How to Remove a Stubborn Virus from Windows 10: A Practical Guide
A persistent virus on Windows 10 can turn a smooth-running PC into a source of constant headaches. Pop-ups hijack the browser, files refuse to open, and your NBN connection in suburban Brisbane or a coastal town in Western Australia starts behaving oddly right when you need it most. Many Australians first notice something is wrong when their Telstra or Optus modem lights flicker during heavy background activity, which is often a hidden process chattering away in the background.
Unlike a one-off browser hijacker, a stubborn infection digs into startup entries, scheduled tasks and registry keys to survive reboots. It may even disable your real-time protection before you get a chance to run a scan. That is why a standard antivirus quick scan rarely gets the job done. You need a layered approach that combines Safe Mode, offline scanning tools and a careful hand on system settings.
This walkthrough walks through a method Movian Security technicians use on customer machines every week. It assumes you have a working Windows 10 PC, an internet connection for downloading tools, and at least an hour of patience. Grab a cuppa, follow the steps in order, and your system should be clean by the end.
Spotting the Symptoms Before You Start
A virus that keeps coming back usually leaves breadcrumbs. Watch for a browser homepage that resets to a dodgy search engine each morning, sudden CPU spikes when the machine should be idle, or friends on WhatsApp receiving odd messages from your accounts. Australian users on the NBN often notice uploads dragging even when the line shows full speed, because a background miner or data-stealer is using the bandwidth.
Other telltale signs include fake Windows Defender Security Center alerts that demand you call a toll-free number, unfamiliar programs in the Apps & Features list, and a fan that ramps up the moment the laptop leaves the charger. If your machine was fine yesterday and sluggish today with no new software installed, treat that as a red flag.
A quick check of Task Manager (Ctrl + Shift + Esc) can confirm suspicions. Sort by Network or CPU and look for processes you cannot explain, especially ones with random names like svc32.exe or winupdate.exe sitting in AppData. Write the names down before you proceed, as you will need them when hunting startup entries later.
Comparison of Scan Types Worth Knowing
| Scan Type | When It Runs | Strengths | Limitations |
|---|---|---|---|
| Quick Scan | Inside Windows, normal boot | Fast, catches common malware in active folders | Can miss dormant or deeply embedded threats |
| Full Scan | Inside Windows, normal boot | Inspects every drive and file | Slower; some malware can hide from the running OS |
| Microsoft Defender Offline Scan | Boots into a recovery environment outside Windows | Removes rootkits and boot-time malware that hide from the OS | Requires a restart; can take 30 to 60 minutes |
| Third-Party Offline Boot Rescue (Kaspersky Rescue Disk) | Boots from USB outside Windows | Independent engine, useful when Defender is compromised | Needs a second clean PC to create the USB |
Knowing the difference lets you pick the right tool for the right stage. A persistent infection usually needs the offline option, because the malware cannot defend itself once Windows is not running.
Preparing Your Machine and Backing Up Important Files
Before deleting anything, protect the data you cannot afford to lose. Copy documents, photos and tax records to an external USB drive or a cloud service such as OneDrive or Google Drive. If you suspect the virus is watching, avoid logging into banking or email while still infected, and do not reuse the same password on the backup device.
Disconnect any mapped network drives and shared folders, since some infections spread through SMB shares. If your home office has a NAS connected to the same router as the infected PC, unplug its Ethernet cable for the duration of the cleanup. Aussies who run small businesses from a home study often overlook this and end up reinfecting the clean machine the moment they plug it back in.
Create a Windows 10 recovery drive on a separate USB stick using the built-in Create a recovery drive tool. This gives you a safety net if a later step goes wrong and Windows refuses to boot. Store the recovery stick somewhere safe, away from the infected PC until needed.
Booting Into Safe Mode With Networking
Safe Mode loads only the essential drivers and services, which stops most malware from auto-starting. Open Settings, then Update & Security, then Recovery, and click Restart now under Advanced startup. Choose Troubleshoot, Advanced options, Startup Settings, and Restart. Press 5 or F5 for Safe Mode with Networking so you can still download tools.
Once you are in, open Task Manager and disable startup items that look suspicious. Skip anything you recognise, such as your antivirus or audio drivers, and focus on entries pointing to random AppData folders or temp locations. Right-click the entry and choose Disable; do not delete yet, as you may need to reference the file path later.
Download a reputable offline scanner, such as the Microsoft Defender Offline package or the Kaspersky Rescue Disk ISO, on another device if Safe Mode browsing feels sluggish. Transfer it via USB, then move to the next step. Having a clean file ready means you are not relying on a possibly compromised browser.
Running an Offline Malware Scan and Cleaning Up
With the offline tool on a USB stick, restart the PC and boot from the device. The scanner will load its own Linux-based environment and examine every drive outside Windows. Allow it to quarantine everything it flags, even if it lists dozens of items. For users in regional South Australia or the Northern Territory on slower satellite links, this step can take the better part of an afternoon, so plan accordingly.
After the scan finishes and you are back in normal Windows, run a full Microsoft Defender scan to catch anything the offline engine missed. Open Security Center, choose Virus & threat protection, then Scan options, and pick Full scan. Review the history tab to confirm each detection has been quarantined or removed, and note the file paths of stubborn items that Defender could not delete.
For anything Defender cannot shift, use the free Malwarebytes edition in a second pass. Run a Threat Scan, then restart and check again. Two engines rarely fail in the same place, which is why layered scanning is the standard approach Movian Security uses on customer machines across Sydney, Melbourne and Perth.
Removing Startup Entries, Scheduled Tasks and Browser Hijacks
Even after a clean scan, leftover startup hooks can drag the infection back. Open Task Manager, head to the Startup tab, and disable every entry you do not recognise. Pay close attention to items with no Publisher, Unknown descriptions, or paths inside AppData, Temp or ProgramData.
Next, open Task Scheduler and review the library for tasks that run at logon or on a timer. Delete any task with a vague name such as SystemUpdater or ChromeHelper that points outside Program Files. Be cautious here, as Windows itself uses Task Scheduler for legitimate maintenance, so only remove tasks you can confidently tie to the earlier scan results.
Finally, reset each browser you use. In Chrome, go to Settings, Reset settings, Restore settings to their original defaults. Repeat in Edge, Firefox or Brave. Clear all browsing data, including cached files and cookies, then uninstall any extensions you did not install yourself. This stops malicious search redirects that fake hijackers rely on to keep pulling users back to scam sites flagged by Scamwatch and the ACCC.
Verifying the Clean and Hardening Windows 10
Run one more full scan a day after cleanup, then another a week later, to confirm the threat has not reappeared. If something comes back, the infection is hiding in a location your scanners are not reaching, often a fake driver or a WMI subscription. At that point, an in-person diagnostic from a local PC repair shop is the sensible next step, especially for users who handle client data or run point-of-sale systems.
While you are at it, turn on tamper protection in Windows Security, set Microsoft Defender to block on first sight, and enable controlled folder access if you are on Windows 10 Pro. These features make it harder for a future infection to disable your defences. Australians who rely on the NBN for remote work should also set their router DNS to a trusted provider such as Cloudflare 1.1.1.1 or Quad9, which blocks known malicious domains at the network edge.
Keep Windows Update on automatic, renew your antivirus subscriptions before they lapse, and back up weekly. A persistent virus is rarely a one-off event; it usually means a habit needs changing. With the right scanning order, a calm head and the steps above, Windows 10 can be returned to the snappy, reliable state it had on the day you first unboxed it.
Movian Security