We review products independently, but we may earn commissions if you make a purchase using affiliate links on our website. Also note that we are not antivirus software; we only provide information about some products.

Cleanup tools, retirement dates and recovery guidance checked · July 23, 2026

Best Malware Removal Tools in 2026: 6 Safe Scanners

Malwarebytes Free is the easiest broad second-opinion scanner, Microsoft Defender Offline is the first move for a threat that keeps returning, and Emsisoft Emergency Kit is the most useful portable option. Every tool here has a narrow job. None can prove that a credential-stealing or ransomware-hit computer is trustworthy again.

Six current tools verified No fake cleanup percentages Norton Power Eraser removed Incident workflow included
Best Malware Removal Tools in 2026 recommendations, security checks and decision criteria
Best Malware Removal Tools in 2026 recommendations, security checks and decision criteria.

If you think the computer is infected now: disconnect it from Wi-Fi and Ethernet before shopping for software. On a home Windows PC, update the existing antivirus, run a full scan, then use Microsoft Defender Offline if the detection returns after reboot. Use one current second-opinion scanner such as Malwarebytes Free or ESET Online Scanner after that. If the device handled work data, ransomware, banking, a password manager, crypto, or administrator credentials, skip the casual cleanup experiment and follow the incident workflow.

The six malware cleanup tools we would still use

This is a removal list, not another antivirus subscription ranking. We favor a current official download, a clear free boundary, a useful recovery role, reversible quarantine, and documentation that tells the user what the scanner can and can't do. We don't award points for a VPN, password manager, generic tune-up module, or an old prevention-test badge.

#1
Best easy second-opinion cleanup

Malwarebytes Free

The current free tier still provides manual Quick and Custom scans on Windows and Mac, plus quarantine and cleanup. Real-time malware, ransomware, exploit and web protection are paid.

Windows and MacManual scansQuarantineFree cleanupNo free real-time layer
$0 manual free scanner; paid protection optional Official download Read our Malwarebytes review
#2
Best for a threat that hides or returns

Microsoft Defender Offline

Built into Windows 10 and 11. It restarts into a trusted environment outside the normal Windows kernel, where a rootkit or recurring threat has fewer places to hide.

Windows 10/11Runs outside WindowsRestart requiredBuilt inRootkit role
Included Windows Security · Scan options Microsoft instructions Read our Defender review
#3
Best portable Windows toolkit

Emsisoft Emergency Kit

A portable UI and command-line scanner that can update itself, quarantine or remove detections, and restore some damaged settings. It requires 64-bit Windows 10 or later.

Portable64-bit Windows 10+One-click updatesUI and CLINo always-on layer
Free current vendor page lists build 2025.7 Get Emergency Kit Read our Emsisoft review
#4
Best free full second-opinion scan

ESET Online Scanner

A Windows one-time scanner with quarantine, saved scan logs and an optional monthly periodic scan. It's a current partial replacement for the retired ESET SysRescue Live disk, not a bootable rescue image.

WindowsOne-time scanQuarantine restoreSave scan logOptional monthly scan
$0 administrator rights needed for periodic mode Start with ESET Read our ESET review
#5
Best disposable Microsoft scanner

Microsoft Safety Scanner

A portable Windows executable for manual scanning and removal. Each download expires after 10 days, forcing a fresh copy with current security intelligence for a later check.

WindowsPortable EXE32/64-bit downloads10-day expiryDetailed log
$0 download a fresh copy for every later use Microsoft download
#6
Best targeted browser and PUP cleanup

Malwarebytes AdwCleaner

A focused free Windows cleaner for adware, browser hijackers and potentially unwanted programs. It's useful when redirects and unwanted extensions are the symptom, not as the only scan after a serious compromise.

WindowsAdwarePUPsBrowser hijackersTargeted role
$0 specialist cleaner, not primary antivirus Get AdwCleaner

The first ten minutes matter more than the scanner brand

If files are being renamed or encrypted, an unknown remote-control window appears, the mouse moves by itself, accounts send messages without you, or an antivirus reports an information stealer, treat it as an incident rather than a slow-computer problem. Disconnect Wi-Fi and Ethernet. Don't plug in a backup drive. Don't keep signing into email, banking, a password manager or an employer VPN from that device.

For a home computer with a single suspicious download and no evidence of account access, isolation followed by the existing antivirus and an offline scan is proportionate. For ransomware or a work device, CISA's ransomware checklist starts with identifying and immediately isolating affected systems. It also warns that powering a system down destroys volatile evidence, so an organization should follow its incident-response plan and preserve memory and logs when capable. A home user who can't disconnect a spreading machine may still need to power it off; a company should call its security team first.

