How to recognise and remove malware or ransomware from your Windows PC
Summary
This guide helps you troubleshoot and resolve: How to recognise and remove malware or ransomware from your Windows PC. Follow the steps below to fix the issue.
Common Causes
Malware and ransomware are two of the most serious threats facing Windows PCs today. Malware (short for malicious software) can slow your computer, steal personal information, or give attackers remote access to your system. Ransomware is a particularly destructive type of malware that locks your files and demands payment for their release. Knowing how to spot the warning signs early and respond quickly can prevent data loss, financial harm, and extended downtime. This guide walks you through identifying an infection and removing it safely from your Windows PC.
Warning signs of infection
Malware and ransomware often announce themselves through unusual behaviour. If you notice any of the following, treat your PC as potentially compromised:
- Unexpected pop-ups, especially those warning of infections or demanding payment
- Files you cannot open, or files with strange new extensions (a common ransomware indicator)
- A ransom note demanding payment in cryptocurrency to unlock your data
- Your browser homepage or search engine has changed without your input
- Your PC is running unusually slowly, the fan is constantly loud, or CPU usage is high when idle
- Programs opening or closing on their own
- You cannot access Windows settings, Task Manager, or Control Panel
- Unknown programs appearing in your Start menu or system tray
- Friends or colleagues receiving strange messages from your email or social accounts
- Disabled or unresponsive antivirus software
What to do first
Before diving into cleanup, take a few precautions to limit the damage:
- Disconnect from the internet. Unplug the Ethernet cable or turn off Wi-Fi. This stops the malware from communicating with attackers or spreading to other devices.
- Disconnect from shared networks. If you are at a workplace, unplug from any network drives or shared folders to prevent lateral spread.
- Do not delete unfamiliar files yet. Some files may be needed for diagnosis or recovery.
- Note what happened. Write down any suspicious emails, websites, or downloads you recall. This information helps with remediation.
Quick Fix Steps
If you suspect a routine malware infection (not ransomware), these steps can resolve many cases:
- Open Settings > Privacy & security > Windows Security > Virus & threat protection.
- Under Current threats, select Scan options and choose Microsoft Defender Offline Scan.
- Click Scan now. Windows will restart and run the scan before Windows loads, which is more effective against persistent malware.
- Once the scan completes, review any detected threats and select Remove or Quarantine.
- Restart your PC and run a second full scan using Microsoft Defender Antivirus to confirm the system is clean.
Shift while selecting Restart from the Start menu, then choose Troubleshoot > Advanced options > Startup Settings > Restart, and press 5 for Safe Mode with Networking.Detailed Instructions
Step 1: Boot into Safe Mode
Safe Mode loads Windows with only essential drivers and services, which prevents most malware from starting.
- Press
Win + Ito open Settings. - Go to System > Recovery.
- Under Advanced startup, click Restart now.
- After restart, choose Troubleshoot > Advanced options > Startup Settings > Restart.
- Press
4for Safe Mode, or5for Safe Mode with Networking if you need internet access for updates.
Step 2: Remove suspicious programs
- In Safe Mode, open Settings > Apps > Installed apps.
- Sort by Install date to find recently added programs.
- Look for anything you do not recognise or did not intentionally install.
- Click the three dots next to the suspicious app and choose Uninstall.
- Follow the prompts and restart when finished.
Step 3: Clear malicious startup items
- Press
Ctrl + Shift + Escto open Task Manager. - Click the Startup apps tab.
- Review each entry, paying attention to the Publisher column. Unknown or unsigned publishers are red flags.
- Right-click any suspicious entry and choose Disable.
- Repeat the process for scheduled tasks by opening Task Scheduler from the Start menu and reviewing tasks under Task Scheduler Library.
Step 4: Run a full antivirus scan
- Open Windows Security from the Start menu.
- Select Virus & threat protection > Scan options.
- Choose Full scan and click Scan now.
- Allow the scan to complete. This may take an hour or more on larger drives.
- Review the results and remove or quarantine any detected threats.
Step 5: Use a second-opinion scanner
No single antivirus engine catches everything. Running a reputable second scanner can catch threats Microsoft Defender missed.
- Malwarebytes Free — available from malwarebytes.com. Run a full system scan and remove anything detected.
- ESET Online Scanner — a browser-based scanner that does not require installation.
Download, install, and run a full scan. Remove any threats identified, then uninstall the scanner if you do not wish to keep it.
Step 6: Check your browser for hijackers
- Open your browser (Edge, Chrome, or Firefox).
- Review your installed extensions:
- Edge:
edge://extensions - Chrome:
chrome://extensions - Firefox:
about:addons
- Edge:
- Remove any extensions you did not install or do not recognise.
- Reset your browser's homepage and search engine via Settings > Privacy, search, and services (Edge) or the equivalent in your browser.
- Clear browsing data, including cached files and cookies.
Step 7: Check for ransomware damage
If your files have been encrypted or renamed with strange extensions, ransomware may have run on your system.
- Do not pay the ransom. There is no guarantee files will be restored.
- Check No More Ransom, a free resource run by Europol and security partners. It offers decryption tools for many known ransomware strains.
- Restore from a clean backup if you have one. Ensure the backup was created before the infection occurred.
- If no backup exists and no decryption tool is available, the encrypted files may be unrecoverable. Focus on removing the malware to prevent further damage.
Step 8: Change your passwords
Once your PC is clean, assume any credentials stored or entered on the device may have been compromised.
- From a different, trusted device, change passwords for your email, banking, social media, and any other important accounts.
- Enable multi-factor authentication (MFA) wherever possible.
- Use a unique password for each account. A password manager can help you generate and store strong passwords.
Step 9: Update Windows and software
- Open Settings > Windows Update.
- Click Check for updates and install any available updates, including optional ones.
- Update your browser and any other software you regularly use to patch known vulnerabilities.
Preventing future infections
A few habits greatly reduce the risk of repeat infections:
- Keep Windows and your applications up to date with the latest security patches.
- Do not click links or open attachments in unsolicited emails or messages.
- Download software only from official sources.
- Maintain regular backups stored on a device that is not permanently connected to your PC.
- Use reputable antivirus software and keep it enabled.
Still Having Issues?
💻 Open a Ticket