What a virus actually does to your system

A computer virus is a program that copies itself onto your machine without your permission and runs code that the person who wrote it wants to run — usually to steal information, display ads, use your processor for mining cryptocurrency, or lock your files until you pay. Unlike the flu, it does not spread through the air; it spreads when you read an infected file, click a malicious link, or open an email attachment from someone you do not know.

Once installed, a virus lives in your hard drive or SSD and runs every time your computer starts. It can slow your machine down by consuming processor and memory, make your internet connection sluggish by sending data in the background, or cause programs to crash. Some viruses hide themselves so well that you notice only the side effects — your fan running constantly, your battery draining fast, or pop-up windows appearing for no reason.

The difference between a virus and other malicious software matters for removal. A trojan pretends to be something useful but is not; a worm spreads itself across networks; ransomware encrypts your files and demands money. The removal steps are similar for all of them, but the names matter when you are searching for help or describing the problem to someone else.

Key Takeaways

  • Most viruses run in the background and hide themselves, so you may not know you have one until your computer slows down, your fan runs constantly, or pop-ups appear.
  • Restarting your computer in Safe Mode with Networking lets you run antivirus software without the virus loading, which is the most reliable way to remove it.
  • Windows Defender (built into Windows) and Malwarebytes are both free and effective for finding and removing viruses; running both increases your chances of catching everything.
  • If your computer will not start normally or the virus blocks antivirus software from running, you may need to use a bootable antivirus tool on a USB drive or take the machine to a repair shop.
  • After removal, change your passwords on another device, turn on Windows Firewall, and keep Windows Update turned on to prevent the same virus from returning.

Starting in Safe Mode to stop the virus from running

Before you run any antivirus software, restart your computer in Safe Mode with Networking. This loads only the essential programs your operating system needs to run — not the virus. Safe Mode also lets you connect to the internet, which you need to read antivirus tools or updates.

On Windows 10 or 11, restart your computer and hold down the Shift key while clicking the power button to shut down. Power it back on. You will see a menu with repair options. Click "Troubleshoot," then "Advanced options," then "Startup Settings," then "Restart." When the computer restarts, press the number 4 or F4 to enter Safe Mode with Networking. On older Windows versions, restart and press F8 repeatedly as the computer boots until you see the Safe Mode menu.

On a Mac, restart and hold Command + S to enter Single-User Mode, or restart and hold Command + Option + R for Recovery Mode. From Recovery Mode, open Disk Utility and run Repair Disk, then restart normally. Macs are less commonly infected than Windows machines, but the principle is the same: you want to prevent the virus from loading before you try to remove it.

Running Windows Defender and Malwarebytes to find and remove the virus

Windows Defender comes built into Windows 10 and 11 and runs automatically in the background. To run a full scan in Safe Mode, click the Windows Start button, type "Windows Defender," and open Windows Security. Click "Virus & threat protection," then "Scan options," then select "Full scan." This will take 30 minutes to several hours depending on how much is on your drive, but it will check every file.

While Windows Defender scans, read Malwarebytes from malwarebytes.com on another device or on the same machine once Defender finishes. The free version is effective for one-time removal. Install it, open it, and click "Scan." Malwarebytes often catches viruses that Windows Defender misses because it uses different detection methods. If Malwarebytes finds threats, click "Quarantine" to isolate them so they cannot run.

Run both tools because they work differently. Windows Defender looks for known virus signatures — patterns that match viruses in its database. Malwarebytes looks for suspicious behavior — a program trying to hide itself, modify system files, or steal data. A virus that hides well from one tool may be obvious to the other. If either tool finds threats, restart your computer normally after quarantining them, then run both scans again to make sure nothing remains.

What to do if the virus blocks antivirus software from running

Some viruses are aggressive enough to prevent antivirus programs from opening or updating. If Windows Defender or Malwarebytes will not start, or if your computer will not boot into Windows at all, you need a bootable antivirus tool — a program that runs from a USB drive before Windows loads.

On another computer, read Kaspersky Rescue Disk or Avast Bootable Rescue Disk from their websites. Insert a blank USB drive, follow the tool's instructions to write the bootable image to the drive, then insert that drive into your infected computer and restart. The computer will boot from the USB instead of the hard drive, and the antivirus tool will run before the virus has a chance to load. Let it scan and remove threats, then restart normally.