Disconnect

Remove network access to stop command-and-control traffic, data theft and lateral movement. Leave clean devices online so you can obtain official tools and help.

Classify

A browser hijacker, a recurring rootkit alert, an info-stealer and active ransomware don't deserve the same cleanup path or confidence level.

Protect evidence

On a managed or business device, don't delete files, clear logs or run a pile of cleaners before the incident responder decides what must be captured.

First ten minutes of malware response covering password safety, network isolation, evidence capture and account containment
Contain the incident and preserve useful evidence before starting cleanup Stop typing passwords, disconnect network access and preserve the detection name, file path and any ransom message. Move urgent account work to a clean device and decide whether business, insurance or law-enforcement reporting applies before deleting evidence.

Malware removal tools compared by the job they actually do

ToolBest rolePlatformInstall?Works outside Windows?Real-time protection
Malwarebytes FreeEasy broad second opinionWindows, Mac; free scanner also on AndroidYesNoPaid only
Defender OfflineRecurring or hidden Windows threatWindows 10/11Built inYes, after restartSeparate built-in Defender layer
Emsisoft Emergency KitPortable technician toolkit64-bit Windows 10+No traditional installNoNo
ESET Online ScannerFree full/periodic second opinionWindowsSmall launcher and dataNoNo
Microsoft Safety ScannerFresh disposable Microsoft scanWindowsPortable EXENoNo
AdwCleanerAdware, PUP and browser repairWindowsPortable toolNoNo

“Free” means the removal role shown in this table can be used without buying a subscription as checked July 23, 2026. It doesn't mean every feature, business use case or support service is free. Follow each vendor's current license.

Malware removal tool chooser comparing Malwarebytes Free, Defender Offline, Emsisoft Emergency Kit, ESET Online Scanner, Safety Scanner and AdwCleaner
Choose a removal tool for its specific job and run one active scan at a time Use Malwarebytes Free for a broad manual second opinion, Defender Offline for threats that hide while Windows runs, Emsisoft from clean portable media, ESET as an alternative-engine scan, Safety Scanner as a short-lived Microsoft tool and AdwCleaner for browser-focused cleanup.

Why this ranking has no made-up “removes 100%” score

Most current consumer lab reports measure whether an installed security product blocks malicious URLs, files and behavior before compromise. That's valuable prevention evidence. It isn't a controlled comparison of how six standalone scanners repair the same already infected machines. A product's 99.x% real-world protection result can't honestly be relabeled as a 99.x% malware-removal rate.

The cleanup problem is also stateful. One machine may have a browser extension and scheduled task; another may have a boot-level component, stolen browser cookies and a modified recovery environment. A scanner can quarantine the executable while leaving passwords, OAuth tokens, remote sessions, altered policies or encrypted files unresolved. The absence of another detection after reboot is evidence, not proof of trust.

We therefore rank documented role, update path, environment, scope, reversibility and lifecycle. We also disclose freshness problems. Emsisoft's current Emergency Kit page still lists version 2025.7.0.12683 from June 27, 2025. That doesn't automatically make its self-updating definitions stale, but it's less reassuring than a clearly refreshed program build. ESET's current help remains active and a 3.4.1.0 service release was announced in June 2026. Microsoft Safety Scanner publishes the current intelligence version and deliberately expires each copy after ten days.

Detailed verdicts: what each scanner is good for

1. Malwarebytes Free — the least confusing broad cleanup choice

Malwarebytes built its reputation around second-opinion cleanup, and the 2026 free boundary remains useful. The vendor's current Free-versus-Paid matrix lists Quick and Custom scans as free on Windows and Mac. Scheduled threat scans, real-time malware and ransomware protection, exploit protection and web protection require a paid plan. That makes the free app a scanner and cleaner, not a permanent antivirus substitute.

Choose it when the installed antivirus reports clean but the browser still redirects, a suspicious process remains, or you want a readable second opinion. Quarantine first, restart, then inspect what changed. Don't assume every potentially unwanted program is malicious; installers and administration tools can trigger policy-based detections. If the only symptom is a hijacked homepage or injected ads, AdwCleaner is the narrower first pass.

Limit: installing another large app on a badly compromised machine gives malware more opportunity to interfere. For a returning detection or suspected rootkit, run Defender Offline first. For a business device, use the organization's approved EDR and incident process rather than a personal utility.

