Your antivirus just found something. Or worse — your browser keeps redirecting, pop-ups appear out of nowhere, and your computer is crawling. The nuclear option is reinstalling Windows, but that means losing your programs, settings, and hours of setup time. The good news: most malware infections can be cleaned without wiping the drive.
Here's the exact process our technicians use to remove malware remotely — the same steps, in order, every time.
1. Disconnect from the Internet
Before you start cleaning, pull the ethernet cable or turn off WiFi. Active malware can download additional payloads, exfiltrate your data, or re-infect cleaned files while you're working. Cutting the connection stops it cold.
2. Boot into Safe Mode with Networking
Safe Mode loads only essential Windows drivers and services, which prevents most malware from running and hiding. You need networking enabled so you can download scanning tools if you don't already have them.
How to enter Safe Mode (Windows 10/11)
- Hold Shift and click Restart from the Start menu
- Choose Troubleshoot > Advanced Options > Startup Settings > Restart
- Press 5 or F5 for Safe Mode with Networking
If your computer won't boot normally, you can force it by holding the power button during startup three times in a row. Windows will automatically enter recovery mode.
3. Run Malwarebytes (Free Version)
Windows Defender is decent for prevention but mediocre at removal. Malwarebytes is the industry standard for cleaning active infections. Download the free version from malwarebytes.com — you don't need the premium trial.
- Install and update the definitions
- Run a Threat Scan (not Quick Scan)
- Quarantine everything it finds
- Restart when prompted
mbsetup.exe to something random like fixpc.exe before running it. Many malware families block processes by name.
4. Run a Second-Opinion Scanner
No single scanner catches everything. After Malwarebytes, run one of these as a second opinion:
- HitmanPro — cloud-based, catches rootkits that local scanners miss
- ESET Online Scanner — thorough deep scan, free, no install needed
- Microsoft Safety Scanner — Microsoft's own emergency removal tool
If either scanner finds additional threats, quarantine them and restart again.
5. Clean Up Browser Hijacks
Malware loves your browser. Even after the core infection is removed, you may still have:
- Rogue browser extensions you didn't install
- A changed homepage or default search engine
- Redirect rules that send you to ad pages
For every browser you use:
- Open the extensions/add-ons page and remove anything you don't recognize
- Reset the homepage and default search engine in settings
- Clear all cookies and cached data
- If problems persist, use the browser's built-in Reset feature (this doesn't delete bookmarks)
6. Check Startup Programs and Scheduled Tasks
Malware survives reboots by adding itself to startup. Open Task Manager (Ctrl+Shift+Esc) and check the Startup tab. Disable anything suspicious — random strings of characters, programs you don't recognize, or items with no publisher listed.
Also check Task Scheduler (taskschd.msc). Sophisticated malware creates scheduled tasks that re-download the payload even after you've removed the executable. Look for tasks with suspicious names or paths pointing to %AppData% or %Temp%.
7. Verify the Cleanup
After all scans and restarts:
- Boot normally (not Safe Mode) and use the computer for 15-20 minutes
- Open your browser — does it behave normally?
- Check Task Manager — is CPU usage normal at idle (under 10%)?
- Run one final Malwarebytes scan to confirm it's clean
When Removal Isn't Enough
Some infections — particularly rootkits, bootkits, and ransomware that has encrypted your files — can't reliably be cleaned without a reinstall. If you've followed every step above and the malware keeps coming back, or if your files have been encrypted, it's time to call in help.
We handle malware removal remotely every day. Our technicians connect to your screen, run professional-grade tools, and clean the infection in a single session — $99 flat rate, no hourly charges. If we can't fix it remotely, you don't pay.