You download a virus when you open a file or visit a website that contains malicious code, usually without realizing it's there
A virus is a program designed to damage your computer, steal your information, or use your machine to attack others. Unlike software you intentionally install, viruses hide inside files that look harmless — a document, an image, a video, or even an email attachment. When you open that file, the virus runs in the background and starts its work. You don't see it happening, which is why viruses are dangerous.
The most common way people download viruses is by opening an email attachment from someone they don't know, or clicking a link in a suspicious email that looks like it came from a bank or a company they use. Another common route is downloading files from websites that aren't legitimate — cracked software, pirated movies, or "free" versions of programs that normally cost money. Viruses also spread through USB drives, shared files, and compromised websites that have been hacked.
Key Takeaways
- Viruses most often arrive through email attachments, suspicious links, or downloads from untrusted websites.
- Once a virus runs on your computer, it can steal passwords, monitor your activity, delete files, or use your machine to send spam.
- Antivirus software can detect and remove many viruses, but prevention — not opening suspicious files — is more reliable than removal.
- If you think you have a virus, disconnect from the internet, run a full antivirus scan, and change your passwords from a different device.
- Keeping your operating system and software updated closes security gaps that viruses exploit to get inside your computer.
How viruses spread through email and messaging
Email is the most common delivery method for viruses. A message arrives that looks like it came from your bank, PayPal, Amazon, or your company's IT department. The email says your account has been compromised, your payment method failed, or you need to update your information. It includes a link or an attachment. When you click the link or open the attachment, the virus downloads and runs.
The trick is that the email looks real. It has the company's logo, similar language, and a sense of urgency. But the sender's actual email address is slightly wrong — something like "paypa1.com" instead of "paypal.com" — or the link goes to a fake website that looks identical to the real one. Once you enter your password on that fake site, the attackers have it. If there's an attachment, opening it runs the virus immediately.
Text messages and messaging apps like WhatsApp or Facebook Messenger work the same way. A message arrives from someone you know — or appears to — with a link to a video, a photo, or a news story. The link actually leads to a site that downloads malware onto your phone or computer.
What happens when a virus runs on your computer
Once a virus is running, it can do several things depending on what it was designed to do. Some viruses are spyware, which means they watch what you type, record your passwords, and monitor which websites you visit. Others are ransomware, which encrypts your files and demands money to unlock them. Some viruses simply delete files or slow your computer down. The most dangerous ones do all of this silently while you work.
A virus might also turn your computer into a bot, which means it becomes part of a network of infected machines controlled by attackers. Your computer then sends spam, launches attacks on websites, or mines cryptocurrency without your knowledge. You might notice your computer running slowly, your internet bill going up, or your fan running constantly — signs that something is using your machine's power.
Some viruses are designed to steal financial information. They log into your bank account, credit card sites, or payment apps and transfer money or make purchases. Others steal your identity by collecting your Social Security number, driver's license information, or tax documents. Once attackers have this information, they can open accounts in your name or sell it to other criminals.
Signs that your computer might have a virus
Your computer may have a virus if it suddenly becomes much slower, crashes frequently, or won't start up properly. You might see pop-up windows appearing constantly, even when you're not browsing the internet. Your browser might redirect you to websites you didn't ask for, or your homepage might change without your permission.
Other warning signs include programs starting on their own, your mouse moving without you touching it, or your keyboard typing things you didn't type. Your antivirus software might alert you to threats, or Windows Defender (on Windows computers) might show warnings. If your friends tell you they received strange messages from your email or social media account, someone may have taken control of your account — often a sign that your computer is infected.
A sudden spike in your internet usage, your computer running hot, or your fan making noise constantly can also indicate a virus is using your machine's resources. If you notice any of these signs, the next step is to scan your computer with antivirus software.
How to remove a virus from your computer
If you think you have a virus, start by disconnecting from the internet. This stops the virus from sending your data to attackers or downloading more malware. Unplug your ethernet cable or turn off your Wi-Fi. Then restart your computer in Safe Mode, which loads only the essential programs Windows needs to run — not the virus.