2. Microsoft Defender Offline — use the restart to your advantage

Defender Offline starts outside the ordinary Windows kernel. Microsoft recommends it when the same malware keeps returning because it can target threats that hide while Windows is running. Save work first: the PC restarts. In Windows Security open Virus & threat protection, choose Scan options, select Microsoft Defender Offline scan, and start it.

This is the best first escalation when Defender repeatedly removes the same item, a rootkit is suspected, or a normal scan can't complete. It isn't a bootable repair service for every unbootable PC, and it doesn't revoke stolen credentials. After the restart, review Protection history, update Windows and the browser, and follow with one second-opinion scanner.

Limit: if malware has damaged the recovery environment or Windows won't start, the built-in workflow may be unavailable. Move to official Windows Recovery options or a clean reinstall rather than downloading an old rescue ISO from a mirror.

3. Emsisoft Emergency Kit — portable, practical and narrowly scoped

Emsisoft describes Emergency Kit as a portable UI and command-line toolkit with malware detection, quarantine/removal, artifact cleanup and restoration of some damaged settings. It can update software and detections with one click. Because it expands to a folder instead of registering as a permanent protection suite, a technician can keep a clean copy ready and discard it after the incident.

It's the best option here for a technician servicing multiple personal Windows PCs or for a user who doesn't want another resident security suite. Update it on a known-clean environment when possible. Copy it only on media you're willing to wipe afterward; a USB drive attached to an infected machine shouldn't be trusted automatically on the next machine.

Limit: the current requirements are 64-bit Windows 10 or later, so it isn't a solution for 32-bit or very old Windows. The visible program build on the vendor page dates to June 2025. Verify the official page and update successfully before relying on a stored copy.

4. ESET Online Scanner — a strong free full-scan second opinion

ESET Online Scanner is designed for a one-time Windows scan. Its current help documents saved scan logs, quarantine restoration and an optional periodic scan. The periodic mode is a monthly quick check of commonly infected areas and requires administrator rights; it shouldn't be confused with real-time protection.

Use ESET when you want a second engine after the installed product has finished, especially when you need a full scan and a log to review. Enable potentially unwanted application detection consciously: it may surface bundlers, remote administration tools and software you chose to install. Read each result before deletion.

Limit: “Online Scanner” still downloads a Windows launcher and detection data. It doesn't scan an iPhone through a web page, and it isn't the old bootable SysRescue environment. ESET explicitly says SysRescue Live is terminated and only partially replaced by Online Scanner.

5. Microsoft Safety Scanner — fresh, official and deliberately temporary

Microsoft Safety Scanner is a portable manual scanner for Windows. It tries to reverse changes made by identified threats and writes detailed results to %SYSTEMROOT%\debug\msert.log. Microsoft provides separate 32-bit and 64-bit downloads.

The ten-day expiry is a useful safety property: the executable isn't intended to sit forgotten in a downloads folder for a year. Download a fresh copy from Microsoft whenever you need another scan. This is a good choice when Windows Security is present but you want a disposable Microsoft scan with an inspectable log.

Limit: it runs only when invoked and doesn't replace real-time protection. If a threat hides from the running OS, Defender Offline is the better Microsoft path.

6. Malwarebytes AdwCleaner — targeted cleanup for an ugly browser

Malwarebytes scopes AdwCleaner to adware, potentially unwanted programs and browser hijackers. That narrow role is useful when search redirects, unwanted extensions, notification spam or bundled software are the problem. It's faster to understand than throwing a full security suite at every browser preference.

Review the proposed repairs. Some organizations intentionally deploy browser policies, proxy settings or remote-support software that can resemble unwanted changes. Quarantine and a saved log are safer than blindly deleting every line.

Limit: a browser cleanup doesn't rule out an information stealer, rootkit or lateral movement. Follow serious symptoms with Defender Offline and a broad second opinion, or reinstall.

