What to look for right now
A virus on your computer usually shows itself through behavior changes you'll notice before you run any scan. Your machine might be slower than usual, programs might crash or freeze, your browser might redirect to sites you didn't ask for, or you might see pop-ups that won't close even when you click the X. You might also notice your fan running constantly, your battery draining faster than normal, or unfamiliar programs appearing in your applications list.
The most reliable first step is to restart your computer in Safe Mode and run a full scan with your built-in antivirus tool. On Windows, restart and press F8 or Shift repeatedly before the login screen appears, then choose Safe Mode with Networking. On Mac, restart and hold Command+S until you see the login prompt. Safe Mode loads only essential programs, which makes it harder for a virus to hide or interfere with the scan.
Key Takeaways
- Slow performance, unexpected pop-ups, browser redirects, and programs crashing are common signs a virus is present.
- Windows Defender (built into Windows) and Malwarebytes are both free tools that can scan your whole computer without you paying anything.
- Restart in Safe Mode before scanning so the virus has fewer places to hide and can't interfere with the scan itself.
- If a scan finds threats, let the tool quarantine or remove them — most modern antivirus software handles this automatically.
Using Windows Defender on a Windows computer
Windows Defender comes pre-installed on every Windows 10 and Windows 11 machine and requires no setup. Open it by typing "Windows Defender" into your search bar and clicking Windows Security. Click Virus & threat protection on the left side, then click Scan options at the bottom.
Choose Full scan, which checks every file on your computer — this takes longer than a quick scan but catches more threats. Click Scan now and let it run. Depending on how much data you have, this can take 30 minutes to several hours. If Defender finds anything, it will show you the results and ask what to do; choosing Remove or Quarantine is safe and removes the threat from your system.
If you want to schedule regular scans so you don't have to remember, go back to Virus & threat protection, scroll down to Virus & threat protection settings, and click Manage settings. Turn on Scheduled scan and choose a day and time when your computer is usually on.
Using Malwarebytes as a second opinion
Malwarebytes is a free tool designed specifically to catch viruses and malware that antivirus programs sometimes miss. Download it from malwarebytes.com, install it, and open it. Click Scan on the left side, then click Threat Scan to check your whole computer. Like Windows Defender, this takes time but is thorough.
Malwarebytes is especially useful if Windows Defender didn't find anything but your computer still feels wrong. Running both tools gives you two separate checks — they use different methods to detect threats, so one might catch something the other missed. If Malwarebytes finds threats, click Quarantine to remove them.
What to do if a scan finds a virus
When either tool finds a threat, you'll see a list showing the file name, where it's located, and what kind of threat it is. The tool will usually offer to quarantine or remove the threat automatically. Quarantine is safer if you're unsure — it moves the file to an isolated folder where it can't run or spread, but you can still see what was found. Remove deletes the file entirely.
After the scan finishes and threats are handled, restart your computer. Then run the scan one more time to make sure nothing was missed. If the same threats appear again, the virus may have reinstalled itself, which means you need to take additional steps like checking your browser extensions or looking for suspicious programs in your applications list.
Checking your browser for unwanted add-ons
Viruses often hide as browser extensions or add-ons that hijack your search results or show extra ads. In Chrome, click the three dots in the top right, go to More tools, then Extensions. Look through the list for anything you don't recognize or didn't install yourself. Click the trash icon to remove it.
In Firefox, click the menu button (three lines) in the top right, click Add-ons, then click Extensions. Remove anything suspicious the same way. In Edge, click the three dots, go to Extensions, and remove anything unfamiliar. After removing extensions, restart your browser and check whether your homepage or search engine has changed back to what you expect.
Checking your installed programs
Viruses sometimes disguise themselves as legitimate programs. On Windows, go to Settings, click Apps, then Apps & features. Scroll through the list and look for programs you don't remember installing. Right-click anything suspicious and choose Uninstall. On Mac, open Applications in Finder and look for unfamiliar programs, then drag them to Trash.
Pay special attention to programs with generic names like "System Tool" or "PC Cleaner" or anything that sounds like it's supposed to help you but you didn't deliberately download. If you're unsure whether a program is legitimate, search its name online — if multiple sources call it malware or a PUP (potentially unwanted program), uninstall it.
When to consider a factory reset
If scans find multiple threats, your computer is still behaving strangely after removal, or you can't identify where a virus is coming from, a factory reset may be necessary. This erases everything on your computer and reinstalls Windows or macOS from scratch, which removes any virus hiding in system files.
Before you reset, back up any files you want to keep to an external drive or cloud storage. On Windows, go to Settings, click System, then Recovery, and choose Reset this PC. On Mac, restart and hold Command+R to enter Recovery Mode, then choose Reinstall macOS. Both processes take an hour or more and will ask you to choose whether to keep your files or erase everything. If you choose to keep files, some viruses may survive, so erasing everything is more thorough.
Frequently Asked Questions
Is it safe to use my computer while a virus scan is running?
You can use your computer, but the scan will run slower and take longer. It's better to let it finish without interruption. Don't open large files or programs while scanning — close your browser and email and let the tool work.
What's the difference between a virus and malware?
A virus spreads by attaching itself to other files and programs. Malware is a broader category that includes viruses, spyware, ransomware, and other harmful software. Most modern threats are malware rather than true viruses, but the scanning process catches both.
Do I need to pay for antivirus software?
No. Windows Defender is free and built in, and Malwarebytes has a free version that scans and removes threats. Paid versions add features like real-time protection, but free tools are enough for most people to detect and remove existing infections.
Can a virus survive after I restart my computer?
Yes, if it's installed as a program or in system files. Restarting alone won't remove a virus — you need to run a scan and let the antivirus tool quarantine or remove it. Some viruses are designed to restart themselves even after removal, which is why running a second scan after restart is important.
What if I think my passwords were stolen?
Change your passwords from a different device if possible — a phone or tablet — so the virus can't capture the new ones. Start with email and banking passwords since those give access to other accounts. If you used the same password everywhere, change all of them. Consider checking your bank and credit card statements for unauthorized charges.