Is your PC suddenly sluggish, flooded with pop-ups, or acting strangely? Here's exactly how to find and remove malware from Windows without paying a cent.
- August 28, 2026
AceShowbiz - You know that sinking feeling. You're just trying to check your bank balance, but your cursor is moving on its own, or a new toolbar has mysteriously appeared in your browser. Maybe your fan is spinning like a jet engine while you're staring at a blank desktop. According to a 2026 report from AV-TEST, over 450,000 new malicious programs are registered every single day. The odds are that at some point, you will have to deal with a rogue file. The good news? You don't need to pay a $200 "virus removal" service at a big-box store. You can do this yourself in about an hour with a few free tools and a bit of patience.
Let's be clear about one thing first: the built-in Windows Defender is actually pretty good these days. It catches a lot of junk in real-time. However, it often misses "Potentially Unwanted Programs" (PUPs) like browser hijackers and adware, which are the most common culprits behind random pop-ups and homepage changes. If you are reading this, your current defenses have likely failed, or you disabled them at some point to install that "free" game mod. Either way, we are going back to basics. Here is your practical, hands-on guide to scrubbing your system clean.
Step 1: Disconnect and Enter Safe Mode
Before you run any scans, you need to cut the malware off from the internet. Many strains of malware communicate with a "command and control" server to download additional payloads or to receive instructions. If you run a scan while connected, the malware might fight back, re-infect files, or encrypt your data in a panic. Unplug your Ethernet cable or turn off your Wi-Fi adapter. This puts you in a controlled environment where the malicious code is effectively blind.
Next, you need to boot into Safe Mode. This is a diagnostic state where Windows loads only the essential drivers and services, which means most malware won't load automatically. To do this on Windows 10 or 11, hold down the Shift key while clicking "Restart" in the Start menu. This will boot you into the blue "Choose an option" screen. Navigate to Troubleshoot > Advanced options > Startup Settings, and click Restart. When the list appears, press 4 or F4 to select "Enable Safe Mode."
In Safe Mode, your screen resolution will look weird, and your background might be black. That is normal. Do not panic. Open your Task Manager (Ctrl + Shift + Esc) and look at the "Startup" tab. If you see any entries with weird names like "RandomNumbers.exe" or "Browser Helper," make a note of them, but don't delete anything yet. We are going to use a shotgun approach first to clear out the obvious junk.
Step 2: Uninstall the Obvious Suspects
Now that you are in Safe Mode, head to Settings > Apps > Installed apps. Scroll through the list and look for anything you didn't install. Common red flags include "Search Engine Protector," "Coupon Server," "Minecraft Mod Installer," or anything with the word "Toolbar" in it. If you see a program that looks suspicious, check the install date. If it matches the exact day your PC started acting up, that is your culprit. Click the three dots next to it and select "Uninstall."
Here is where it gets tricky: some malware is "persistent." If you uninstall a program and it immediately reappears in the list, or if you get an error saying "You do not have access," the malicious process is still running in the background. That is why we are in Safe Mode. If the uninstaller fails, we will handle it with a dedicated removal tool in the next step.
Don't forget to check your browser extensions. Open Edge or Chrome (if they work in Safe Mode) and go to the extensions page. Remove any extension you don't recognize, especially ones that claim to "enhance your shopping experience" or "save you money." These are almost always adware. They inject ads into pages you visit, and they slow down your browser by tracking your every move. Clearing these out manually takes two minutes and saves you a headache later.
Step 3: Run a Full System Scan with Microsoft Defender
Since you are on Windows, you already have a powerful scanner built-in. Even if you usually use a third-party antivirus, Microsoft Defender is a solid second opinion. In Safe Mode, open the Windows Security app (search for "Windows Security" in the Start menu). Click on "Virus & threat protection" and then select "Scan options." Choose Full scan and click "Scan now."
This scan will take a while—anywhere from 30 minutes to two hours, depending on how much data you have. It checks every file on your hard drive, including system files and temporary folders. If Defender finds something, it will either quarantine it or ask you to take action. Click "Remove" or "Quarantine" and let it do its job. Don't interrupt this process; let it finish completely.