A safe malware-removal workflow for a home Windows PC

  1. Isolate the PC. Disconnect network access and external backup/storage devices. Photograph the warning or ransom note with another device if you need a record.
  2. Decide whether this is bigger than DIY. Work data, active ransomware, a remote attacker, financial access, administrator credentials or multiple affected devices justify professional/organizational incident response.
  3. Use a clean device for preparation. Read official instructions, download tools to fresh removable media if necessary, and contact banks or work support without using the suspected PC.
  4. Update the existing antivirus and scan. If Windows is stable, update intelligence and run a full scan. Microsoft advises cloud-delivered protection and automatic sample submission for Defender.
  5. Run outside the normal OS when persistence is suspected. Save work and run Defender Offline. Review Protection history after Windows returns.
  6. Use one second opinion. Run Malwarebytes Free, ESET Online Scanner, Emsisoft Emergency Kit or Safety Scanner—not four simultaneously. Quarantine first and save the scan log.
  7. Patch and inspect persistence. Update Windows, browsers and exposed applications. Check extensions, proxy settings, startup apps and newly created administrator accounts. Don't “fix” unknown registry entries from a forum checklist.
  8. Recover accounts from a trusted device. After the affected system is cleaned or reinstalled, change high-value passwords from a known-clean device, revoke active sessions, rotate recovery codes and enable phishing-resistant MFA where available. A cleaner can't invalidate stolen cookies or tokens.
  9. Back up data, not the infection. Copy irreplaceable documents after scanning. Avoid restoring executables, scripts, cracked software, browser profiles or full system images created after the compromise.
  10. Monitor, then make a trust decision. Recurring detections, unknown sign-ins, security settings that revert, or unexplained admin accounts mean the cleanup failed. Reinstall from trusted media.

Microsoft's account-recovery guidance says to clear malware before changing a compromised Microsoft password. The practical refinement is to perform urgent containment and account recovery from a separate trusted device when the infected device may still be monitored.

Safe Windows malware removal decision flow from containment and full scan through Defender Offline, second opinion and clean reinstall
Escalate from one updated resident scanner to offline scanning, a second opinion or reinstall Contain and preserve evidence, update one resident antivirus and run a full scan. If the threat returns, move to Defender Offline; use one manual second opinion after cleanup, rescan after restart and reinstall from trusted media when trust is not restored.

What not to do on an infected computer

Don't install two real-time antivirus suites

Microsoft warns that simultaneous antimalware products can slow or destabilize Windows. A manual second-opinion scanner is different; keep only one resident real-time provider.

Don't download from a mirror or ad

Search ads and software portals can imitate security brands. Type the vendor domain, use the contextual official links here, and verify the digital signature before running an emergency executable.

Don't trust a “clean” message as an identity reset

Removal doesn't rotate passwords, sign out remote sessions, restore encrypted data or tell every organization that credentials were exposed.

Don't run expert diagnostic scripts blindly

FRST and similar tools can help a trained helper diagnose persistence, but an automated forum fix can remove legitimate services or destroy evidence. Use a reputable supervised support channel.

When a clean reinstall is safer than another scan

No scanner can give a mathematical guarantee that a hostile administrator, rootkit or credential stealer left nothing behind. Microsoft itself recommends reset, restore or reinstall when malware caused irreversible changes. Prefer reinstalling from trusted media when any of these apply:

  • Ransomware executed, even if a decryptor or backup restores files.
  • An information stealer, remote-access trojan or unknown administrator account was confirmed.
  • Security settings, services or detections return after offline and second-opinion scans.
  • The machine handled domain-admin, business VPN, wallet seed, signing key or password-manager access.
  • Windows Update, Defender, Recovery or system files remain damaged.
  • You can't establish when the compromise started or which persistence mechanisms ran.

A reinstall isn't magic if the same malicious installer, compromised browser sync, infected macro, exposed remote desktop or stolen cloud account is restored immediately. Patch first, restore only known-good data, rotate credentials and remove the original entry point.

Clean reinstall decision tree for information stealers, remote access, ransomware, administrator compromise and recurring malware
High-consequence compromise is a trust problem, not another scanner contest Confirmed information theft, remote access, ransomware, administrator compromise, disabled security controls, unexplained system-integrity failure or malware that returns after offline scanning can justify a clean reinstall. Restore documents and known-good data, not untrusted programs.

Malware removal on Mac, Android and iPhone is a different problem

Mac

Malwarebytes Free provides manual Mac scans, but start with Apple's own signals: Gatekeeper, XProtect and notarization checks. Apple advises trashing an item identified as malware. Remove unknown profiles, login items and browser extensions, update macOS, and erase/reinstall from Recovery if administrator-level compromise remains plausible.

Android

A current Android security app can scan installed packages, but persistent symptoms may come from device-admin rights, accessibility abuse, sideloaded APKs, notification permissions or a compromised Google account. Remove unknown administrator/accessibility apps, update Android and Play system components, run Play Protect, and factory-reset when the device remains controlled. Don't restore the same suspect APK.

iPhone and iPad

Ordinary third-party apps can't perform a Windows-style full filesystem malware scan on iOS. Security apps focus on malicious links, breach monitoring, unwanted calendars, network protection and account risk. Update iOS, remove unknown profiles/VPNs, review Apple Account devices and sessions, and erase/restore when compromise is credible. A website claiming to scan every iPhone file from Safari isn't doing that.

