How to tell if your computer is compromised

A hacked computer usually shows itself through behavior that is noticeably different from normal — programs that open on their own, a mouse cursor moving without your hand on it, or your computer running slowly even when you are not using anything. Your antivirus software may alert you directly, or you might notice unfamiliar programs in your installed software list. The most reliable sign is when your accounts — email, banking, social media — show activity you did not cause, like password changes or login attempts from places you have never been.

Not every slowdown means you are hacked. A full hard drive, too many browser tabs, or outdated software can all make a computer sluggish. But when slowness comes with unexplained programs, strange network activity, or account breaches, the risk is real. The sooner you notice and act, the less damage an attacker can do.

Key Takeaways

  • Watch for programs opening without your input, your mouse moving on its own, or unexpected account activity — these are the most common signs of a compromise.
  • Check your installed programs list and browser extensions regularly, because malware often hides as legitimate-looking software.
  • Run a full scan with your antivirus software in Safe Mode, where fewer programs load and malware has less room to hide.
  • Change your passwords from a different device while your main computer is offline, so an attacker cannot intercept the new password.
  • If your computer was used to send spam or attack other systems, contact your internet provider to report it before you reconnect.

Unexpected programs and browser changes

Open your Control Panel (on Windows) or System Preferences (on Mac) and look at the list of installed programs. Malware often disguises itself with names that sound legitimate — "System Update", "Security Tool", "Browser Helper" — but if you do not remember installing something, it should not be there. Pay special attention to anything installed recently, which you can sort by date.

Check your browser extensions and add-ons next. Open your browser settings, find the extensions or add-ons section, and remove anything unfamiliar. Malware frequently installs itself as a browser extension so it can track what you type, redirect your searches, or inject ads into every page you visit. If you see an extension you do not recognize, delete it when ready — you can always reinstall legitimate ones later.

Look at your browser's home page and search engine settings too. If they have changed to something you did not set, malware has likely modified them. Change them back to what you want, then check again in a few days — if they change again on their own, the malware is still active and you need to move to the scanning step.

Running a full antivirus scan in Safe Mode

Safe Mode is a special startup option that loads only the bare minimum programs your computer needs to run. Malware cannot hide as easily in Safe Mode because there are fewer places for it to operate. To enter Safe Mode on Windows, restart your computer and press F8 repeatedly as it boots up, then select "Safe Mode with Networking" from the menu. On Mac, restart and hold Shift until you see the login screen.

Once in Safe Mode, open your antivirus software and run a full system scan. This scan will check every file on your hard drive, which takes time — anywhere from 30 minutes to several hours depending on how much data you have. Do not interrupt it. When the scan finishes, review the results carefully. Your antivirus will show you what it found and ask whether to remove, quarantine, or ignore each item. Remove anything it flags as malware or a virus.

If your antivirus software is missing or will not open, malware may have disabled it. read a standalone scanner like Malwarebytes or Windows Defender Offline on a different computer, transfer it to a USB drive, and run it from the USB drive on your infected computer. These tools do not require installation and can work even when your main antivirus has been compromised.

Checking your accounts and changing passwords

While your computer is still offline or in Safe Mode, use a different device — a phone, tablet, or another computer — to check your email and important accounts. Look at the login history or recent activity section if your email provider offers it. Gmail shows "Last account activity" with the location and device type; Outlook has a "Recent activity" page. If you see logins from places you have never been or devices you do not own, an attacker has accessed your account.

Change your passwords from that other device, not from the infected computer. Create new passwords that are at least 12 characters long and include uppercase letters, numbers, and symbols. Start with your email password first — email is the master key to all your other accounts, because password reset links go there. Then change passwords for banking, social media, and any other account that holds sensitive information. Do not reuse passwords across different sites.

If you use a password manager, change the master password too. If you do not use one, this is a good time to start — a password manager stores complex passwords so you do not have to remember them or write them down. Popular options include Bitwarden, 1Password, and Dashlane.

Disconnecting from the internet and getting professional help

If the antivirus scan found malware but did not remove it all, or if you are still seeing suspicious activity after cleaning, disconnect your computer from the internet. Unplug the ethernet cable or turn off Wi-Fi. This stops the malware from communicating with its controller or spreading to other devices on your network. Leave it disconnected until you have a plan.

At this point, you have three options. The first is to continue cleaning yourself — read additional scanning tools, research the specific malware you found, and work through removal guides. This works if you are comfortable with technical steps and have time. The second is to take your computer to a local repair shop that specializes in malware removal. They have tools and experience you may not, and the cost is usually between 100 and 300 dollars. The third is to back up your important files and reinstall your operating system from scratch, which completely removes the malware but takes several hours and requires you to reinstall all your programs.

Before you reconnect to the internet, contact your internet service provider and tell them your computer was compromised. Some malware turns infected computers into "bots" that attack other systems without your knowledge. Your provider may have already detected this and can help you understand what happened.

Preventing future infections

Keep your operating system and all software updated. Updates patch security holes that malware exploits. On Windows, go to Settings > Update & Security and check for updates. On Mac, go to System Preferences > Software Update. Set updates to install automatically so you do not have to remember.

Use antivirus software and keep it current. Windows Defender, which comes built into Windows, is adequate for most people. Mac users should consider a third-party antivirus because macOS is increasingly targeted. Whatever you choose, make sure it runs regular scans — weekly or monthly depending on your usage.

Be cautious with email attachments and downloads. Do not open attachments from people you do not know, and do not read files from untrusted websites. Malware often spreads through email attachments that look like invoices, resumes, or delivery notices. If something seems odd or you were not expecting it, ask the sender before you open it.

Frequently Asked Questions

Can I get hacked just by visiting a website?

Yes, through what is called a "drive-by read". A compromised or malicious website can exploit a security hole in your browser or plugins and install malware without you clicking anything. This is why keeping your browser and plugins updated is critical — updates close the holes attackers use.

What if I see a pop-up warning that my computer is infected?

Do not click anything on the pop-up. These are almost always scams designed to trick you into downloading malware or calling a fake support number. Close the browser tab or force-quit the browser entirely. If the pop-up keeps coming back, restart your computer and run an antivirus scan.

Will a factory reset remove all malware?

A factory reset (also called a clean install) removes nearly all malware because it erases and rewrites your entire hard drive. However, some advanced malware can hide in your router or firmware, so also restart your router and change its password after a factory reset.

Is it safe to use my computer while it is being scanned?

No. Close all other programs and let the scan run uninterrupted. Using your computer while scanning slows the scan down and can cause it to miss infections. Plan for the scan to take several hours and do something else in the meantime.

What should I do if my bank account was accessed?

Contact your bank when ready by phone — use the number on the back of your card, not a number from an email or website. Tell them your account may have been compromised and ask them to review recent transactions. They can freeze your account, reverse fraudulent charges, and issue a new card if needed.