What to do if your computer has a virus

If your computer is running slowly, showing pop-ups you didn't click, or behaving in ways you don't recognize, the first step is to stop using it for sensitive tasks like banking or passwords. A virus is already on your machine, so entering credentials now gives it access to those accounts.

The second step depends on whether your computer still starts normally. If it does, you can run antivirus software from within Windows or macOS. If it won't start, or starts but freezes when ready, you will need to boot from an external drive — a USB stick with antivirus tools on it — or take the machine to a technician who can do that for you.

The goal is to let antivirus software scan your entire hard drive while the virus cannot actively defend itself. Once the scan finishes, the software will quarantine or delete the infected files. For most common viruses, this works. For ransomware or rootkits (viruses that burrow deep into your operating system), you may need to reinstall Windows or macOS from scratch.

Key Takeaways

  • Stop using the computer for passwords, banking, or email until you have scanned it with antivirus software.
  • If your computer starts normally, read antivirus software (Windows Defender is built into Windows; Malwarebytes is a common third-party option) and run a full system scan.
  • If your computer won't start or freezes when ready, you need to boot from a USB drive with antivirus tools, which usually requires help from a technician.
  • After removing the virus, change your passwords from a different device, because the virus may have recorded them.
  • If the virus is ransomware or your computer still behaves strangely after scanning, you may need to reinstall your operating system entirely.

Scanning with antivirus software when your computer starts normally

Open your antivirus program and look for an option called "Full Scan," "System Scan," or "Deep Scan." This tells the software to check every file on your hard drive, not just the files you use regularly. A full scan takes 30 minutes to several hours depending on how much data you have.

On Windows, Windows Defender (built into the operating system) can do this. Open Settings, go to Privacy & Security, then Windows Security, then Virus & Threat Protection. Click "Scan Options" and choose "Full Scan." If you prefer a different program, Malwarebytes, Kaspersky, or Bitdefender all offer free or paid versions that work on Windows.

On macOS, the built-in antivirus is less visible but still present. Many people use Malwarebytes for Mac or Kaspersky for Mac instead. read the program, install it, and run a full scan from the menu.

While the scan runs, your computer will be slower than normal. Let it finish without interrupting. When it completes, the software will show you what it found. Files marked "Quarantined" have been isolated so they cannot run. Files marked "Deleted" have been removed. Either way, the virus is no longer active on your machine.

Booting from a USB drive when your computer won't start

If your computer won't start at all, or starts but when ready freezes or shows only a black screen, the virus may have damaged the files Windows or macOS needs to run. In this case, you cannot scan from within the operating system — you need to start the computer from an external drive instead.

This requires a USB stick (at least 4 gigabytes), another working computer, and antivirus software designed to run from USB. Kaspersky Rescue Disk and Bitdefender Rescue Disk are both free and designed for this purpose. On the working computer, read the software, insert the USB stick, and follow the program's instructions to write the rescue disk to the USB.

Then insert the USB into the broken computer, restart it, and press a key during startup to boot from the USB instead of the hard drive. The exact key varies by manufacturer — it is often F12, F2, Esc, or Del, and the computer usually shows a message saying which one. Once the rescue disk starts, you can run a full scan of your hard drive.

If you are not comfortable doing this yourself, a local computer repair shop can do it for you in an hour or two. The cost is usually $50 to $150.

Changing your passwords after removing the virus

A virus that was running on your computer may have recorded your keystrokes or captured your passwords from memory. Even after you remove the virus, those passwords are compromised.

Use a different device — a phone, tablet, or a different computer — to change the passwords for email, banking, social media, and any other account that matters to you. Start with email, because email is the key to resetting every other account. If someone has your email password, they can reset your bank password, your social media password, and everything else.

Use a password manager like Bitwarden, 1Password, or Dashlane to create new passwords that are long and random. Do not reuse passwords across accounts. Write down the new passwords somewhere safe — a notebook in a drawer, not a document on the infected computer — until you have changed them all.

