Could a handful of quick, measured moves be all you need to reclaim a compromised computer? Many people assume a shop visit is the only option when apps crash or unknown processes appear. That’s not always true.
Start by containing the threat: unplug the network, boot Windows into Safe Mode, and avoid logging into accounts while you investigate.
Use built-in tools like Task Manager, Event Viewer, and Activity history to spot odd activity. Clear temporary files, reset browsers, then run a full scan with Microsoft Defender or reputable scanners such as Malwarebytes or Avast.
If these steps fail, consider a system reset and restore only from backups made before the compromise. For a deeper read on virus cleanup and best practices, see this vendor walkthrough and guidance on stubborn infections at haktechs.
Key Takeaways
- Contain first: disconnect and use Safe Mode before probing the system.
- Investigate with built-ins: Task Manager and Event Viewer reveal suspicious processes.
- Clean and scan: clear temp files, reset browsers, and run full antivirus scans.
- Escalate if needed: use Reset this PC and restore only from safe backups.
- Verify settings: check proxy/LAN and update OS and software to reduce reinfection risk.
Before You Start: Contain the threat and prep your Windows PC
First, isolate the machine by cutting off any Wi‑Fi or Ethernet links so the infection can’t phone home. Containment is your top priority. Stopping the connection prevents further data loss and blocks remote updates from attacker servers.
Disconnect from the internet?
Yes. Physically unplug Ethernet, turn off Wi‑Fi, or power down the router to break the network path. This severs the connection between the attacker and your device and reduces lateral spread across other devices.
Should you log in or enter passwords?
Don’t sign in. Avoid email, banking, or cloud accounts. Some types of keyloggers capture passwords and clipboard data instantly. If you must fetch a scanner, reconnect only long enough to download it, then disconnect again.
What are common signs of infection?
Watch for sudden slowdowns, frequent crashes, unexpected programs or processes, pop-up messages, and browser redirects. Unexplained CPU spikes and new toolbars are also red flags on Windows.
- Prepare a clean USB drive and enable viewing of hidden files before working offline.
- Document suspicious filenames and settings—this helps during later cleanup.
- Plan to boot into Safe Mode or Safe Mode with Networking only when you need limited services or a brief download.
For official recovery advice and further reading, consult the Microsoft resources.
The step-by-step guide to remove pc malware at home
Booting into a low‑footprint Windows mode makes cleanup work safer and faster. This limits running programs and services so you can inspect activity without interference.
Reboot into Safe Mode or Safe Mode with Networking on Windows 10/11
Press Windows + I, then go to Update & Security (Windows 10) or System (Windows 11) > Recovery > Advanced startup > Restart now. After the reboot choose Troubleshoot > Advanced options > Startup Settings > Restart, then press 4/F4 for safe mode or 5/F5 for safe mode networking.
Monitor your PC’s activity: Task Manager, Event Viewer, and Activity history
Open Task Manager (Ctrl + Shift + Esc) and look for odd process names, unsigned parents, or heavy resource use. Check Event Viewer under Windows Logs for unexpected logons, crashes, or service failures.
View Activity history in Settings > Privacy & security > Activity history to see recent files and apps. Use that context to focus investigations on suspicious items.

Delete temporary files and system cache with Storage Sense
Go to Settings > System > Storage > Temporary Files. Toggle Storage Sense on and click Clean now to delete caches, installers, and leftover temporary files attackers hide in.
Run a full malware scan with Microsoft Defender or a trusted scanner
From Windows Security run a full scan with Microsoft Defender. Then run a reputable second‑opinion antivirus such as Malwarebytes or Avast to catch families Defender might miss.
Quarantine and remove malicious software, then restart computer
Quarantine any detections and remove confirmed threats. Document filenames and affected settings, then restart into normal mode and confirm no odd programs or services return.
“Quarantine first, document what you found, then reboot and verify stability.”
For a comprehensive removal checklist see this walkthrough.
Clean up your browsers and restore secure settings
Attackers often change browser defaults to capture traffic or inject ads. Start by restoring each browser’s default settings and then remove any lingering data or extensions that could reconnect to malicious servers. This reduces the chance of reinfection and restores a predictable browsing environment.
Reset Chrome, Edge, or Firefox to their defaults
In Chrome use the three dots > Settings > Reset settings > Restore settings to their original defaults > Reset.
In Edge: three dots > Settings > Reset settings > Restore settings to their default values > Reset.
In Firefox: Menu > Help > More Troubleshooting Information > Refresh Firefox > Finish.
Clear cache, cookies, and history
After a reset, open each browser’s privacy menu and clear cached files, cookies, and history. This removes scripts or stored tokens that attackers use to persist.
On Windows, run Storage Sense: Settings > System > Storage > Clean now to flush system temp files as well.
Audit extensions and startup pages for suspicious links
Review installed extensions and startup pages. Uninstall any add-ons you didn’t install or that request broad permissions.
