MarzleyTech Learn

Home / Learn / Computer hardware & maintenance / Removing viruses and cleaning up a slow, infected PC

Removing viruses and cleaning up a slow, infected PC

"My computer has a virus" is one of the most common requests a technician gets, especially for machines that use flash disks in cyber cafés and print shops. Here's a safe, step-by-step routine.

Signs of infection

  • Folders turned into shortcuts on flash disks, or files hidden
  • Pop-ups and adverts everywhere, even outside the browser
  • The browser homepage or search engine changed by itself
  • Unknown programs or browser extensions
  • Very slow performance, disk or CPU busy with nothing open
  • Antivirus switched off and won't turn back on
  • Friends receiving messages or emails you didn't send

Step 1: protect the data first

  1. Back up the user's important files to an external drive or cloud, but scan the backup before restoring later.
  2. Disconnect from the network if you suspect ransomware or data theft.

Step 2: update and run Microsoft Defender

Microsoft Defender (Windows Security) is built in and effective.

  1. Windows Update: install all updates (this updates Defender too).
  2. Windows Security → Virus & threat protection → Scan options → Full scan.
  3. For stubborn infections: Microsoft Defender Offline scan (restarts and scans before Windows loads, when malware can't hide).

Step 3: a second opinion

Run one reputable on-demand scanner (e.g. Malwarebytes Free or ESET Online Scanner). Only download them from the official websites. Don't install several antivirus programs permanently: they conflict and slow the PC.

Step 4: remove the leftovers

  • Settings → Apps → Installed apps: sort by install date; uninstall unknown or suspicious programs (search the name online if unsure).
  • Browser extensions: remove any you don't recognise (Chrome: ⋮ → Extensions).
  • Reset browser settings (Chrome: Settings → Reset settings) to fix hijacked homepages and search engines.
  • Task Manager → Startup apps: disable unknown entries.

Step 5: fix the "shortcut virus" on flash disks

After scanning the flash disk with Defender, restore hidden files with Command Prompt (replace E: with the flash disk's letter):

attrib -h -r -s /s /d E:\*.*

Then delete the leftover .lnk shortcut files and any suspicious .exe or .vbs files at the root of the flash disk.

Step 6: clean up and speed up

  • Settings → System → Storage → Temporary files: remove them; turn on Storage Sense.
  • Disable unnecessary start-up programs.
  • Uninstall bloatware.
  • Check the disk's health (Task Manager → Performance, or the maker's tool).

When to reinstall Windows instead

If infections keep coming back, security tools can't run, or the system is badly damaged, the cleanest fix is a reset or fresh install:

  • Settings → System → Recovery → Reset this PC (choose "Remove everything" for a clean start), or
  • A fresh install from a USB made with Microsoft's Media Creation Tool.

Restore only scanned personal files, never old program installers from an unknown source.

After cleaning: prevent it happening again

HabitWhy
Keep Windows and apps updated automaticallyCloses security holes
Keep Defender on; don't disable it "to install something"That something is often malware
Use genuine or free legal software, not cracksCracks are the #1 infection source
Turn off AutoPlay for USB drives (Settings → Bluetooth & devices → AutoPlay)Stops flash disk malware running itself
Scan flash disks before opening filesCyber café disks are often infected
Use a standard (non-admin) account for daily useMalware can do less damage
Regular backupsRecover from anything

Explaining it to the customer

Tell the customer what you found, what you removed, and 2–3 habits to avoid it next time. It builds trust, and they'll come back.

Why malware removal is in demand

Pop-ups, slow computers, "shortcut virus" flash disks, hijacked browsers and stolen social media accounts are everyday problems for computer users, cyber cafés, schools and offices. Many infections come from cracked software, fake downloads and infected USB drives. Technicians who clean computers properly, protect customers' data and teach prevention earn repeat business and referrals.

Types of malware you'll meet

TypeWhat it doesTypical sign
Adware / browser hijackersShow ads, change homepage and search enginePop-ups, strange search results, new toolbars
TrojansDisguised as useful software; give attackers accessUnknown programs, unexpected network activity
Worms (e.g. USB "shortcut" malware)Spread via flash disks and networksFiles replaced by shortcuts on flash disks
Spyware / info-stealersSteal passwords, browser sessions, crypto walletsAccounts accessed by others, logins from new locations
RansomwareEncrypts files and demands paymentFiles with strange extensions, ransom note
CryptominersUse the computer to mine cryptocurrencyHigh CPU usage, overheating, noisy fans
Scareware / fake antivirusFake alerts demanding payment"Your PC is infected, call this number" pop-ups

