A laptop that suddenly shows pop-ups, redirects searches, runs hot, or slows to a crawl can make a normal workday feel urgent fast. When you need to remove malware from a laptop, the goal is not just to make the warnings disappear. You need to stop the threat, protect your accounts and files, and make sure it does not return after the next restart.
Some malware is annoying but limited to your browser. Other infections can steal saved passwords, encrypt files, monitor activity, or spread across a home or small business network. A calm, methodical response gives you the best chance of cleaning the computer without making the situation worse.
First, disconnect the laptop from the internet
Turn off Wi-Fi or unplug the Ethernet cable as soon as you suspect an active infection. This can prevent malware from sending data out, downloading more harmful files, or moving to other computers on the same network.
Do not immediately start entering passwords, logging into email, or opening financial accounts from the affected laptop. If the malware includes a keylogger or password-stealing tool, every new login may give an attacker more information.
There is one exception: if the laptop belongs to a business and is connected to shared drives, servers, or other workstations, isolate it and contact IT support before experimenting with cleanup tools. A quick wipe or an unplanned restart can complicate an investigation or put shared data at risk.
How to remove malware from a laptop step by step
Start with the security software already installed on your computer. On most current Windows laptops, Microsoft Defender is built in and can run a full scan. Update its definitions if possible after reconnecting briefly to a trusted network, then disconnect again if you are concerned about an active threat.
Run a full scan rather than the quickest option. A quick scan checks common infection locations, but malware can hide in downloads, temporary folders, browser data, startup items, and less obvious parts of the system. Let the scan finish, even if it takes a while. If it finds suspicious files, follow the recommendation to quarantine or remove them, then restart when prompted.
If the problem persists, run an offline scan. An offline scan restarts the laptop and checks for threats before much of Windows loads. That matters because some malware is designed to stay active and resist removal while the operating system is running.
Afterward, use a reputable second-opinion malware scanner. One scanner may catch something another misses, but avoid downloading several random “PC cleaner” programs. Fake antivirus alerts and cleanup utilities are a common way malware gets onto a computer in the first place. If a website claims your laptop has dozens of infections and demands payment immediately, close it. Do not call the number in the pop-up.
Check the places malware commonly changes
A clean scan is encouraging, but take a few minutes to check for changes the infection may have made. Review recently installed apps and remove programs you do not recognize, especially anything installed around the time the trouble began. Be careful not to remove a legitimate driver or business application simply because its name is unfamiliar.
Next, inspect your browser. Remove unknown extensions, clear browser notifications from sites you do not trust, and check that your default search engine and home page are correct. Browser hijackers often make it seem as if the whole laptop is infected when the problem is mostly contained in Chrome, Edge, Firefox, or another browser.
Also look at startup applications. If a strange program launches whenever you sign in, it may be the reason pop-ups or performance problems return after a reboot. On Windows, the Startup Apps section in Settings can help you identify unnecessary items. Disable only programs you can identify with confidence. When in doubt, take a screenshot and get help before deleting anything.
Back up files carefully
If your documents, photos, or project files are important, back them up after the initial malware scan. Use an external drive or a trusted cloud account, but avoid copying executable files, unknown downloads, installers, or suspicious folders. Those can carry the infection into your backup.
This is also the point where the type of malware matters. If files have strange extensions, will not open, or a message demands payment to restore access, you may be dealing with ransomware. Do not pay immediately or assume a payment will restore your data. Disconnect the laptop, preserve the ransom note if one exists, and get professional help. The safest recovery path may be a clean backup, not trying to negotiate with criminals.
Change passwords from a different device
Once the laptop is isolated, change important passwords from a known-clean phone, tablet, or another computer. Start with your email account because email password resets can unlock many other accounts. Then change passwords for banking, shopping, work platforms, cloud storage, and social media.
Use unique passwords and turn on multi-factor authentication wherever it is available. If your browser saved passwords before the infection, assume they could be exposed, particularly if the laptop had an information-stealing infection. Watch bank and credit card accounts for unfamiliar activity over the next several weeks.
For a small business, alert employees who may have signed in from the affected machine. You may need to reset company passwords, revoke active sessions, review email forwarding rules, and check whether the same login was used elsewhere. This can sound like a lot, but it is far easier than responding after a compromised account sends phishing messages to customers.
When a scan is not enough
Malware removal is not always a one-button fix. A laptop may need a deeper cleanup or a full Windows reinstall if it still has unexplained pop-ups, security software will not run, new accounts appear, browser settings keep changing, or performance remains poor after scans complete.
A reinstall is often the most trustworthy option for a severe infection, but it comes with a trade-off: applications must be reinstalled, settings need to be rebuilt, and files must be restored from a clean backup. For someone who needs a laptop for work or school, that downtime can be frustrating. Still, a clean operating system is sometimes safer than hoping a persistent threat has been fully removed.
Mac laptops can get malware too, although the symptoms are often browser redirects, unwanted profiles, fake update prompts, or intrusive adware rather than traditional Windows-style viruses. The same principles apply: disconnect, scan with trusted tools, remove unknown applications and browser extensions, and change passwords from a clean device.
Prevent the next infection
Most malware arrives through a few familiar routes: a fake delivery notice, a password-reset email, a software crack, a malicious ad, or a file attachment that looks routine. Keeping Windows, browsers, and installed software updated closes many of the gaps attackers use.
Use a standard account for daily work when possible, leave built-in security protection enabled, and be skeptical of unexpected prompts that ask for administrator access. Back up essential files regularly, with at least one backup disconnected from the laptop when not in use. That simple habit can turn a major ransomware event into a manageable repair.
If the laptop is still acting suspicious, you do not have to keep guessing. Don’t Panic! Computer Repair can come to your Salt Lake City location or provide remote guidance when appropriate, diagnose the problem, explain what was found, and help you choose between cleanup, data recovery, or a fresh start. Acting early protects more than the laptop – it protects the work, photos, accounts, and peace of mind tied to it.