On Windows, restart your computer and press F8 or Shift+F8 repeatedly as it boots up. You should see a menu with "Safe Mode" as an option. On a Mac, restart and hold Command+S until you see text on the screen, or restart and hold Command+Option+R for Recovery Mode. Once in Safe Mode, open your antivirus software and run a full system scan. This can take an hour or more, but it searches every file on your computer.
If you don't have antivirus software installed, download it from a different computer and transfer it on a USB drive, or download it directly from the antivirus company's website. Popular options include Windows Defender (built into Windows), Malwarebytes, Avast, or Norton. Let the scan finish completely and remove any threats it finds.
After the scan, restart your computer normally and change all your passwords — but do this from a different device if possible, like your phone or a friend's computer. This ensures the virus isn't logging your new passwords as you type them. Change your passwords for email, banking, social media, and any other important accounts.
Preventing viruses before they reach your computer
Prevention is far more effective than removal. The first step is to never open email attachments from people you don't know, and be suspicious of attachments from people you do know if you weren't expecting them. If someone sends you an unexpected file, contact them through another method — a phone call or a separate message — to confirm they actually sent it.
Don't click links in emails, even if they look like they came from companies you trust. Instead, go directly to the company's website by typing the address into your browser, or call their customer service number. This way you know you're on the real site, not a fake one designed to steal your information.
Keep your operating system updated. Windows, macOS, and Linux all release security updates regularly that patch holes viruses use to get inside. Turn on automatic updates so you don't have to remember to do it manually. The same applies to your browser, email client, and any software you use regularly.
Install antivirus software and keep it running. Windows Defender comes built into Windows and is free. On a Mac, built-in protections are usually sufficient, but you can add Malwarebytes for extra security. Keep your antivirus definitions updated — this is the list of known viruses the software uses to identify threats. Most antivirus programs update automatically.
Download software only from official sources. If you want a program, go to the company's website or use your computer's official app store (Microsoft Store on Windows, App Store on Mac). Avoid websites that offer "free" versions of paid software or pirated movies and music — these are common sources of viruses.
What to do if you've already given attackers your information
If a virus stole your passwords, financial information, or personal data, act quickly. Change all your passwords from a different device. Contact your bank and credit card companies to report the breach and ask them to watch for unauthorized transactions. You can also place a fraud alert with the three major credit bureaus — Equifax, Experian, and TransUnion — by calling one of them. The bureau you call will notify the other two.
Check your credit report for accounts you didn't open. You can get a free report from each bureau once a year at annualcreditreport.com. If you see fraudulent accounts, dispute them with the bureau and the company that opened the account. Consider freezing your credit, which prevents anyone from opening new accounts in your name without your permission. You can do this for free through the same three bureaus.
If your Social Security number was stolen, you may want to consider identity theft protection services, though many of these cost money. The Federal Trade Commission offers free resources at identitytheft.gov if you've been a victim of identity theft.
Frequently Asked Questions
Can a virus infect my phone?
Yes, but it's less common than on computers. iPhones are harder to infect because Apple controls what apps can do, but Android phones are more vulnerable. Download apps only from Google Play or the official app store, avoid clicking links in text messages from unknown numbers, and keep your phone's operating system updated.
Will restarting my computer get rid of a virus?
Restarting alone won't remove a virus, but it can help temporarily stop it from running. Some viruses restart themselves automatically when your computer boots up. To actually remove a virus, you need to run antivirus software in Safe Mode and let it scan and delete the infected files.
Is it safe to use my computer while antivirus software is scanning?
It's better not to. A full system scan can take a long time, and using your computer while it's scanning slows both down. More importantly, if the virus is still running, it might interfere with the scan or hide from it. Let the scan finish completely without interruption.
What's the difference between a virus and malware?
A virus is a type of malware — malware is the umbrella term for any malicious software, including viruses, spyware, ransomware, and worms. All viruses are malware, but not all malware is technically a virus. The terms are often used interchangeably in everyday conversation.
Can I get a virus from just visiting a website?
Yes, if the website has been hacked or is designed to spread malware. This is called a "drive-by download." Your browser might download and run malicious code without you clicking anything. Keeping your browser and operating system updated reduces this risk, as does using antivirus software that blocks known malicious sites.