How to Remove Malware From a PC
Stop banking, rotate passwords from a clean device, then run Defender and optional cleanup. Published USD pricing; scores not assigned.
Bottom line
How to Remove Malware From a PC: finish free controls first, then consider paid tools only for a leftover job you can name. We do not publish product scores on this page. Scores stay not assigned until verification is complete.
Key takeaways
- Stop using the suspect PC for banking; change critical passwords from a clean device
- Run Windows Security full scan after updating security intelligence
- Boot to safe mode or use Defender offline scan if the PC is unstable
- Run a reputable on-demand cleaner from an official site (Malwarebytes Free or Premium shortlist)
- Restore from backup or clean-install Windows if the system remains untrustworthy
- Open the Antivirus Finder only after free steps if a leftover suite job remains
How it works
-
1Free
Contain the suspect PC before scanners
Stop entering passwords on a suspect PC when possible. Unplug drives you do not need, note suspicious behavior, and rotate email or banking credentials from a known-clean device.
- Unplug other drives you do not need
- Use a clean device to change email and banking passwords
- Note what suspicious behavior you saw
- Turn on MFA on email after you regain control
-
2Free
Scan with Microsoft Defender
Update security intelligence first, run a full scan, quarantine detections, then reboot and re-check. Use offline scan options in Windows Security when the PC is unstable or real-time protection looks broken.
- Update security intelligence first
- Quarantine detections and reboot
- Consider Defender offline scan if available on your build
- Confirm real-time protection is enabled afterward
-
3Optional paid
Optional cleanup shortlist tool
Malwarebytes is the cleanup-focused option after Defender. Prefer official Free on-demand cleanup first when that matches the job; Premium Standard showed from $59.99/yr on 2026-08-09 if you want ongoing prevention. Avoid stacking multiple real-time AVs.
- Download only from the official vendor site
- Run an on-demand scan first
- Reassess whether Premium is necessary after cleanup
- Do not install a second always-on suite beside Premium without a clear reason
-
4Free
Rebuild when trust is gone
If the PC still misbehaves after updates, Defender, and a reputable cleaner, restore from a known-good backup or clean-install Windows. Extra subscriptions cannot honestly guarantee every advanced infection is gone.
- Confirm a backup exists before wiping
- Reinstall only from trusted media
- Rotate passwords again after the rebuild
-
5Optional paid
Product analysis: Malwarebytes cleanup vs Bitdefender suite
Malwarebytes is the incident cleanup lane after Defender (Free on-demand verified; Windows Individual Standard from $59.99/yr on 2026-08-09; 60-day money-back advertised). Bitdefender Antivirus Plus from $24.99/yr first-year fits when the leftover job after the scare is multi-device always-on seats, not another on-demand scan. Do not invent removal percentages.
- Finish containment and Defender scans first
- Prefer official Free cleanup before Premium
- Switch to suite seats only when the leftover job is annual coverage
-
6Free
Scenario: redirects after a shady installer, Defender still on
Keep Defender real-time enabled. Run a full or offline scan, then Malwarebytes Free cleanup from the official site if leftovers remain. Do not disable Defender to install a panic suite from an ad.
- Defender real-time stays on
- Official cleaner download only
- Skip dual always-on engines
-
7Free
Scenario forks that change the answer
Banking still happening on the suspect PC: stop; rotate passwords from a clean device before any cleaner logo. Defender full or offline scan already cleared symptoms and habits are healthy: skip paid cleanup this week. Residual scare after free OS hygiene: Malwarebytes Free on-demand cleanup from the official download, keep Defender on. Household also needs annual multi-device seats after the scare: finish containment, then shortlist Bitdefender suite packaging instead of dual always-on engines. System still untrustworthy after updates, Defender, and a reputable cleaner: restore from known-good backup or clean-install Windows.
- Match response to contamination state, not ads
- Refuse dual always-on engines
- Prefer reinstall over endless scanner stacking
-
8Free
Scenario: still banking on the infected PC
Stop. Use a clean phone or another healthy device to rotate email and banking passwords with MFA. Cleaner logos cannot undo active session theft while you keep logging into money apps on the suspect machine.
- Banking and email from a clean device only
- Rotate high-value passwords first
- Return to Defender and official cleanup after containment
-
9Free
Scenario: PC unstable after a USB scare
If Windows will not stay healthy after a random USB install, prefer Defender offline scan or Safe Mode cleanup before buying a new suite. Unplug nonessential drives, scan, then reassess. Paid cleaners are optional after free OS recovery steps, not a substitute for a rebuild when trust is gone.
- Unplug nonessential external drives
- Try Defender offline or Safe Mode full scan
- Rebuild if the system stays untrustworthy after free steps
-
10Free
Scenario: ransomware note but backups restore
Disconnect, restore from the known-good backup, and rotate passwords from a clean device. Do not pay a ransom from fear copy. Prefer Malwarebytes cleanup only if residual scare remains after restore; Bitdefender seats are a later leftover if multi-device coverage remains.
- Restore from tested backup first
- Rotate critical passwords from a clean device
- Skip dual always-on engines during recovery
-
11Free
Scenario: browser extensions left after cleanup
After Defender and optional Malwarebytes cleanup, audit browser extensions and search settings on a clean profile. Paid AV does not replace removing unknown toolbars that keep redirecting. Prefer rebuild if the profile stays untrustworthy.
- Remove unknown extensions and reset search defaults
- Keep one real-time engine maximum
- Rebuild the browser profile if redirects continue
-
12Free
Scenario: remote-help tool left installed after the scare
Uninstall leftover TeamViewer-style helpers and revoke any shared sessions before suite shopping. Paid cleaners do not close a remote-access path you forgot to remove.
- Remove unused remote-help apps
- Revoke shared sessions from a clean device
- Return to Defender and official cleanup after containment
-
13Free
Final verdict
Contain first. After Defender scans: Malwarebytes when residual cleanup is the leftover job; Bitdefender only when multi-device seats remain after the scare. Overall score is not assigned. Prefer rebuild when trust is gone. Commissions
- Containment before cleaner CTAs
- One real-time engine maximum
- Re-check same-day
Limits of this explainer
- Rootkits that require professional rebuilds
- Stolen session tokens already used elsewhere
- Guaranteed 100% removal outcomes
- Requests for your passwords; we never ask
- Fabricated detection-rate promises for any cleaner
Sources
Final verdict
Contain first, confirm Defender is healthy, then optional cleanup. Overall score is not assigned. Commissions never set this guide.
FAQ
Frequently asked questions
Final verdict: what should I do first?
Can you guarantee malware removal?
Should I pay immediately?
What prices appear on the product cards?
Can I suggest a correction to this guide?
Who should not buy a paid device security product after this guide?
Update history
Price captures verified 2026-08-09. Re-check free OS controls and any listed prices same-day before purchase.
Continue reading
Hub, tools, and related guides.
Expert guides & insights
Related guides
Stay in the same problem space without jumping brands.
Continue with Antivirus finder
Open a live tool or guide for the next practical step.
Ready for a clearer next step?
Continue with a live guide or tool on SecurityChecklist.
Page information & sources
About this page
Windows malware cleanup: stop banking, rotate passwords from a clean device, then Defender and optional Malwarebytes. Published USD pricing notes.
Corrections
Commercial disclosure
Some product links may be commercial. Affiliate relationships never set rankings. See the affiliate disclosure.