Think Your Computer Has a Virus? Do This, in This Order

Updated September 1, 2026

A laptop displaying code in a dim room

Not every misbehaving computer is infected — but some are, and the order you do things in matters: done wrong, you can wipe evidence, lock yourself out of accounts, or hand your passwords to the people who put the malware there.

Read the symptoms first — they tell you what you are dealing with, and a slow computer is usually just a slow computer.

What the symptoms actually tell you

Different infections leave different fingerprints. Match yours before you touch anything.

  • Pop-ups outside the browser, a home page that changed itself, searches that land somewhere odd. Adware or a browser hijacker — annoying, common, and usually removable in an afternoon.
  • A full-screen warning with an alarm sound and a phone number. Not an infection — a scam web page pretending to be one. Close the browser and see the fake Microsoft pop-up guide. Never call the number.
  • The fan roaring while you are doing nothing, the machine hot and sluggish. The signature of a cryptominer — your computer is working hard, just not for you. Task Manager will show an unfamiliar process pinning the CPU.
  • A new "antivirus" you never installed demanding payment. That program is the infection.
  • Friends getting emails you did not send, or sign-ins you do not recognize. An account problem as much as a computer problem — passwords move to the top of your list.
  • Plain slowness with none of the above. Usually not malware — a full disk, too many startup programs, or old hardware. Work through the slow-computer checklist before assuming the worst.

Step 1: disconnect, and don't panic-click

Turn off Wi-Fi or unplug the network cable. Most malware needs the internet to do real damage — to send your data out, download more of itself, or take instructions.

Two things you never do: call a phone number a pop-up shows you, or let a "support agent" from one connect to the machine — that is the scam itself. If a note is demanding payment for your files, stop here and go straight to the ransomware first-24-hours guide — a different emergency with its own order.

Step 2: run the scanner you already own

Windows Security, built into Windows 10 and 11, is genuinely good — and already installed.

  1. Open Windows Security → Virus & threat protection → Scan options and run a Full scan — not the quick one. Let it quarantine what it finds, restart, and run it again until a pass comes back clean.
  2. From the same screen, run the Microsoft Defender Offline scan. This restarts the computer and scans before Windows loads — how you catch rootkits that hide while Windows runs. About fifteen minutes, and the step most people skip.

Step 3: get a second opinion from Malwarebytes

No single engine catches everything, and adware in particular slips past the big ones. Malwarebytes' free tier is an on-demand scanner — you click, it scans, it removes — with no real-time protection, still the model as of September 2026. For a one-off cleanup, that is exactly the right tool. Premium adds always-on shields (published rates start around $45 a year for one device as of September 2026), but Windows Security already covers that part.

Download it by typing malwarebytes.com yourself, not by clicking an ad — fake download pages for security tools are a favourite way to turn one infection into two.

Norton and McAfee sell competent suites on a subscription model — as of September 2026, a discounted first year that auto-renews noticeably higher, so judge them on the renewal price. For removing an infection you already have, the free scans above do the work.

The fake-cleaner trap

Do not install three more "cleaner" apps from ads — most are junk or worse. The pattern never changes: a free "scan" finds thousands of alarming-sounding problems, then wants a payment to fix them. Registry cleaners, driver updaters, RAM boosters — none of them remove malware, and some of them are malware. Two reputable scanners is plenty. If both come back clean twice, the machine is clean.

Step 4: purge the browser

If your symptom was redirects, pop-ups or a changed home page, the infection probably lives in the browser, not Windows — and scanners do not always reach it.

  1. Extensions. Remove anything you do not remember installing, plus anything you no longer use. Hijacked or quietly sold-off extensions are one of the most common infections there is.
  2. Home page and search engine. Set both back in settings. If a setting snaps back after you change it, something is enforcing it — keep hunting.
  3. Notification permissions. Spam sites ask to "show notifications", then push fake virus alerts that look like they come from Windows. In site settings, strip notification permission from any site you do not recognize.
  4. If it still misbehaves, use the browser's own reset-settings option. You keep bookmarks and saved passwords; you lose the junk.

