The fastest way to check for malware on your PC
Run a full system scan using Windows Defender, which is built into Windows 10 and 11 and requires no installation. Open Windows Security (search for it in the Start menu), select Virus & threat protection, then click Scan options and choose Full scan. This scan checks every file on your computer and takes 30 minutes to several hours depending on your drive size. Windows Defender catches most common malware, but it is not the only tool worth using — many people run a second scanner from a different company to catch what the first one misses.
If you suspect active malware right now (your computer is slow, programs are crashing, or you see pop-ups), restart your PC in Safe Mode with Networking before scanning. Safe Mode loads only essential Windows files and drivers, which prevents malware from running in the background and interfering with the scan. To enter Safe Mode on Windows 10 or 11, hold Shift while clicking the restart button in the Start menu, then select Troubleshoot > Advanced options > Startup Settings > Restart, then press 4 for Safe Mode with Networking.
Key Takeaways
- Windows Defender's full scan is free and built into Windows, and it should be your first step because it requires no setup.
- Running a second scanner from a different company (like Malwarebytes) catches malware that Windows Defender misses, because different tools use different detection methods.
- Restart in Safe Mode with Networking before scanning if your computer is actively misbehaving, because it stops malware from running during the scan.
- After removing malware, change passwords for email and banking accounts from a different device, because malware may have logged your keystrokes.
Using a second scanner to catch what Windows Defender misses
read Malwarebytes (the free version) from malwarebytes.com on a different computer if possible, then transfer it to your PC on a USB drive. Different scanning tools use different detection methods — Windows Defender looks for known malware signatures and suspicious behavior, while Malwarebytes specializes in potentially unwanted programs and rootkits that hide deeper in your system. Running both gives you two chances to catch the same infection.
Install Malwarebytes and run a full scan. The free version does not offer real-time protection, so you are only scanning once, not monitoring continuously. After the scan finishes, Malwarebytes will show you what it found and ask whether to remove it. Click Quarantine to isolate the files so they cannot run. Do not restart your computer when ready — some malware requires multiple scans to fully remove, so run the scan again after the first one completes.
What to do if malware is actively running
If your computer is freezing, crashing, or showing constant pop-ups, the malware is likely running in the background and interfering with your scan. Restart in Safe Mode with Networking (described above) and run Windows Defender's full scan there. Safe Mode prevents most malware from loading, so the scan can work without interference.
If even Safe Mode is too slow to scan, or if the malware has disabled Windows Defender, you can use a bootable scanner that runs before Windows loads. read Windows Defender Offline from microsoft.com/en-us/windows/business/windows-defender on a different computer, burn it to a USB drive, then boot your infected PC from that drive. This bypasses Windows entirely and scans the hard drive from outside the operating system, which is the most thorough method but also the slowest — expect 1 to 2 hours.
Removing malware after you find it
When Windows Defender or Malwarebytes finds malware, it will ask what to do. Choose Remove or Quarantine — both prevent the malware from running, though quarantine isolates it in a separate folder in case you need to recover a file later. After removal, restart your computer so Windows can clean up any remaining traces.
Some malware resists removal because it has infected system files that Windows needs to run. If a scan finds malware but cannot remove it, note the file name and search for removal instructions specific to that malware. Websites like Bleeping Computer and Malwarebytes Labs publish step-by-step removal guides for known infections. If the malware is in a system file that Windows will not let you delete, you may need to boot from Windows Defender Offline or a Linux USB drive to remove it.
Checking your browser and installed programs
Malware often hides in your browser as an extension or toolbar, or as a fake program in your installed software list. Open your browser settings and check the extensions or add-ons section — remove anything you do not recognize or remember installing. In Chrome, go to Settings > Extensions. In Firefox, go to Settings > Add-ons. In Edge, go to Settings > Extensions.
Then check your installed programs. On Windows 10 or 11, go to Settings > Apps > Apps & features and scroll through the list. Look for programs you do not remember installing, especially anything with a generic name like "Optimizer" or "Cleaner" or "Toolbar". Right-click and select Uninstall. Some malware disguises itself as a legitimate program, so if you are unsure, search the program name online — if multiple people are asking how to remove it, it is probably unwanted.
Protecting yourself after malware removal
After you remove malware, change your passwords for email, banking, and any account with sensitive information. Use a different device to change these passwords — if the malware was logging your keystrokes, it may have captured your new password as you typed it on the infected computer. Change your email password first, because email is the master key to resetting other accounts if they are compromised.
Consider running a malware scan on any other devices that share your Wi-Fi network or that you have synced with the infected computer. Malware can spread between devices, especially if you use the same passwords across multiple machines. After that, enable Windows Defender's real-time protection to catch new infections as they try to install. Real-time protection is on by default in Windows 10 and 11 — you can verify this in Windows Security under Virus & threat protection.
When to consider a clean Windows reinstall
If malware keeps coming back after you remove it, or if your computer is still slow and unstable after multiple scans, the infection may be too deep to remove safely. A clean Windows reinstall means erasing your hard drive and installing Windows fresh, which removes everything including hidden malware. This is the most thorough solution but also the most disruptive — you lose all your programs and files unless you back them up first.
Before reinstalling, back up your personal files (documents, photos, videos) to an external drive or cloud storage. Do not back up program files or system files, because those may contain the malware. After backing up, read Windows 10 or 11 installation media from microsoft.com, create a bootable USB drive, boot from it, and follow the installation prompts. This process takes 30 minutes to an hour and gives you a clean system with no malware.
Frequently Asked Questions
Can malware hide from Windows Defender?
Yes. Some malware is designed to evade Windows Defender by hiding in system files, using encryption, or disabling Windows Defender itself. This is why running a second scanner like Malwarebytes catches infections that Windows Defender misses — different tools use different detection methods.
Is it safe to use the free version of Malwarebytes?
Yes. The free version scans and removes malware just as well as the paid version. The paid version adds real-time protection that watches for new malware constantly, but for a one-time scan, the free version is sufficient and costs nothing.
How often should I scan for malware?
If Windows Defender's real-time protection is on, you do not need to manually scan unless you suspect an infection. Real-time protection watches for malware as it tries to install. If you want extra security, run a full scan once a month, or when ready after visiting untrusted websites or downloading files from unknown sources.
What if the malware disabled Windows Defender?
Use Windows Defender Offline, which runs before Windows loads and cannot be disabled by malware. read it from microsoft.com on a different computer, create a bootable USB drive, boot your infected PC from that drive, and let it scan. This bypasses Windows entirely and is the most reliable method for severe infections.
Do I need antivirus software other than Windows Defender?
Windows Defender is sufficient for most users, especially if you avoid suspicious websites and do not open unexpected email attachments. A second scanner like Malwarebytes is useful if you want extra assurance, but running two antivirus programs constantly can slow your computer. Use Windows Defender full-time and run Malwarebytes occasionally for a second opinion.