How to recognise and remove a keylogger or spyware from your Windows PC
Summary
This guide helps you troubleshoot and resolve: How to recognise and remove a keylogger or spyware from your Windows PC. Follow the steps below to fix the issue.
Common Causes
Keyloggers and spyware are malicious programs designed to silently monitor your activity, capture keystrokes, and steal sensitive information such as passwords, banking details, and business credentials. Because they run quietly in the background, they can be difficult to detect. This guide walks you through recognising the warning signs, removing infections from a Windows PC, and securing your accounts afterwards. If you suspect an active compromise, treat every password stored on or used from the machine as exposed.
Warning Signs Your PC May Be Compromised
No single symptom confirms an infection, but several together should raise suspicion:
- Unexpected cursor movement, text appearing as if typed by itself, or characters lagging behind keystrokes
- Unfamiliar processes running in Task Manager, especially ones consuming CPU or network when the PC is idle
- Slow browser performance, unexpected toolbars, or search results being redirected
- New programs, scheduled tasks, or startup items you did not install
- Friends or colleagues receiving messages you did not send
- Unusual outbound network traffic, particularly to unfamiliar IP addresses
- Antivirus or Windows Security being disabled or unable to update
Quick Fix Steps
- Disconnect from the internet (turn off Wi-Fi or unplug the Ethernet cable).
- Back up critical business files to an external drive, but only files you can verify are clean (avoid executables and scripts).
- Run a full scan with Windows Security, then a second scan with a reputable on-demand tool such as Malwarebytes.
- Remove anything detected and restart the PC.
- Review startup items, scheduled tasks, and browser extensions for anything unfamiliar.
- Change all passwords from a clean device and enable multi-factor authentication.
- If infection persists, perform a full Windows reset or clean reinstall.
Detailed Removal Instructions
Step 1: Disconnect and Back Up
Unplugging the network stops the spyware from transmitting captured data and prevents it from downloading further payloads. Back up only documents, spreadsheets, and other data files you trust. Do not back up program installers, .exe files, browser profiles, or email archives from the suspect machine, as these may harbour the infection.
Step 2: Run Windows Security Offline Scan
An offline scan runs before Windows fully loads, which makes it harder for malware to hide.
- Open Settings > Privacy & security > Windows Security.
- Select Virus & threat protection.
- Under Current threats, click Scan options.
- Choose Microsoft Defender Offline scan and click Scan now.
- The PC will restart and run the scan. Review results and remove any detected threats.
Step 3: Run a Second-Opinion Scanner
Defender is strong but not infallible. A second scanner catches what the first one misses.
- On a clean device, download the Malwarebytes installer from the official site.
- Transfer it via USB to the suspect PC (do not reconnect to the internet yet).
- Install, update the definitions, and run a Threat Scan.
- Quarantine everything found, then restart.
Step 4: Inspect Startup Items and Scheduled Tasks
Spyware often reinstalls itself through startup entries or scheduled tasks.
- Press
Ctrl + Shift + Escto open Task Manager. - Click the Startup apps tab. Disable anything you do not recognise by right-clicking and choosing Disable.
- Press
Win + R, typetaskschd.msc, and pressEnter. - Review the Task Scheduler Library for unfamiliar tasks, particularly ones that run on logon or at frequent intervals. Delete anything suspicious.
Step 5: Check Installed Programs and Browser Extensions
- Open Settings > Apps > Installed apps.
- Sort by Install date and review anything installed around the time symptoms began.
- Uninstall unfamiliar programs, especially anything labelled as a "system optimiser", "PDF converter", or "search protector".
- In your browser (Edge, Chrome, or Firefox), open the extensions page and remove any add-ons you did not install.
Step 6: Reset Browser Settings
- Microsoft Edge: Settings > Reset settings > Restore settings to their default values.
- Google Chrome: Settings > Reset settings > Restore settings to their original defaults.
- Mozilla Firefox: Help > More Troubleshooting Information > Refresh Firefox.
Step 7: Verify Network and Account Activity
Once the system is clean, reconnect to the internet and check for signs of compromise beyond the PC itself.
- Review sign-in activity for your Microsoft 365, Google, and banking accounts.
- Revoke any active sessions you do not recognise.
- Check your email rules for auto-forwarding you did not create.
- Run
netstat -anoin an elevated Command Prompt to list active connections; investigate any unfamiliar remote addresses.
Recovering After an Infection
Removing the malware is only half the job. Anything typed, viewed, or stored on the compromised machine should be considered exposed.
- From a known-clean device, change passwords for every account accessed on the infected PC. Start with email, banking, and any accounts holding business or client data.
- Enable multi-factor authentication on every account that supports it. Prefer authenticator app codes over SMS where possible.
- Rotate any API keys, tokens, or shared credentials used during the period of suspected compromise.
- Notify your bank if financial details were entered, and monitor statements for unauthorised transactions.
- Inform affected colleagues or clients if their data may have been exposed.
- Review your Windows login password and ensure the local account or Microsoft account uses a strong, unique password.
When to Reinstall Windows
If scans keep finding new infections, symptoms persist after removal, or you cannot confidently identify what was running on the machine, a clean reinstall is the safest path. Use the Microsoft Media Creation Tool to create a bootable USB on a clean PC, boot the infected machine from it, and choose the option to wipe all partitions during setup. After installation, install drivers, then immediately run Windows Update and a full Defender scan before restoring any data.
Preventing Future Infections
A few habits significantly reduce the chance of another compromise:
- Keep Windows, your browser, and all installed software up to date so security patches are applied promptly.
- Use a reputable antivirus or endpoint protection product and ensure real-time scanning is enabled.
- Be cautious with email attachments and links, even when they appear to come from known contacts.
- Download software only from official vendor websites and avoid third-party download portals.
- Use a standard user account for daily work and reserve an administrator account for software installation only.
- Enable multi-factor authentication on every account that supports it.
- Back up important files regularly to an external drive or trusted cloud service so you can recover quickly if a reinstall is needed.
Still Having Issues?
💻 Open a Ticket