How to use Safe Mode to delete persistent malware on Windows
Persistent malware can block security software, reopen after removal, or hide its files behind ordinary Windows processes. Safe Mode helps by loading Windows with a limited set of drivers and startup components, reducing the number of places malicious software can run.
This method is useful for adware, browser hijackers, unwanted programs, and some trojans. It is not a guarantee against every infection. Rootkits, ransomware, and threats that alter recovery settings may require an offline scan, system restore, or professional incident response.
Before deleting anything, identify the symptoms and protect important documents. If ransomware is active, disconnect the computer from the internet and avoid opening encrypted files. Do not run suspicious “fixer” tools downloaded from pop-ups, because they may install additional malware.
Why Safe Mode helps with malware removal
Normal Windows startup loads third-party services, scheduled tasks, browser extensions, and background applications. Malware often depends on these components to maintain persistence or interfere with antivirus programs. Safe Mode starts only essential Windows services, making some threats inactive and easier to locate.
Safe Mode does not remove malicious files by itself. It creates a cleaner environment for scanning and manual cleanup. Windows Security, Microsoft Defender Offline, and a reputable second-opinion scanner can be more effective when the malware is not actively running.
For broader security advice and platform-specific explanations, review the Windows security guides before making advanced changes to the registry or system folders.
Prepare the computer before restarting
Save work and disconnect unnecessary external drives. If the infection may have stolen passwords, use a different trusted device to change important credentials, especially email, banking, and administrator account passwords. Avoid signing into sensitive services from the infected computer until it has been checked.
Create a backup only if you can do so safely. Copy personal documents, photos, and other irreplaceable files to a clean drive, but do not back up executable files, cracked software, unknown scripts, or suspicious browser extensions. Keep the backup disconnected after copying.
If you need internet access for a security scanner, choose Safe Mode with Networking, but ordinary Safe Mode is safer when offline cleanup is possible. Networking allows malware to contact command-and-control servers and may expose the system to additional downloads.
Enter Safe Mode in Windows 10 or 11
The most reliable route is through Windows Recovery Environment. Open Settings, select System, choose Recovery, and click Restart now beside Advanced startup. In Windows 10, the option is under Update & Security > Recovery.
After the blue recovery screen appears, select Troubleshoot > Advanced options > Startup Settings > Restart. Press 4 or F4 for Safe Mode, or press 5 or F5 for Safe Mode with Networking. Sign in with an account that has administrator privileges.
If Windows will not start normally, interrupt the boot process two or three times by holding the power button during startup. Windows should open automatic repair and display the same recovery options. Use this approach carefully, since repeated forced shutdowns can cause file-system problems.
| Startup option |
Internet access |
Best use |
Main caution |
| Safe Mode |
No |
Offline malware scans and manual cleanup |
Some cloud-based tools will not update |
| Safe Mode with Networking |
Yes |
Downloading a trusted scanner or updates |
Malware may communicate online |
| Normal Windows startup |
Yes |
Final verification after cleanup |
Persistent threats can run normally |
| Microsoft Defender Offline |
No during scan |
Suspected rootkits or deeply embedded malware |
Requires a restart and scan time |
Find and remove suspicious components
Once Safe Mode loads, open Settings > Apps > Installed apps and sort programs by installation date. Remove software you do not recognize, especially recently installed toolbars, coupon applications, fake security utilities, and programs associated with browser redirection. Use the standard Windows uninstaller first.
Check Task Manager by pressing Ctrl + Shift + Esc. Review startup entries and disable unknown items, but do not delete files merely because their names look unfamiliar. Research the publisher and file location from a trusted security source. Legitimate Windows processes can also have technical names that resemble malware.
Run a full scan with Microsoft Defender. If the threat interferes with the scan, use Microsoft Defender Offline from Windows Security > Virus & threat protection > Scan options. An offline scan restarts the computer and examines the system before the usual Windows environment is loaded.
Browser cleanup is also important. Remove unknown extensions, reset hijacked search settings, and delete suspicious notification permissions. For detailed Windows-specific troubleshooting, the Windows malware resources provide additional guidance on browser hijackers and unwanted applications.
Remove persistence when the threat returns
If malware reappears after restarting normally, inspect common persistence locations. Review Task Manager > Startup apps, Task Scheduler, and unfamiliar services. Look for entries that launch files from temporary folders, user profile directories, or randomly named folders. Disable a suspicious task before deleting its associated file.
Do not edit the registry casually. Incorrect changes can prevent Windows from booting. If a registry entry is clearly linked to a confirmed threat, export a backup of the relevant key first and record what was changed. Security software should handle registry cleanup whenever possible.
A threat that survives Safe Mode may use a boot-level component, altered system policy, or a hidden administrator account. In that situation, run Defender Offline, install pending Windows security updates, and consider restoring the system from a known-clean backup. Ransomware victims should preserve encrypted samples and ransom notes for analysis rather than paying immediately.
Practical cleanup recommendations
Use a consistent process to reduce the chance of leaving behind a startup mechanism:
- Disconnect from the internet unless a trusted scanner specifically requires access.
- Run a full antivirus scan and follow it with an offline scan when persistence is suspected.
- Remove unknown applications, extensions, scheduled tasks, and startup entries only after verifying their connection to the infection.
- Restart normally and confirm that redirects, pop-ups, high CPU usage, and suspicious processes have stopped.
- Update Windows, browsers, drivers, and security software after cleanup is complete.
After the system is stable, clear browser data and review installed extensions again. Monitor network activity, account alerts, and system performance for several days. If the computer is also used with Apple devices, keep platform instructions separate and consult Mac security tips rather than applying Windows repair steps to macOS.
Keep a clean recovery path
Safe Mode is a controlled starting point, not a substitute for layered protection. Enable real-time antivirus protection, keep automatic updates active, and use a standard user account for everyday work. Browser protections, reputable ad-blocking tools, and cautious download habits can prevent many reinfections.
Maintain offline or versioned backups so a serious infection does not eliminate your recovery options. When malware continues to return, system files are damaged, or sensitive information may have been exposed, disconnect the device and obtain qualified incident-response help.
Use Safe Mode methodically, document every cleanup action, and verify the computer after returning to normal startup. These steps give persistent malware fewer opportunities to launch and help restore a safer Windows environment.