a free decryptor becomes available.
  • The malware keeps coming back after removal.
  • Security tools are disabled and cannot be turned on.
  • You suspect a rootkit or boot-level infection.
  • The computer holds banking, business or work credentials.

To reinstall, create Windows installation media on another computer, boot from it, delete all partitions on the system disk and install fresh. Restore your files after scanning them, and reinstall programs from official sources.

How to prevent reinfection

  • Keep Windows, browsers and apps updated.
  • Use a standard user account for daily work, not an administrator account.
  • Do not use cracked software or open unexpected attachments.
  • Keep offline or cloud versioned backups.
  • Use a password manager and MFA.

To understand the types, see our posts on viruses versus worms and what a virus is. If it is a work device, report to your IT or security team, and in India serious incidents can be reported to CERT-In.

Common mistakes

  • Changing passwords before cleaning the machine.
  • Paying for a "cleaner" that a pop-up advertised, which is often malware itself.
  • Restoring a full system backup that contains the malware.
  • Deleting files without a backup.

Next steps

Next steps: to learn how analysts investigate infections, see our CHFI course, or read about ransomware recovery.

Related reading

Frequently Asked Questions

Disconnect from the network, back up personal files, boot to Safe Mode, run a full and an offline scan, remove suspicious start-up items and programs, update Windows and change passwords from a clean device. Reinstall if it returns.

Not always. New or deeply hidden malware can evade detection, and a scan cannot prove a system is clean. For serious infections, ransomware or repeated reinfection, backing up data and reinstalling the operating system is the safest route.

Reinstall if it was ransomware, the malware returns, security tools are disabled, you suspect a rootkit, or the PC holds banking or work credentials. For minor adware, a careful cleanup may be enough.

Hold Shift and click Restart, choose Troubleshoot, Advanced options, Startup Settings, Restart, then pick Safe Mode. Run your antivirus scan there. Windows Security also offers a Microsoft Defender Offline scan that runs before Windows loads.

Disconnect it from Wi-Fi and Ethernet to stop data leaving or the malware spreading, remove USB drives and stop entering passwords. Then back up personal files and begin scanning and cleanup.

Usually yes for software malware, because it wipes the system partition, but not always for firmware or boot-level infections. Use a clean reinstall from trusted media, update firmware and then restore scanned data.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.