If you do not have access to another computer or the bootable tool does not work, take your machine to a local computer repair shop. They have professional tools and can remove the virus without losing your files. The cost is usually between $100 and $300 depending on how badly infected the machine is.

Changing passwords and securing your accounts after removal

Once the virus is gone, assume that any passwords you typed while infected have been stolen. On a different device — a phone, tablet, or another computer — change the passwords for your email, bank, social media, and any other account that matters. Do this on a device you are confident is not infected.

Start with your email password because your email is the key to resetting every other password. If the virus stole your email password, an attacker can use it to reset your bank password, your social media password, and anything else tied to that email address. After you change your email password, go through your email recovery options (phone number, backup email address) and make sure they are still yours.

If you use the same password across multiple sites, change all of them. If you do not use a password manager, consider setting one up now — Bitwarden and 1Password both store unique passwords for each site so that if one account is compromised, the others are not. This takes an hour but prevents the same virus from giving an attacker access to everything.

Turning on Windows Firewall and keeping Windows Update enabled

Windows Firewall is a built-in tool that blocks unauthorized programs from connecting to the internet. It is usually on by default, but if you turned it off to fix a different problem, turn it back on now. Click the Windows Start button, type "Windows Defender Firewall," and open it. Make sure both "Private networks" and "Public networks" show "Windows Defender Firewall is on."

Windows Update downloads security patches that close the holes viruses use to get in. Many people turn it off because updates restart the computer at inconvenient times, but turning it off leaves you vulnerable. Go to Settings, click "Update & Security," then "Windows Update," and make sure "Automatic (recommended)" is selected. You can choose the time of day updates install by clicking "Change active hours."

These two steps — Firewall on and Windows Update automatic — stop most viruses from coming back. They do not require you to do anything after you set them once. The combination of automatic updates and a working firewall is more effective than any antivirus software because it prevents infection in the first place rather than cleaning it up afterward.

Preventing the same virus from returning

Most people get the same virus twice because they do not change the behavior that let it in the first time. If you got infected by opening an email attachment from someone you did not know, stop opening attachments from strangers. If you got infected by downloading a cracked program or a movie from a torrent site, stop doing that. If you got infected by clicking a link in a pop-up, close pop-ups by clicking the X button, not by clicking inside them.

Use common sense about what you read. Programs from the Microsoft Store, the Apple App Store, or the official websites of well-known companies (Google, Adobe, Mozilla) are safe. Programs from random websites, especially if they promise something free that normally costs money, are often infected. If a website asks you to disable your antivirus to install something, that is a sign the thing you are installing is malicious.

Keep your browser up to date because browsers are a common entry point for viruses. Chrome, Firefox, Edge, and Safari all update automatically if you let them. Do not disable automatic updates to avoid restart prompts — the restart takes five minutes, but a virus infection takes hours to clean up.

Frequently Asked Questions

How do I know if my computer has a virus?

Common signs are a constantly running fan, slow performance even when you are not running programs, unexpected pop-ups, programs crashing, or your internet connection being slow. Open Task Manager (Ctrl + Shift + Esc on Windows) and look at the CPU and Memory columns. If something is using 50% or more of your processor and you do not recognize the program name, that is suspicious. Run Windows Defender and Malwarebytes to scan.

Will removing a virus delete my files?

Antivirus software removes the virus but leaves your documents, photos, and other files alone. However, some viruses (called ransomware) encrypt your files and demand money to unlock them. If your files are encrypted, do not pay. Contact the FBI's Internet Crime Complaint Center or your local police department. Restore from a backup if you have one.

Can I get a virus from visiting a website?

Yes, if the website is malicious or has been hacked. You do not have to click anything — just visiting can trigger a read. This is called a drive-by read. Keep your browser and operating system updated, use Windows Firewall, and avoid websites that look suspicious or ask you to read things you did not request.

Is it safe to use my computer while antivirus software is scanning?

Yes, but it will be slow. The antivirus tool is reading every file on your drive, which takes processor and disk time. If you need to use your computer, let the scan finish first — it usually takes less time than you think, and you will get better results.

What if I cannot remove the virus myself?

Take your computer to a local repair shop. They have professional tools, bootable antivirus disks, and experience with stubborn infections. The cost is usually $100 to $300. Do not mail your computer to a repair service unless you are sure the company is legitimate — shipping a computer with sensitive files on it carries risk.