Additional Microsoft Defender tools and services that provide security across various platforms and environments
If a phishing scam may have led to malware installation, use this cleanup path:
- Uninstall anything that was downloaded or installed because of the scam.
- Remove any app, browser add-in, or tool that appeared after the phishing event.
- Run a full malware scan in Windows Security.
- Open Start > Settings > Update & Security > Windows Security > Virus & threat protection.
- Run a full scan and remove anything detected.
- If malware keeps returning or the device still behaves suspiciously, run Microsoft Defender Offline.
- Go to Start > Settings > Update & Security > Windows Security > Virus & threat protection.
- Under Current threats, select Scan options.
- Select Windows Defender Offline scan and then Scan now.
- Note: the PC restarts before the scan, so save work first.
- Install all Windows security updates.
- Open Start > Settings > Update & Security > Windows Update and apply available updates.
- Change passwords if credentials may have been exposed.
- This is especially important if links were clicked, attachments were opened, or credentials were entered.
- If a scammer was given remote access or the device continues showing fake alerts or abnormal behavior, consider resetting the device.
- This is more disruptive, but may be the best option in persistent cases.
To avoid reinfection, do not revisit the phishing site or reopen the phishing email attachment. Malware can return if the same malicious site or email is encountered again. Using a modern browser such as Microsoft Edge helps block malicious websites.