Step 5: change your passwords — from a different device

If the scanners found anything real, assume passwords typed on that machine were seen. Use your phone — on cellular data, not the house Wi-Fi, in case the router is also suspect — and change your email password first, because email resets everything else. Then banking, then anywhere with a saved card. If your email shows sign-ins you do not recognize, follow the email-hacked first hour as well.

Once the machine is confirmed clean, rotate your remaining passwords over the following days and turn on two-factor authentication — the twenty-minute job that turns a stolen password into a dead end.

When wipe-and-reinstall is the honest answer

Sometimes cleaning is the wrong economics. If every scan finds something new, if the machine still misbehaves after two clean passes, or if the infection was a rootkit or a banking trojan rather than routine adware, stop playing whack-a-mole. A Windows reset with "Remove everything" — or a clean reinstall — takes an evening and removes virtually everything, including the things scanners argue about.

Copy documents, photos and desktop files off first; data files are generally safe. Do not restore old programs or run old installers from the backup — that is how the problem comes home again. Reinstall applications fresh, from their makers' own sites.

The Mac reality

Macs get malware too — rarely classic viruses, mostly adware, hijackers and fake "cleaners" inside bogus installers or cracked software. macOS blocks known malware on its own, so the triage is shorter: check System Settings for configuration profiles you did not create (a favourite hijacker trick), purge the browser as above, and run the free Mac version of Malwarebytes as the second opinion. A paid suite is rarely worth it on a Mac.

While the machine is still suspect

  • Do not pay anything a pop-up demands, ever.
  • Do not bank or shop on it until you are confident it is clean.
  • Do not plug in your backup drive until the final scans are clean — a backup that touches an infected machine can carry the problem forward.
  • Do think about how it got in. Most infections arrive through one click, and learning to spot a phishing email is the cheapest prevention there is.

If you'd rather watch someone else clean it

A deep clean is methodical, slightly tedious work — exactly the kind of job to hand off. Post the problem free on Koadi, set a fixed price or take bids from vetted, identity-verified technicians, and watch every step over a screen-share. Remote help covers every US state; when hands are needed, a local vetted technician comes to you. Payment sits in escrow until you approve the fix — if the machine is not clean, you have not paid. Or call (848) 266-6363 and tell us what the screen is doing.

Frequently asked questions

Is Windows Defender good enough to remove a virus?
For most infections, yes. Run Windows Security's full scan, then the Microsoft Defender Offline scan, which checks the machine before Windows loads. Where it is weakest is adware and junk programs, so pair it with a free Malwarebytes scan. If things keep coming back after both, the machine needs a professional or a clean reinstall.
Do I need to pay for antivirus in 2026?
Most home users do not. Windows Security is built in and handles real-time protection, and the free tier of Malwarebytes covers on-demand second opinions. Paid suites bundle extras like VPNs and identity monitoring — if you want one, compare the auto-renewal price rather than the discounted first year, because the two usually differ.
Will resetting my PC get rid of a virus?
Almost always. A Windows reset with the "Remove everything" option, or a clean reinstall, removes virtually all malware, including rootkits that scanners struggle with. Copy documents and photos off first — data files are generally safe — but reinstall programs fresh rather than restoring old installers, or you may bring the infection back with them.
Can Macs get viruses?
Yes, though rarely classic viruses — mostly adware, browser hijackers and fake cleaner apps delivered through bogus installers. macOS blocks known malware on its own. Redirected searches or a changed home page usually mean a browser extension or a configuration profile to remove. Download any cleanup tool from the maker's own site, never from an ad.

Still stuck?

Post this problem on Koadi — a vetted technician picks it up in minutes, and you don't pay until it's fixed.

Get a tech on it
← All fix-it guides