How to Remove Malware from a Windows PC
Suspect your PC is infected? Here is a step-by-step guide to identifying, containing, and removing malware from Windows 10 and Windows 11.
How to Remove Malware from a Windows PC
Your PC is running slower than usual. Your browser keeps redirecting to sites you did not navigate to. You are seeing pop-ups you cannot close. These are classic signs that something is wrong — and that something is often malware.
Step 1: Recognize the Signs of Infection
Common symptoms include unusual slowness, browser redirects, unexpected pop-ups, programs opening or closing on their own, unfamiliar programs in your installed apps list, antivirus software disabled, and high network activity when you are not actively using the internet.
Step 2: Disconnect from the Internet
Before running any scans, disconnect your PC from the internet. This prevents malware from communicating with command-and-control servers, downloading additional payloads, or exfiltrating data while you are trying to clean the system.
Step 3: Boot into Safe Mode
Safe Mode starts Windows with only essential drivers and services, which prevents most malware from loading at startup. To boot into Safe Mode on Windows 11: hold Shift and click Restart, then select Troubleshoot → Advanced Options → Startup Settings → Restart, then press 4 or F4.
Step 4: Run a Full Malware Scan
With your PC in Safe Mode, run a full system scan with your antivirus software. A full scan examines every file on your system. If you are using SentinelForge Security, navigate to the Scan section and select Full System Scan. Let the scan run to completion.
Step 5: Review and Quarantine Detected Threats
After the scan completes, review the results carefully. Quarantine high-severity threats immediately. Quarantine isolates the file so it cannot execute, but preserves it in case you need to restore it later.
Step 6: Review the Incident Timeline
Knowing what was infected is not enough — you need to understand how the infection got in and what it did while it was active. SentinelForge's Threat Replay™ feature presents a chronological timeline of the events surrounding a detection.
Step 7: Remove Persistence Mechanisms
Check startup programs, scheduled tasks, browser extensions, and installed programs for anything unfamiliar. Many malware infections install themselves to run at startup.
Step 8: Update Everything
Once the malware is removed, update your operating system, browsers, and all installed software. Most malware exploits known vulnerabilities in outdated software.
Step 9: Change Your Passwords
If the malware was active for any period of time, change passwords for email accounts, banking and financial services, and any accounts where you store payment information.
Step 10: Run a Second Scan
After completing all the above steps, reconnect to the internet, update your antivirus definitions, and run a second full scan to confirm the system is clean.
SentinelForge Security includes real-time malware scanning, quarantine management, and Threat Replay™ forensics. View plans starting at $7.99/mo.
Explore Topics
Written by
SentinelForge Security Team
Content creator and writer sharing insights and stories.