If Defender finds nothing, that doesn't mean you are in the clear. Many modern threats are "fileless" or hidden in the registry. This is where the heavy artillery comes in. You need a dedicated second scanner. I recommend downloading Malwarebytes AdwCleaner or the full Malwarebytes Free version. These tools are specifically designed to hunt down PUPs and browser hijackers that Defender often ignores.
Step 4: Deploy the Heavy Artillery (Malwarebytes)
Here is the reality: Windows Defender is like a security guard at the front door. Malwarebytes is the detective who looks for fingerprints on the windows. You need both. Go to the official Malwarebytes website on a clean device (like your phone) and download the free installer to a USB drive, or download it directly on your PC—just ensure you are still in Safe Mode. Install it and run a "Threat Scan."
Malwarebytes is aggressive. It will flag things like "PUP.Optional.Legit" or "Adware.Junk." These aren't necessarily viruses, but they are programs that serve ads or track you without consent. Select all the detections and click "Quarantine." Once quarantined, the files are encrypted and isolated, so they can't harm your system. If the scan takes longer than 15 minutes, that is normal; it is scanning every file and every registry key.
After the quarantine, reboot your PC normally (not Safe Mode). Run Malwarebytes one more time in regular mode. If the scan comes back clean, you have likely removed the bulk of the infection. But wait—we aren't done yet. Malware often leaves behind "scheduled tasks" that try to re-download the malware even after you remove the original files. We need to check your system's startup processes to ensure nothing is lurking there.
Step 5: Check Scheduled Tasks and the Registry
Let's look at the sneaky stuff. Press Win + R, type taskschd.msc, and hit Enter. This opens the Task Scheduler. Look through the "Active Tasks" list. Malware often creates tasks with generic names like "UpdateTask" or "SyncService" that run at logon. If you see a task that triggers an .exe file located in the AppData or Temp folder, that is a huge red flag. Right-click it and select "Disable," then "Delete."
Next, we are going to check the registry, but only the startup keys. Press Win + R, type regedit, and navigate to this path: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run. This is where programs launch when you log in. Look for any values with suspicious paths, like C:\Users\Public\random.exe or %AppData%\Temp\svchost.exe. If you find one, right-click the value and delete it. Be careful here—only delete entries you are 100% sure are malicious. Deleting the wrong key (like your graphics driver) can cause boot issues.
If the registry looks clean but your browser still has a weird homepage, check your proxy settings. Malware often sets a system-wide proxy to intercept your internet traffic. Go to Settings > Network & Internet > Proxy. If "Use a proxy server" is toggled on and pointing to a random IP address, turn it off. This is a common tactic for redirecting your searches to fake pages.
Step 6: Reset Your Browser and Passwords
Even after removing the malware, your browser settings might still be compromised. The fastest fix is to reset the browser entirely. In Chrome, go to Settings > Reset settings > Restore settings to their original defaults. This will disable all extensions, clear temporary data, and reset your homepage. In Edge, it's the same path. This is a nuclear option, so you will lose your saved passwords if you haven't synced them—make sure you have them backed up first.
Once your browser is clean, you absolutely must change your passwords. If the malware was a keylogger, it captured everything you typed, including your email password, banking credentials, and social media logins. Change the passwords for your primary email first, then your bank, then everything else. Enable Two-Factor Authentication (2FA) on your email and bank accounts immediately. This ensures that even if the attacker has your password, they can't get in without your phone.
Finally, run a full scan with Defender one last time to confirm the system is clean. Then, update your Windows OS and all your software. Outdated software is the number one way malware gets in. If you were running an old version of Chrome or a Windows 10 build from 2021, you were vulnerable to exploits that have been patched since. Update everything, then consider setting your updates to automatic so you never have to think about it again.
Cleaning malware isn't fun, but it is a skill. You now know how to boot into Safe Mode, use two different scanners, and check your system for persistence mechanisms. That puts you ahead of 90% of users who would have paid a technician $150 for the same process. Keep your Defender on, keep Malwarebytes installed for monthly scans, and be picky about what you download. Your PC will thank you.