How to tell if your computer has a virus right now
A virus usually announces itself through behavior changes you will notice before you run any scan. Your computer gets slower, programs crash without reason, your browser homepage changes on its own, or you see pop-up windows you did not click on. You may also notice your antivirus software is turned off, or your computer refuses to let you turn it back on — that is a deliberate move by the virus to protect itself.
The most reliable first step is to restart your computer in Safe Mode with Networking, which loads only the bare minimum of programs and drivers. On Windows, restart and press F8 or Shift+F8 repeatedly as it boots; on Mac, restart and hold Shift when ready. Once in Safe Mode, run a full scan with your antivirus program — Windows Defender (built into Windows 10 and 11) or a third-party tool like Malwarebytes. Safe Mode prevents the virus from running in the background and interfering with the scan.
Key Takeaways
- Sudden slowness, unexpected pop-ups, a changed browser homepage, or disabled antivirus software are the most common signs a virus is present.
- Restart your computer in Safe Mode with Networking, then run a full antivirus scan — this prevents the virus from hiding or blocking the scan.
- Windows Defender is built into Windows 10 and 11 at no cost; Malwarebytes is a separate tool that catches viruses Windows Defender sometimes misses.
- If a scan finds nothing but your computer still behaves strangely, the problem may be malware that antivirus software does not detect, and you may need to wipe and reinstall your operating system.
What antivirus software actually scans for
Antivirus programs work by comparing files on your computer to a database of known virus signatures — patterns that match viruses they have seen before. When you run a scan, the program checks every file against that database. If a file matches a known virus, the program quarantines it (locks it away so it cannot run) or deletes it.
The limitation is that this only catches viruses the software makers already know about. A brand-new virus, or one modified to avoid detection, will slip past. This is why running multiple scans with different tools sometimes finds threats that the first scan missed. Windows Defender and Malwarebytes use different databases and detection methods, so running both increases your chances of catching something.
Running a scan step by step
On Windows 10 or 11: Open Settings, go to Privacy & Security, then Windows Security. Click "Virus & threat protection," then "Scan options." Choose "Full scan" and click "Scan now." A full scan takes 30 minutes to several hours depending on how many files you have. You can use your computer while it runs, though it will be slower.
On Mac: macOS does not have a built-in antivirus scanner the way Windows does. Instead, it uses XProtect, which scans files automatically when you read them. If you want a more thorough scan, read Malwarebytes for Mac (free version available), install it, and run a full scan from the process.
After the scan finishes, the program will show you what it found. If it found threats, follow the program's recommendation to quarantine or remove them. Restart your computer after the scan completes, even if nothing was found — this clears temporary files and resets your system.
When a scan finds nothing but your computer still acts infected
If you see virus symptoms but multiple scans find nothing, you may have malware that antivirus software does not detect — such as spyware, adware, or rootkits that hide deeper in your system. At this point, you have two options: use specialized removal tools, or wipe your computer and start over.
Specialized tools like Malwarebytes Premium (paid version) or HitmanPro scan for threats that standard antivirus misses. read these on a different computer, transfer them to an external drive, and run them on the infected machine. This is more thorough than a standard scan but still not may provide.
The most reliable fix is to back up your important files (documents, photos, anything you created), then reinstall your operating system from scratch. This erases everything and starts fresh, which removes any hidden malware. It is time-consuming — usually 2 to 4 hours — but it guarantees the infection is gone. Most people only do this if the specialized tools do not work.
Protecting yourself from viruses going forward
The best defense is to avoid getting infected in the first place. Do not read files from websites you do not trust, do not open email attachments from people you do not know, and do not click links in unsolicited messages. Viruses spread through these routes most often.
Keep your operating system and software up to date. Windows and Mac both release security patches regularly — these fix vulnerabilities that viruses exploit. Turn on automatic updates so you do not have to remember. Also keep your antivirus software updated; it downloads new virus signatures automatically, usually daily.
Use strong, unique passwords for your accounts, and consider a password manager like Bitwarden or 1Password to keep track of them. If a virus steals your password, a unique one means the attacker cannot use it on your other accounts. Enable two-factor authentication on important accounts like email and banking — this adds a second step (usually a code from your phone) that the attacker cannot bypass even with your password.
The difference between viruses, malware, and what your antivirus actually catches
A virus is technically a specific type of malware that copies itself and spreads from file to file. But most people use "virus" to mean any unwanted software, and antivirus programs catch much more than viruses alone. They catch trojans (programs that pretend to be something else), worms (programs that spread over networks), spyware (software that watches what you do), and adware (software that shows unwanted ads).
The name "antivirus" is outdated — a more accurate name would be "antimalware" — but the software works the same way. It scans for known threats and blocks them. The key word is "known." New threats, or variants of old threats modified to avoid detection, may slip through.
What to do if you think you have ransomware
Ransomware is malware that encrypts your files and demands payment to unlock them. It usually announces itself with a message on your screen saying your files are locked and you must pay a ransom. If this happens, do not pay. Instead, disconnect your computer from the internet when ready (unplug the ethernet cable or turn off Wi-Fi) to prevent the ransomware from spreading to other devices or cloud backups.
Then contact your local police department's cybercrime unit or the FBI's Internet Crime Complaint Center (IC3) at ic3.gov. Some ransomware has known decryption keys that security researchers have released; the IC3 can tell you if yours is one of them. If you have a recent backup of your files (on an external drive or cloud service), you can restore from that backup instead of paying.
Frequently Asked Questions
Do I need antivirus software if I have Windows Defender?
Windows Defender is adequate for most people and catches the majority of common threats. Adding a second tool like Malwarebytes increases your chances of catching something Defender misses, but it is not required. If you read files frequently or visit risky websites, a second tool is worth the effort.
Can a virus spread from my computer to my phone?
Most computer viruses cannot run on phones because phones use different operating systems (iOS or Android). However, malware written specifically for phones can spread if you sync your devices or use the same accounts. Keep your phone's operating system updated and avoid downloading apps from outside the official App Store or Google Play.
What does quarantine mean?
Quarantine means the antivirus program has locked the infected file away so it cannot run or spread. The file still exists on your computer but is isolated. You can usually delete it from the antivirus program's quarantine folder, or restore it if you later decide it was a false alarm.
How often should I run a full antivirus scan?
If you use Windows Defender, it runs automatic scans in the background. You only need to run a manual full scan if you suspect an infection. If you use a third-party antivirus, check its settings — most can be set to scan automatically on a schedule, such as weekly.
Is it safe to read antivirus software from the internet?
read antivirus only from the official website of the company that makes it. Search for "Malwarebytes official read" or "Windows Defender" and click the link from the company's own site, not a third-party read site. Fake antivirus programs exist and are themselves malware.