Retired and limited tools that current lists still recommend

ToolCurrent statusWhat to use instead
Norton Power EraserDiscontinued April 30, 2026; Norton says it's unsupported and no longer functionalDefender Offline plus one current second-opinion scanner
ESET SysRescue LiveEOL September 29, 2023; databases are outdated and download was removedESET Online Scanner partially replaces it; use Windows Recovery/reinstall if the PC can't boot
Microsoft MSRTStill released for specific prevalent families, but Microsoft doesn't call it comprehensiveDefender Offline or Safety Scanner for a broader manual cleanup
Old USB copiesProgram or definitions may be stale; media may be contaminatedDownload a fresh signed copy from the official vendor on a clean device

Norton's EOL notice is unambiguous: Power Eraser stopped being supported and functional after April 30, 2026, and Norton offers no standalone replacement. ESET likewise says SysRescue Live is terminated. Don't resurrect either from a third-party archive because an old article still ranks it.

Microsoft's MSRT documentation says the monthly tool targets specific prevalent malware families and directs users to Defender Offline or Safety Scanner for comprehensive detection and removal. It's a useful background safety net, not the only incident tool.

What current community discussions add—and what they can't prove

Current r/antivirus and support discussions repeatedly point home users toward Malwarebytes, ESET Online Scanner, Emsisoft Emergency Kit and Defender Offline as second opinions. They also frequently recommend reinstalling after a serious compromise. That's useful directional evidence about workflows people can actually follow, not a controlled efficacy ranking. We found no credible reason to copy usernames, isolated scan screenshots or vote counts into a universal “best” claim.

The pattern worth keeping is escalation: built-in full/offline scan, one reputable second opinion, then reinstall when persistence or credential theft is plausible. The pattern to reject is a 12-tool checklist run without reading detections or preserving logs.

Frequently asked questions about malware removal

What is the best free malware removal tool in 2026?

Malwarebytes Free is the easiest broad manual second opinion for most home users. Microsoft Defender Offline is the better first choice when a Windows threat keeps returning or may hide while Windows runs. ESET Online Scanner and Emsisoft Emergency Kit are strong alternatives when you want a different engine or a portable toolkit.

Can Malwarebytes Free remove malware without paying?

Yes. Malwarebytes' current feature matrix lists manual Quick and Custom scans as free on Windows and Mac, with cleanup and quarantine. Scheduled threat scans and real-time malware, ransomware, exploit and web protection are paid. The free app is a cleanup scanner, not a permanent real-time antivirus replacement.

Should I run Malwarebytes and Microsoft Defender together?

You can use Malwarebytes Free as a manual second-opinion scanner while Defender remains the real-time provider. Avoid enabling two full real-time antivirus suites at once because their file and network hooks can conflict. Scan sequentially, restart when asked and review quarantine results.

Does a clean antivirus scan prove the computer is safe?

No. A clean result reduces uncertainty but can't prove that credentials, session tokens or data weren't stolen, that every persistence method was removed, or that encrypted files are trustworthy. Serious ransomware, remote-access, administrator or information-stealer incidents often justify a clean reinstall and account recovery from a trusted device.

When should I use Microsoft Defender Offline?

Use it when malware returns after removal, a rootkit or boot-level threat is suspected, Defender can't clean the item while Windows is running, or you want a deeper built-in verification. Save work first because the PC restarts and scans outside the normal Windows kernel.

Is Norton Power Eraser still available in 2026?

No. Norton discontinued Power Eraser on April 30, 2026 and says it's no longer supported or functional. Don't download an archived copy. Use Defender Offline, Malwarebytes Free, ESET Online Scanner, Emsisoft Emergency Kit or Microsoft Safety Scanner according to the job.

Will malware removal decrypt ransomware files?

Usually not. Removing the malicious process can stop further encryption, but it doesn't automatically decrypt files. Preserve the ransom note and encrypted samples, isolate affected systems, check reputable law-enforcement or No More Ransom resources for a verified decryptor, and restore only from known-good backups after rebuilding the system.

Should I change passwords before or after malware removal?

Do urgent account recovery from a separate known-clean device when active theft is possible. On the affected PC, don't enter new credentials until it has been cleaned or reinstalled. Then rotate important passwords, revoke sessions and recovery codes, review forwarding rules and enable strong MFA.

Editorial note: Product roles, free-tier boundaries, system requirements and retirement dates were rechecked against vendor documentation on July 23, 2026. We didn't run live malware on the local site workstation and don't turn prevention-test percentages into cleanup claims. Downloads and licensing can change; use the linked official page.