Skip to content
Popular Topics Windows 11 AI Tools Wi-Fi PC Upgrades Home Office Retro Tech
Networking, Cloud & Security

How to Remove Viruses and Malware from Windows 11 in 2026

Remove viruses and malware from Windows 11 using Microsoft Defender, Offline Scan, startup and browser cleanup, account recovery and safe reinstall steps when cleanup is not trustworthy.

Red padlock on a computer keyboard representing Windows 11 malware protection

Some links on PCFix411 may earn a commission from GearReady, software partners, or Amazon Associates at no extra cost to you.

Updated for September 2026. Windows 11 has a much stronger built-in security stack than the PCs targeted by old malware-removal tutorials. For most home users, the first response to a suspected infection should begin with Windows Security and Microsoft Defender rather than downloading a collection of random cleanup utilities.

The goal is not only to remove a detected file. You also need to determine whether the attacker gained account access, installed remote-control software, changed browser settings or left the PC in a state you cannot confidently trust.

Signs Your Windows PC May Be Infected

  • Unexpected browser redirects, pop-ups or fake security warnings.
  • Antivirus or Windows Security is disabled without explanation.
  • New apps, extensions or remote-access tools appear.
  • Unusual CPU, disk or network activity continues while the PC is idle.
  • Files are renamed, encrypted or replaced with ransom notes.
  • Accounts show logins or messages you did not send.
  • The browser homepage, search engine or notification permissions keep changing.

One symptom does not prove malware. A slow or crashing PC can also be caused by bad drivers, failing hardware or ordinary software problems. Use evidence before assuming infection.

1. Disconnect the PC if You Suspect an Active Compromise

If the computer is encrypting files, opening unwanted pages, running unknown remote-access software or showing other signs of an active compromise, disconnect Wi-Fi or Ethernet while you investigate.

Do not enter banking credentials, passwords or payment information on a device you do not trust.

2. Preserve Anything You May Need

If the problem could involve ransomware or a serious account compromise, photograph ransom notes, unusual messages or suspicious program names before cleanup. Do not copy unknown executables to other computers.

Important personal documents can be backed up cautiously, but do not treat a backup made after infection as automatically clean.

3. Update Windows and Defender Security Intelligence

When it is safe to reconnect, open Settings > Windows Update and install available security updates. Then open Windows Security > Virus & threat protection and confirm that Microsoft Defender security intelligence is current.

Current signatures matter because a scan is only as useful as the threat information available to the engine.

4. Run a Quick Scan

Open Windows Security > Virus & threat protection and choose Quick scan. This checks the locations where active threats commonly appear.

Review anything Defender quarantines. Do not restore a file simply because an application stops working afterward; first verify that the detection was a false positive from a trustworthy source.

Open padlock and computer keyboard keys representing malware cleanup and account security
Malware cleanup is only part of recovery; exposed passwords and connected accounts may also need attention. Photo: FlyD / Unsplash.

5. Run a Full Scan When Symptoms Remain

Open Scan options and run a Full scan if the Quick scan finds something significant or symptoms remain. A Full scan takes longer because it examines more files and locations.

If the PC becomes unstable during normal operation, do not keep launching unrelated cleanup tools. Move to the offline scan or recovery options below.

6. Use Microsoft Defender Offline for Stubborn Malware

Microsoft Defender Offline restarts the computer and scans outside the normal Windows environment. That can help detect threats that hide, lock files or interfere with security software while Windows is running.

Microsoft documents Defender Offline as a deeper troubleshooting option for persistent malware. Save open work before starting because the PC will restart.

7. Remove Suspicious Apps

Open Settings > Apps > Installed apps and sort by installation date when useful. Look for software installed around the time the problem began, especially unknown remote-access tools, bundled download managers, fake optimizers and programs with no clear purpose.

Do not remove system components you do not understand merely because the name is unfamiliar. Research the publisher and file location first.

8. Audit Browser Extensions and Notification Permissions

Malware-like behavior is often caused by an extension or website notification permission rather than a traditional Windows virus. Review extensions in every installed browser and remove anything you did not intentionally install.

Also review site notification permissions. A malicious website can continue sending fake “virus detected” notifications after you have left the site.

If the problem started with an alarming pop-up or fake support call, see Tech Scams Exposed: How to Spot and Avoid Online Scams in 2026.

