Home › Knowledgebase › KB-280

How to recognise and remove a keylogger or spyware from your Windows PC

Summary

This guide helps you troubleshoot and resolve: How to recognise and remove a keylogger or spyware from your Windows PC. Follow the steps below to fix the issue.

Quick Tip: Need immediate assistance? 💻 Open a Ticket

Common Causes

Keyloggers and spyware are malicious programs designed to silently monitor your activity, capture keystrokes, and steal sensitive information such as passwords, banking details, and business credentials. Because they run quietly in the background, they can be difficult to detect. This guide walks you through recognising the warning signs, removing infections from a Windows PC, and securing your accounts afterwards. If you suspect an active compromise, treat every password stored on or used from the machine as exposed.

Warning Signs Your PC May Be Compromised

No single symptom confirms an infection, but several together should raise suspicion:

If you handle banking, payroll, or client credentials on the affected machine, disconnect it from the network immediately and change your passwords from a different, trusted device before continuing.

Quick Fix Steps

  1. Disconnect from the internet (turn off Wi-Fi or unplug the Ethernet cable).
  2. Back up critical business files to an external drive, but only files you can verify are clean (avoid executables and scripts).
  3. Run a full scan with Windows Security, then a second scan with a reputable on-demand tool such as Malwarebytes.
  4. Remove anything detected and restart the PC.
  5. Review startup items, scheduled tasks, and browser extensions for anything unfamiliar.
  6. Change all passwords from a clean device and enable multi-factor authentication.
  7. If infection persists, perform a full Windows reset or clean reinstall.

Detailed Removal Instructions

Step 1: Disconnect and Back Up

Unplugging the network stops the spyware from transmitting captured data and prevents it from downloading further payloads. Back up only documents, spreadsheets, and other data files you trust. Do not back up program installers, .exe files, browser profiles, or email archives from the suspect machine, as these may harbour the infection.

Step 2: Run Windows Security Offline Scan

An offline scan runs before Windows fully loads, which makes it harder for malware to hide.

  1. Open Settings > Privacy & security > Windows Security.
  2. Select Virus & threat protection.
  3. Under Current threats, click Scan options.
  4. Choose Microsoft Defender Offline scan and click Scan now.
  5. The PC will restart and run the scan. Review results and remove any detected threats.

Step 3: Run a Second-Opinion Scanner

Defender is strong but not infallible. A second scanner catches what the first one misses.

  1. On a clean device, download the Malwarebytes installer from the official site.
  2. Transfer it via USB to the suspect PC (do not reconnect to the internet yet).
  3. Install, update the definitions, and run a Threat Scan.
  4. Quarantine everything found, then restart.

Step 4: Inspect Startup Items and Scheduled Tasks

Spyware often reinstalls itself through startup entries or scheduled tasks.

  1. Press Ctrl + Shift + Esc to open Task Manager.
  2. Click the Startup apps tab. Disable anything you do not recognise by right-clicking and choosing Disable.
  3. Press Win + R, type taskschd.msc, and press Enter.
  4. Review the Task Scheduler Library for unfamiliar tasks, particularly ones that run on logon or at frequent intervals. Delete anything suspicious.

Step 5: Check Installed Programs and Browser Extensions

  1. Open Settings > Apps > Installed apps.
  2. Sort by Install date and review anything installed around the time symptoms began.
  3. Uninstall unfamiliar programs, especially anything labelled as a "system optimiser", "PDF converter", or "search protector".
  4. In your browser (Edge, Chrome, or Firefox), open the extensions page and remove any add-ons you did not install.
Pay close attention to programs with no publisher name, missing icons, or names that look like random character strings. These are common hallmarks of malicious software.

Step 6: Reset Browser Settings

  1. Microsoft Edge: Settings > Reset settings > Restore settings to their default values.
  2. Google Chrome: Settings > Reset settings > Restore settings to their original defaults.
  3. Mozilla Firefox: Help > More Troubleshooting Information > Refresh Firefox.

Step 7: Verify Network and Account Activity

Once the system is clean, reconnect to the internet and check for signs of compromise beyond the PC itself.

Recovering After an Infection

Removing the malware is only half the job. Anything typed, viewed, or stored on the compromised machine should be considered exposed.

  1. From a known-clean device, change passwords for every account accessed on the infected PC. Start with email, banking, and any accounts holding business or client data.
  2. Enable multi-factor authentication on every account that supports it. Prefer authenticator app codes over SMS where possible.
  3. Rotate any API keys, tokens, or shared credentials used during the period of suspected compromise.
  4. Notify your bank if financial details were entered, and monitor statements for unauthorised transactions.
  5. Inform affected colleagues or clients if their data may have been exposed.
  6. Review your Windows login password and ensure the local account or Microsoft account uses a strong, unique password.

When to Reinstall Windows

If scans keep finding new infections, symptoms persist after removal, or you cannot confidently identify what was running on the machine, a clean reinstall is the safest path. Use the Microsoft Media Creation Tool to create a bootable USB on a clean PC, boot the infected machine from it, and choose the option to wipe all partitions during setup. After installation, install drivers, then immediately run Windows Update and a full Defender scan before restoring any data.

Restoring from a system image or old backup can reintroduce the infection. Only restore personal documents, never applications, browser profiles, or full disk images taken from the compromised machine.

Preventing Future Infections

A few habits significantly reduce the chance of another compromise:

If you are part of a managed business environment, report the incident to your IT team or managed service provider before attempting removal. They may need to preserve evidence, isolate the device on the network, and check whether other machines are affected.

Still Having Issues?

Need more help? If the issue persists after trying these steps, please open a support ticket and our team will assist you.

💻 Open a Ticket