Virus & Spyware Removal
You can remove most malware yourself -- if you know which tool does what, in what order, and what to do about every password you just compromised.
Or: a Geek handles it remotely or on-site and leaves when it works. $99.99.
You clicked 'You've won an iPhone!' You have not won an iPhone.
Before you touch anything on the infected machine:
- •DO NOT pay ransomware demands. Payment does not guarantee decryption, funds more attacks, and marks you as a paying target. Contact a professional immediately instead.
- •If you see ransomware (files encrypted, ransom note on screen): disconnect from the internet immediately by unplugging ethernet and turning off Wi-Fi. Do NOT restart. Call a professional -- the encryption may not have completed on all files yet.
- •Do NOT use the infected computer for banking, email, shopping, or any account that matters. Assume your keystrokes are being logged and your passwords are compromised from the moment you suspect infection.
- •Fake antivirus programs -- ones that pop up and claim to have found 200 viruses -- are themselves malware. Do NOT click anything inside them, including 'Cancel' or 'X.' Use Task Manager to force-close them.
- •Some malware persists through Safe Mode by loading as a system service. If Safe Mode doesn't help, you may need an offline bootable scanner. This guide covers that.
- •After removal, assume all passwords used on that machine are compromised. Change them -- every single one -- from a clean device.
- •If cloud sync (OneDrive, Dropbox, Google Drive) is active, pause it NOW. Ransomware encrypts local files and sync helpfully uploads the encrypted versions, overwriting your good backups.
What you'll need
Affiliate links below go to Amazon search results for each item. Prices vary -- we don't set them.
The best free malware scanner -- catches what Defender misses. Download on a clean device and transfer via USB if needed.
For running offline scanners or transferring clean tools to an infected machine. The patient can't fill its own prescription.
For downloading tools, looking up steps, and changing passwords -- do NOT use the infected machine for any of this.
You'll be changing every important password at the end. All of them. Yes, all of them.
Runs a scan before Windows boots, catching malware that hides from normal scans. Already on your machine -- no download needed.
Bootable USB scanner completely independent of Windows. The nuclear option when everything else fails.
Back up your clean files BEFORE you start. Some removal tools are aggressive. Better to have it and not need it.
The steps
9 steps to decontamination. The malware is not going to remove itself -- well, actually some of it does. That's worse.
Identify the infection type before doing anything
Disconnect from the network immediately
Boot into Safe Mode with Networking
Run Malwarebytes free scan
Run Windows Defender Offline Scan
Remove suspicious programs and clean your browsers
Change all passwords from a clean device and enable 2FA on everything
Harden your system to prevent reinfection
Final verification -- confirm the machine is actually clean
Rather Not Touch the Infected Machine?
A Geek removes the malware, cleans your browsers, hardens your system, and walks you through the password changes.
From $99.99 on-site
Same-day available · Satisfaction guaranteed
Not Sure What You're Dealing With?
Our "Talk Me Through It" option connects you with a live Geek on video call while you work.
From $49.99
By the numbers
Don't Let It Sit. Get It Cleaned.
If the guide got you there -- great, your machine is clean and your passwords are changed.
If you're still seeing popups, redirects, or suspicious processes -- every hour on an infected machine is another hour of exposure. We've cleaned thousands of these.
