Malware Removal Tools
Investigative work means opening untrusted files and visiting hostile sites, so a clean machine matters. These are scanners, cleanup utilities and monitoring tools, grouped by operating system. Most are free or open source, though several also offer optional paid upgrades (such as real-time protection) that you don't need for on-demand scanning. Layer them sensibly: one real-time antivirus, plus on-demand scanners for a second opinion. Download only from the official links here, verify any published hashes or code-signing certificates, and avoid mirror, repackaging and driver-updater sites. Nothing here is scraped or tied to any account.
Windows 10 / 11 (14)
Suggested minimum: Microsoft Defender + Malwarebytes Free + AdwCleaner. If you suspect an infection: Defender Offline, then a second-opinion scanner, then check startup entries with Autoruns.
-
Microsoft Defender Antivirus(*) Built in
Primary real-time protection. Keep it on unless another real-time AV replaces it.
-
Microsoft Defender Offline(*) Built in
Pre-boot scan for rootkits and stubborn malware.
-
Malwarebytes Free Free (manual scans)
Second-opinion scanner for malware, adware and PUPs. Real-time protection is paid.
-
Malwarebytes AdwCleaner Free
Browser hijackers, unwanted extensions, adware and preinstalled junk.
-
Microsoft Safety Scanner(*) Free
Portable one-time scan. Expires after 10 days, so download fresh each time.
-
Windows Malicious Software Removal Tool(*) Free
Targeted removal of common malware, delivered monthly via Windows Update. Not a full antivirus.
-
ESET Online Scanner Free
On-demand second opinion. Don't leave a second persistent AV installed.
-
Kaspersky Virus Removal Tool Free
Portable disinfection scanner. Kaspersky is Moscow-based; the US banned its software sales and updates in 2024, and some governments restrict its use. Check your own policy first.
-
ClamWin Open source
Manual file/folder scanner. No real-time scanning.
-
ClamAV Open source
Command-line scanning engine, good for scripts and file workflows.
-
Sysinternals Suite(*) Free
Microsoft's investigation toolkit. Most useful: Autoruns, Process Explorer, TCPView, Sigcheck, Process Monitor.
-
Autoruns(*) Free
Reveals startup and persistence entries (tasks, services, drivers, Run keys). Disable before deleting.
-
Process Explorer(*) Free
Inspect processes and DLLs; verifies signatures and checks hashes against VirusTotal.
-
TCPView(*) Free
Maps active network connections to the processes that own them.
macOS (8)
Suggested minimum: Keep macOS updated (XProtect and Gatekeeper do the baseline work) + Malwarebytes Free + KnockKnock. Add LuLu for outbound connection control.
-
XProtect, Gatekeeper and Malware Removal Tool Built in
Apple's native malware blocking and remediation. Nothing to install; just keep macOS updated.
-
Malwarebytes for Mac Free (manual scans)
On-demand malware and adware cleanup.
-
KnockKnock Open source
Lists software installed in persistence locations. Runs without installing.
-
LuLu Open source
Outbound firewall that alerts on unknown connections.
-
BlockBlock Open source
Alerts when something tries to install a persistent component.
-
Objective-See tools Open source
Directory of the developer's other Mac security utilities. Source and SHA-256 hashes published.
-
ClamAV Open source
Command-line scanning; better suited to technical users.
-
ClamXAV Commercial (trial)
Desktop antivirus interface built on ClamAV.
Linux (desktop and server) (16)
Suggested minimum: Desktop: updates + firewall + ClamAV/ClamTk + Lynis, with rkhunter or chkrootkit for periodic checks. Internet-facing PHP host: ClamAV + Maldet + AIDE + Wazuh or osquery, plus off-host backups. Install from your distribution's repository where possible.
-
ClamAV Open source
Scans files, mail, uploads, shares and archives.
-
ClamTk Open source
Graphical front end for ClamAV.
-
Linux Malware Detect (Maldet) Open source
Built for shared hosting and web servers: PHP, WordPress and upload malware.
-
rkhunter Open source
Rootkit and backdoor checks. Treat warnings as leads to investigate, not confirmed infections.
-
chkrootkit Open source
Lightweight rootkit indicator scan; companion to rkhunter.
-
Lynis Open source
Security audit and hardening assessment. Finds weaknesses; doesn't remove malware.
-
AIDE Open source
File-integrity monitoring. Build a clean baseline and store it off-host.
-
Firejail Open source
Sandbox for browsers, document readers and downloaded apps.
-
Wazuh Open source
Endpoint monitoring, log analysis and alerting dashboard. Heavy for a single desktop.
-
osquery Open source
Query processes, ports, packages and users with SQL for threat hunting.
-
YARA Open source
Rule-based malware hunting for files and web roots.
-
YARA-X Open source
Newer YARA engine; check rule compatibility.
-
Suricata Open source
Network IDS/IPS; best at a firewall, router or network sensor.
-
Zeek Open source
Network traffic analysis; complements Suricata.
-
fail2ban Open source
Blocks repeated login attempts on SSH, mail and web services.
-
CrowdSec Open source / free tier
Log-based intrusion prevention with shared threat intelligence.
Android (5)
Suggested minimum: Keep Play Protect on, install updates, and avoid unknown APK sources. Add Hypatia if you sideload and Shelter to isolate questionable apps.
-
Google Play Protect(*) Built in
Android's default harmful-app scanning. Keep it enabled.
-
Malwarebytes for Android Free (paid extras)
Manual scans after sideloading or suspicious behavior.
-
Hypatia Open source
On-device malware scanner, via F-Droid. Most useful if you install APKs outside Google Play.
-
Shelter Open source
Isolates less-trusted apps in a work profile. Containment, not detection.
-
RethinkDNS Open source
Firewall, DNS filtering and connection visibility. Also on F-Droid. Not a malware remover.
(*) May lose some privacy when using.
iPhone/iPad: no antivirus app can scan iOS itself. Install updates promptly, and consider Lockdown Mode if you may be a targeted-attack victim.
Know a tool that belongs here? Suggest a resource.