Manually check homepage and search provider entries for unfamiliar links and delete them.
- Why reset: restores safe defaults and removes unwanted homepages and search providers.
- Why clear: cached data and files may retain malicious scripts.
- Why audit: extensions or startup programs often carry persistent web redirects.
| Action | Chrome | Edge | Firefox |
|---|---|---|---|
| Reset settings | three dots > Settings > Reset settings > Restore defaults | three dots > Settings > Reset settings > Restore defaults | Menu > Help > More Troubleshooting Information > Refresh Firefox |
| Clear cache/cookies | Settings > Privacy & security > Clear browsing data | Settings > Privacy, search & services > Clear browsing data | Options > Privacy & Security > Cookies and Site Data > Clear |
| Check extensions/startup | More tools > Extensions | Settings > Extensions | Menu > Add-ons and themes |

“Reset, clear, and audit — those three actions neutralize common browser persistence techniques.”
Run a final safety check such as Chrome Safety Check and review saved passwords. For Chrome-specific recovery steps, consult this Chrome recovery page.
Network and system settings that malware often hijacks
Before you trust network traffic again, inspect core system settings that attackers commonly change. Small edits in network options can keep an infection alive even after scans finish.
How do I verify Windows proxy and LAN settings?
Open Control Panel > Internet Options > Connections > LAN settings. Make sure Automatically detect settings is checked.
Also ensure Use automatic configuration script and Use a proxy server for your LAN are unchecked unless you set them intentionally. Malicious proxies can silently reroute your connection and block security updates.
Which autoruns should I review for reinfection risk?
Audit startup apps, services, and Scheduled Tasks. These autoruns often re-trigger payloads after cleanup.
Use Task Manager, Services.msc, and Task Scheduler to list entries. Compare unknown programs against vendor information and trusted communities before deleting.
Watch file paths that point into user profiles, temp folders, or odd system locations. Correlate those entries with Event Viewer and resource monitors to see which actually consume resources or cause errors.
“If an item only fails in Safe mode, treat it as suspicious and remove it.”
After edits, reboot and re-validate your settings and DNS behavior. If values revert, further scans or a stronger recovery path are needed. For more recovery reading see this walkthrough on how to get rid of a virus or malware on your and the instructions on how to safely remove malware from a Windows 11.
If removal fails: Safe recovery options without the repair shop
If repeated scans still show infections, plan a controlled recovery rather than panic. Start with another full scan in a limited environment and escalate only when necessary.
When should you run another scan in Safe Mode with Networking?
If detections return after cleanup, reboot into safe mode and run a fresh full scan. A brief mode with networking lets antivirus tools update signatures before scanning.
Updating definitions can catch new or nested threats that earlier scans missed. If an entry keeps coming back, document its path and quarantine it before moving on.
When is “Reset this PC” or a reinstall the right option?
If entrenched threats persist, use Windows “Reset this PC.” On Windows 10 go to Settings > Update & Security > Recovery > Get started. On Windows 11 use Settings > System > Recovery > Reset PC.
Reinstalling the operating system wipes the disk and removes persistent agents. Only restore files from backups made before the incident, and scan each restored file before opening it.
- Back up essential data, then restart computer into recovery and pick the option that fits your tolerance for app loss.
- After reset, reinstall trusted programs and run a full antivirus plus a second‑opinion scanner to validate integrity.
- Clear caches and delete temporary items again, then repeat targeted scans on folders you restored.
- If the process fails or crashes, restart and try offline repair media or installation USB tools.
| Action | When to pick it | Effect |
|---|---|---|
| Rescan in Safe Mode | Detections persist but system still boots | Updates definitions and isolates active processes |
| Reset this PC | Multiple scans fail or persistence returns | Reinstalls Windows, preserves or removes files per choice |
| Full reinstall from media | System compromised deeply or reset failed | Wipes disk, restores clean operating system |
| Selective data restore | After clean OS is verified | Bring back only scanned, known‑clean files |
“Back up data, update tools, then verify each restored file — an ounce of patience prevents a second infection.”
For more on virus cleanup and recovery, consult this practical resource: Malwarebytes’ removal checklist.
Conclusion
Good digital habits cut risk: keep your antivirus active, tighten device settings, and back up critical data. Update your computer promptly, avoid suspicious links, and install apps only from trusted sources.
You now have a practical guide for identifying, containing, and the removal of common malware using built‑in Windows tools and reputable scanners.
Stay proactive: harden security, patch software, and be wary of unexpected links and attachments. Back up essential data and verify restores before opening files. If the infection returns, repeat Safe Mode scans or use Reset this PC and restore only pre‑infection backups.
Share trustworthy information with family or team, enforce stronger passwords and multi‑factor authentication, and keep system baselines under watch. For a compact removal checklist, consult this removal checklist.