Home › Knowledgebase › KB-223

How to recognise and remove malware or ransomware from your Windows PC

Summary

This guide helps you troubleshoot and resolve: How to recognise and remove malware or ransomware from your Windows PC. Follow the steps below to fix the issue.

Quick Tip: Need immediate assistance? 💻 Open a Ticket

Common Causes

Malware and ransomware are two of the most serious threats facing Windows PCs today. Malware (short for malicious software) can slow your computer, steal personal information, or give attackers remote access to your system. Ransomware is a particularly destructive type of malware that locks your files and demands payment for their release. Knowing how to spot the warning signs early and respond quickly can prevent data loss, financial harm, and extended downtime. This guide walks you through identifying an infection and removing it safely from your Windows PC.

Warning signs of infection

Malware and ransomware often announce themselves through unusual behaviour. If you notice any of the following, treat your PC as potentially compromised:

If you see a ransom note demanding payment, do not pay. Disconnect the affected PC from the network immediately and contact 220 for assistance before taking further action.

What to do first

Before diving into cleanup, take a few precautions to limit the damage:

  1. Disconnect from the internet. Unplug the Ethernet cable or turn off Wi-Fi. This stops the malware from communicating with attackers or spreading to other devices.
  2. Disconnect from shared networks. If you are at a workplace, unplug from any network drives or shared folders to prevent lateral spread.
  3. Do not delete unfamiliar files yet. Some files may be needed for diagnosis or recovery.
  4. Note what happened. Write down any suspicious emails, websites, or downloads you recall. This information helps with remediation.

Quick Fix Steps

If you suspect a routine malware infection (not ransomware), these steps can resolve many cases:

  1. Open Settings > Privacy & security > Windows Security > Virus & threat protection.
  2. Under Current threats, select Scan options and choose Microsoft Defender Offline Scan.
  3. Click Scan now. Windows will restart and run the scan before Windows loads, which is more effective against persistent malware.
  4. Once the scan completes, review any detected threats and select Remove or Quarantine.
  5. Restart your PC and run a second full scan using Microsoft Defender Antivirus to confirm the system is clean.
If Windows Security itself will not open or has been disabled, boot into Safe Mode with Networking before running the scan. Hold Shift while selecting Restart from the Start menu, then choose Troubleshoot > Advanced options > Startup Settings > Restart, and press 5 for Safe Mode with Networking.

Detailed Instructions

Step 1: Boot into Safe Mode

Safe Mode loads Windows with only essential drivers and services, which prevents most malware from starting.

  1. Press Win + I to open Settings.
  2. Go to System > Recovery.
  3. Under Advanced startup, click Restart now.
  4. After restart, choose Troubleshoot > Advanced options > Startup Settings > Restart.
  5. Press 4 for Safe Mode, or 5 for Safe Mode with Networking if you need internet access for updates.

Step 2: Remove suspicious programs

  1. In Safe Mode, open Settings > Apps > Installed apps.
  2. Sort by Install date to find recently added programs.
  3. Look for anything you do not recognise or did not intentionally install.
  4. Click the three dots next to the suspicious app and choose Uninstall.
  5. Follow the prompts and restart when finished.
Common culprits hide behind generic names like "System Update", "Driver Manager", or "PC Optimiser". If you are unsure, search the program name online before uninstalling.

Step 3: Clear malicious startup items

  1. Press Ctrl + Shift + Esc to open Task Manager.
  2. Click the Startup apps tab.
  3. Review each entry, paying attention to the Publisher column. Unknown or unsigned publishers are red flags.
  4. Right-click any suspicious entry and choose Disable.
  5. Repeat the process for scheduled tasks by opening Task Scheduler from the Start menu and reviewing tasks under Task Scheduler Library.

Step 4: Run a full antivirus scan

  1. Open Windows Security from the Start menu.
  2. Select Virus & threat protection > Scan options.
  3. Choose Full scan and click Scan now.
  4. Allow the scan to complete. This may take an hour or more on larger drives.
  5. Review the results and remove or quarantine any detected threats.

Step 5: Use a second-opinion scanner

No single antivirus engine catches everything. Running a reputable second scanner can catch threats Microsoft Defender missed.

Download, install, and run a full scan. Remove any threats identified, then uninstall the scanner if you do not wish to keep it.

Step 6: Check your browser for hijackers

  1. Open your browser (Edge, Chrome, or Firefox).
  2. Review your installed extensions:
    • Edge: edge://extensions
    • Chrome: chrome://extensions
    • Firefox: about:addons
  3. Remove any extensions you did not install or do not recognise.
  4. Reset your browser's homepage and search engine via Settings > Privacy, search, and services (Edge) or the equivalent in your browser.
  5. Clear browsing data, including cached files and cookies.

Step 7: Check for ransomware damage

If your files have been encrypted or renamed with strange extensions, ransomware may have run on your system.

  1. Do not pay the ransom. There is no guarantee files will be restored.
  2. Check No More Ransom, a free resource run by Europol and security partners. It offers decryption tools for many known ransomware strains.
  3. Restore from a clean backup if you have one. Ensure the backup was created before the infection occurred.
  4. If no backup exists and no decryption tool is available, the encrypted files may be unrecoverable. Focus on removing the malware to prevent further damage.

Step 8: Change your passwords

Once your PC is clean, assume any credentials stored or entered on the device may have been compromised.

  1. From a different, trusted device, change passwords for your email, banking, social media, and any other important accounts.
  2. Enable multi-factor authentication (MFA) wherever possible.
  3. Use a unique password for each account. A password manager can help you generate and store strong passwords.

Step 9: Update Windows and software

  1. Open Settings > Windows Update.
  2. Click Check for updates and install any available updates, including optional ones.
  3. Update your browser and any other software you regularly use to patch known vulnerabilities.

Preventing future infections

A few habits greatly reduce the risk of repeat infections:

If you suspect a serious infection, are dealing with ransomware, or are unsure about any step, stop and contact 220 for assistance. Do not pay any ransom demand.

Still Having Issues?

Need more help? If the issue persists after trying these steps, please open a support ticket and our team will assist you.

💻 Open a Ticket