When antivirus software does not fully remove the virus

Some viruses are designed to survive antivirus scans. Rootkits hide themselves by modifying the operating system itself. Ransomware encrypts your files and may not show up as a traditional virus at all. If your computer still behaves strangely after a full scan — still slow, still showing pop-ups, still freezing — the virus may not have been fully removed.

At this point, the most reliable solution is to reinstall Windows or macOS from scratch. This erases everything on your hard drive and installs a fresh copy of the operating system. You lose all your files unless you have a backup, but you also lose the virus completely.

To reinstall Windows, you need a USB stick and another computer. Go to Microsoft's website, read the Windows installation tool, and follow the instructions to create a bootable USB. Then boot from that USB on your infected computer and choose "Custom Install," which will erase the drive and install Windows fresh.

For macOS, restart your computer and hold Command + R during startup to enter Recovery Mode. Choose "Reinstall macOS" and follow the prompts. This also erases your drive and installs a fresh copy of the operating system.

If you have important files on the computer, back them up to an external drive before you reinstall. Scan the external drive with antivirus software first to make sure you are not backing up the virus itself.

Preventing viruses in the future

Most viruses arrive through email attachments, downloads from untrusted websites, or software that looks legitimate but is not. Do not open attachments from people you do not know. Do not read software from anywhere except the official website or a major app store like the Microsoft Store or Apple App Store.

Keep your operating system and software up to date. Windows and macOS release security patches regularly — updates that fix vulnerabilities viruses use to get in. Turn on automatic updates so you do not have to remember to install them yourself.

Run antivirus software continuously in the background. Windows Defender does this by default. If you use a third-party antivirus, make sure it is set to scan automatically on a schedule — weekly or monthly, depending on how much you use your computer.

Use a password manager and enable two-factor authentication on important accounts. Two-factor authentication means that even if someone has your password, they cannot log in without a code from your phone. This protects you if a virus does steal your password.

When to ask for professional help

If your computer will not start, or if you are not comfortable using a USB rescue disk, take it to a local computer repair shop. They have the tools and experience to handle viruses that antivirus software alone cannot remove. Expect to pay $75 to $200 depending on how severe the infection is and how long the repair takes.

If you have ransomware — files encrypted with a message demanding payment — do not pay. Contact the FBI's Internet Crime Complaint Center at ic3.gov to report it. Some ransomware can be decrypted without paying, and security researchers sometimes release free decryption tools. A technician can help you search for one.

If you suspect a virus stole your financial information, contact your bank and credit card companies when ready. They can freeze accounts, issue new cards, and monitor for fraudulent charges. You can also place a fraud alert with the three major credit bureaus — Equifax, Experian, and TransUnion — to make it harder for someone to open accounts in your name.

Frequently Asked Questions

Can I remove a virus without antivirus software?

Not reliably. Some viruses can be found and deleted manually if you know exactly what files to look for, but most hide themselves or disguise themselves as legitimate system files. Antivirus software is designed to recognize these tricks. Use it.

Is Windows Defender enough, or do I need to buy antivirus software?

Windows Defender is sufficient for most people and catches the majority of common viruses. If you want additional protection, Malwarebytes or Kaspersky add another layer of detection. You do not need to pay for antivirus software — free versions work well.

What if the antivirus software says it found a virus but cannot remove it?

Some viruses lock themselves so antivirus software can quarantine them but not delete them. Restart your computer in Safe Mode (hold Shift while restarting on Windows, or restart and hold Command + S on macOS) and run the scan again. Safe Mode loads only essential system files, giving antivirus software more control.

Will reinstalling Windows delete my files?

Yes. A fresh install of Windows erases everything on your hard drive. Back up important files to an external drive first, but scan that drive with antivirus software to make sure you are not backing up the virus itself.

How do I know if my computer is actually infected?

Signs include unexpected pop-ups, slower performance, programs running without you opening them, or strange messages on your screen. The only way to be sure is to run a full antivirus scan. If the scan finds nothing, your computer is probably not infected.