9. Check Startup Apps

Open Task Manager with Ctrl + Shift + Esc and select Startup apps. Disable unfamiliar or unnecessary startup entries while you investigate them.

Disabling a startup item does not remove malware, but it can expose what is launching automatically and reduce unwanted background activity during diagnosis.

10. Review Running Processes Carefully

Task Manager can show unusual CPU, memory, disk and network usage. A strange process name alone is not proof of malware because Windows and third-party software use many unfamiliar executable names.

Use the publisher, file location, digital signature and reputable security results to evaluate a process rather than ending every item you do not recognize.

11. Check Windows Security Protection Settings

Confirm that real-time protection and the normal Windows Security features you rely on have not been deliberately disabled by unwanted software. If another reputable antivirus suite is installed, understand that it may replace parts of Defender’s real-time protection by design.

12. Change Passwords From a Known-Clean Device

If you typed passwords while the PC may have been compromised, change important credentials from another trusted device. Start with:

  1. Primary email account.
  2. Password manager.
  3. Banking and financial accounts.
  4. Microsoft, Google and Apple accounts.
  5. Social-media and shopping accounts.

Enable multifactor authentication where available and review recent sign-in activity for sessions you do not recognize.

13. Revoke Sessions and Connected Apps

Changing a password may not end every active session. Major account providers let you review signed-in devices, app permissions and security activity. Remove unknown sessions and revoke suspicious connected applications.

14. What if a Scammer Had Remote Access?

If you intentionally installed remote-control software because a caller or pop-up told you to, treat the incident as more serious than an ordinary browser popup. The person may have viewed files, watched banking activity or changed system settings.

Disconnect the PC, uninstall unauthorized remote software, protect accounts from a clean device and contact financial institutions immediately if money or banking information was exposed.

15. Do You Need a Second-Opinion Scanner?

A reputable second-opinion scanner can be useful when symptoms remain, but avoid downloading several “free PC cleaner” programs from search ads. Use established vendors and obtain software from their official websites.

More scanners are not automatically better. Multiple real-time antivirus products can conflict with one another.

16. Restore Windows When You Cannot Trust the Cleanup

If malware repeatedly returns, security software keeps being disabled, system files are heavily altered or a scammer had extensive remote access, a clean Windows reinstall can be safer than trying to prove that every change was removed.

Back up irreplaceable personal files carefully, reinstall Windows from a trusted source, install updates and applications cleanly, then restore documents rather than unknown executables.

17. Ransomware Requires a Different Mindset

If files are actively being encrypted, disconnect the machine and other reachable storage immediately. Do not keep opening files to “test” whether they work. Preserve the ransom note and identify the ransomware family if possible before deciding on recovery.

Your safest recovery path is often a known-good offline or cloud backup that was not encrypted with the PC.

18. Reduce the Chance of Reinfection

  • Keep Windows, browsers and major applications updated.
  • Leave reputable real-time protection enabled.
  • Install software from official or trusted sources.
  • Avoid unexpected attachments and “urgent” security downloads.
  • Use unique passwords and multifactor authentication.
  • Keep recoverable backups separate from the computer.
  • Do not grant remote access because of an unsolicited call or browser warning.

Windows 11 Malware Cleanup Checklist

  1. Disconnect if an attack appears active.
  2. Update Windows and Defender.
  3. Run Quick scan.
  4. Run Full scan if needed.
  5. Use Defender Offline for stubborn threats.
  6. Audit apps, extensions, notifications and startup entries.
  7. Protect accounts from a clean device.
  8. Remove unauthorized remote-access tools.
  9. Consider a reputable second-opinion scanner.
  10. Reinstall Windows when the system cannot be trusted.

Microsoft’s current guidance explains persistent malware and Microsoft Defender Offline. If the PC is unstable as well as infected, use the Windows freezing guide and the PC Won’t Boot diagnostic checklist to separate malware symptoms from hardware or operating-system failure.

Bottom Line

Start Windows 11 malware cleanup with the built-in security stack, then expand only when the evidence requires it. Remove suspicious software and browser changes, protect exposed accounts separately, and do not hesitate to reinstall Windows when you cannot confidently trust what happened to the system. A clean known-good state is more valuable than endlessly stacking cleanup utilities on an uncertain installation.