A professional cleaning workflow

  1. Interview the customer: when did it start? What was installed? Any lost money or hacked accounts?
  2. Isolate: disconnect from networks if active compromise is suspected.
  3. Back up data (documents, photos) to a clean external drive, scanning it before restoring later. Don't back up programs or installers from an infected system.
  4. Update and run Microsoft Defender full scan, then an offline scan (Microsoft Defender Offline) for stubborn threats.
  5. Second-opinion scanner from a reputable vendor.
  6. Check persistence points: startup apps (Task Manager), scheduled tasks (Task Scheduler), installed programs, browser extensions, services.
  7. Reset browsers and remove unknown extensions; check search engine and homepage settings.
  8. Update Windows, browsers and all software; remove pirated software.
  9. Change passwords from a clean device for email, banking, social media; enable 2-step verification; sign out other sessions.
  10. Test and document what was found and done.

Browser clean-up checklist

CheckWhere (Chrome as example)
Unknown extensionsMenu → Extensions → Manage extensions: remove unknown ones
Search engine and homepageSettings → Search engine / On start-up
Site notifications spamSettings → Privacy and security → Site settings → Notifications: block unwanted sites
Reset settingsSettings → Reset settings
Saved passwords exposurePassword Checkup in the Google account

Many "virus" complaints are actually spammy notification permissions a user allowed on a website; removing them stops pop-ups instantly.

The shortcut virus on flash disks (safe approach)

  1. Don't double-click the shortcuts (that runs the malware).
  2. Scan the flash disk with Defender.
  3. Show hidden files (File Explorer → View → Show → Hidden items), or use the command prompt to remove hidden/system attributes so real files reappear.
  4. Delete suspicious .lnk shortcuts and unknown script/executable files in the root of the drive.
  5. Copy the recovered files to a clean location, then format the flash disk.
  6. Clean the computer that infected it; otherwise the problem returns.

When to reinstall instead of cleaning

  • Ransomware, rootkits, or repeated reinfection after cleaning.
  • Evidence of serious compromise (banking trojans, remote access tools).
  • The system is extremely slow and full of junk, and cleaning would take longer than a fresh install.
  • Business machines handling sensitive data, where certainty matters.

A clean install (after backing up data) removes doubt. Restore only data files, scanned first.

Explaining the problem to customers

TEXT
We found adware installed through a "free" video downloader, plus 14 browser extensions
showing ads. We removed them, updated Windows and your browser, and reset the browser.
Your documents are safe. Because your Facebook password may have been exposed,
we helped you change it and turned on 2-step verification.
Tips: install software only from official sites or the Microsoft Store, and click
"Block" when websites ask to send notifications.

Plain language, what you found, what you did, and how to prevent it next time.

Prevention plan for customers and offices

  • Keep Windows Update and Microsoft Defender on.
  • Use standard user accounts for daily work.
  • No cracked or pirated software; use free legal alternatives.
  • Scan flash disks; disable AutoRun.
  • Back up important files regularly (3-2-1 rule).
  • Use a password manager and 2-step verification.
  • Train staff to recognise phishing and fake downloads.

Practice

  1. Review startup apps, scheduled tasks and browser extensions on a practice computer.
  2. Run a Microsoft Defender full scan and an offline scan; note the steps.
  3. Recover files from a flash disk with hidden attributes (on a test drive).
  4. Write a customer report for a fictional adware cleanup.
  5. Create a one-page prevention checklist to give customers.
Think about it: After cleaning a customer's laptop, you discover their Gmail was accessed from another country last week. What extra steps should you take?Show answer

Help them change the Gmail password from a clean device, sign out all other sessions, review recovery email/phone, forwarding rules and connected apps, enable 2-step verification, and check other accounts that use the same password or can be reset via that email (banking, social media). Advise watching for suspicious activity and informing contacts if scam messages were sent.

Check yourself

  1. What is the name of Windows' built-in antivirus? (two words)

    Show answer

    Microsoft Defender

  2. Which Defender scan runs before Windows loads to catch hidden malware? (two words)

    Show answer

    offline scan

  3. Which Command Prompt command un-hides files on a flash disk?

    Show answer

    attrib

  4. What is the most common source of malware on personal computers? (two words)

    Show answer

    cracked software

  5. Which Windows feature should you turn off to stop USB drives running programs automatically?

    Show answer

    AutoPlay

  6. Which Microsoft Defender scan runs before Windows starts to remove stubborn malware?

    Show answer

    offline scan

  7. What browser permission often causes spam pop-ups without real malware?

    Show answer

    notifications

  8. From what kind of device should passwords be changed after an infection?

    Show answer

    clean

Lesson 6 of 7 in Computer hardware & maintenance · Printable course notes