Malware Removal Tools

Investigative work means opening untrusted files and visiting hostile sites, so a clean machine matters. These are scanners, cleanup utilities and monitoring tools, grouped by operating system. Most are free or open source, though several also offer optional paid upgrades (such as real-time protection) that you don't need for on-demand scanning. Layer them sensibly: one real-time antivirus, plus on-demand scanners for a second opinion. Download only from the official links here, verify any published hashes or code-signing certificates, and avoid mirror, repackaging and driver-updater sites. Nothing here is scraped or tied to any account.

Windows 10 / 11 (14)

Suggested minimum: Microsoft Defender + Malwarebytes Free + AdwCleaner. If you suspect an infection: Defender Offline, then a second-opinion scanner, then check startup entries with Autoruns.

  • Microsoft Defender Antivirus(*) Built in
    Primary real-time protection. Keep it on unless another real-time AV replaces it.
  • Microsoft Defender Offline(*) Built in
    Pre-boot scan for rootkits and stubborn malware.
  • Malwarebytes Free Free (manual scans)
    Second-opinion scanner for malware, adware and PUPs. Real-time protection is paid.
  • Malwarebytes AdwCleaner Free
    Browser hijackers, unwanted extensions, adware and preinstalled junk.
  • Microsoft Safety Scanner(*) Free
    Portable one-time scan. Expires after 10 days, so download fresh each time.
  • Windows Malicious Software Removal Tool(*) Free
    Targeted removal of common malware, delivered monthly via Windows Update. Not a full antivirus.
  • ESET Online Scanner Free
    On-demand second opinion. Don't leave a second persistent AV installed.
  • Kaspersky Virus Removal Tool Free
    Portable disinfection scanner. Kaspersky is Moscow-based; the US banned its software sales and updates in 2024, and some governments restrict its use. Check your own policy first.
  • ClamWin Open source
    Manual file/folder scanner. No real-time scanning.
  • ClamAV Open source
    Command-line scanning engine, good for scripts and file workflows.
  • Sysinternals Suite(*) Free
    Microsoft's investigation toolkit. Most useful: Autoruns, Process Explorer, TCPView, Sigcheck, Process Monitor.
  • Autoruns(*) Free
    Reveals startup and persistence entries (tasks, services, drivers, Run keys). Disable before deleting.
  • Process Explorer(*) Free
    Inspect processes and DLLs; verifies signatures and checks hashes against VirusTotal.
  • TCPView(*) Free
    Maps active network connections to the processes that own them.
macOS (8)

Suggested minimum: Keep macOS updated (XProtect and Gatekeeper do the baseline work) + Malwarebytes Free + KnockKnock. Add LuLu for outbound connection control.

  • XProtect, Gatekeeper and Malware Removal Tool Built in
    Apple's native malware blocking and remediation. Nothing to install; just keep macOS updated.
  • Malwarebytes for Mac Free (manual scans)
    On-demand malware and adware cleanup.
  • KnockKnock Open source
    Lists software installed in persistence locations. Runs without installing.
  • LuLu Open source
    Outbound firewall that alerts on unknown connections.
  • BlockBlock Open source
    Alerts when something tries to install a persistent component.
  • Objective-See tools Open source
    Directory of the developer's other Mac security utilities. Source and SHA-256 hashes published.
  • ClamAV Open source
    Command-line scanning; better suited to technical users.
  • ClamXAV Commercial (trial)
    Desktop antivirus interface built on ClamAV.
Linux (desktop and server) (16)

Suggested minimum: Desktop: updates + firewall + ClamAV/ClamTk + Lynis, with rkhunter or chkrootkit for periodic checks. Internet-facing PHP host: ClamAV + Maldet + AIDE + Wazuh or osquery, plus off-host backups. Install from your distribution's repository where possible.

  • ClamAV Open source
    Scans files, mail, uploads, shares and archives.
  • ClamTk Open source
    Graphical front end for ClamAV.
  • Linux Malware Detect (Maldet) Open source
    Built for shared hosting and web servers: PHP, WordPress and upload malware.
  • rkhunter Open source
    Rootkit and backdoor checks. Treat warnings as leads to investigate, not confirmed infections.
  • chkrootkit Open source
    Lightweight rootkit indicator scan; companion to rkhunter.
  • Lynis Open source
    Security audit and hardening assessment. Finds weaknesses; doesn't remove malware.
  • AIDE Open source
    File-integrity monitoring. Build a clean baseline and store it off-host.
  • Firejail Open source
    Sandbox for browsers, document readers and downloaded apps.
  • Wazuh Open source
    Endpoint monitoring, log analysis and alerting dashboard. Heavy for a single desktop.
  • osquery Open source
    Query processes, ports, packages and users with SQL for threat hunting.
  • YARA Open source
    Rule-based malware hunting for files and web roots.
  • YARA-X Open source
    Newer YARA engine; check rule compatibility.
  • Suricata Open source
    Network IDS/IPS; best at a firewall, router or network sensor.
  • Zeek Open source
    Network traffic analysis; complements Suricata.
  • fail2ban Open source
    Blocks repeated login attempts on SSH, mail and web services.
  • CrowdSec Open source / free tier
    Log-based intrusion prevention with shared threat intelligence.
Android (5)

Suggested minimum: Keep Play Protect on, install updates, and avoid unknown APK sources. Add Hypatia if you sideload and Shelter to isolate questionable apps.

  • Google Play Protect(*) Built in
    Android's default harmful-app scanning. Keep it enabled.
  • Malwarebytes for Android Free (paid extras)
    Manual scans after sideloading or suspicious behavior.
  • Hypatia Open source
    On-device malware scanner, via F-Droid. Most useful if you install APKs outside Google Play.
  • Shelter Open source
    Isolates less-trusted apps in a work profile. Containment, not detection.
  • RethinkDNS Open source
    Firewall, DNS filtering and connection visibility. Also on F-Droid. Not a malware remover.

(*) May lose some privacy when using.

iPhone/iPad: no antivirus app can scan iOS itself. Install updates promptly, and consider Lockdown Mode if you may be a targeted-attack victim.

Know a tool that belongs here? Suggest a resource.

Support this site

Terms of Service, Privacy and Disclaimers | Contact

Visits 9/28/2026: 2,681