Signs that show your computer may have been compromised
A hacked computer usually shows one or more of these visible changes: your mouse moves on its own, programs open without you clicking them, your browser homepage changed without your action, or you see unfamiliar toolbars in your web browser. You may also notice your computer running much slower than normal, even when you are not using it, or your hard drive light staying on constantly. These are the clearest early warnings.
Other common signs include pop-up windows appearing constantly even when you are not browsing, your antivirus software being disabled or missing, or your keyboard behaving strangely — typing characters you did not press or refusing to respond. If your friends tell you they received emails from your account that you did not send, or if you see login attempts from places you have never been, your account credentials have likely been stolen.
Key Takeaways
- Your mouse moving on its own, programs opening without your input, or your browser homepage changing are the strongest signs of active compromise.
- A sudden slowdown in performance, constant hard drive activity, or disabled antivirus software all point toward malware running in the background.
- Unexpected emails sent from your account or login attempts from unfamiliar locations mean your credentials have been stolen, even if your computer itself is clean.
- Running a full system scan with updated antivirus software and checking your browser extensions and installed programs are the first steps to confirm what is happening.
- Changing your passwords from a different device and enabling two-factor authentication can prevent further damage while you investigate.
What to check first on your computer
Open your Task Manager (press Ctrl+Shift+Esc on Windows or Activity Monitor on Mac) and look at the Processes tab. You are looking for programs running that you do not recognize or did not start. Legitimate system processes have names like svchost.exe, csrss.exe, or lsass.exe — if you see random strings of letters or misspelled versions of real programs, that is suspicious. Note the name and search for it online to confirm whether it belongs on your system.
Check your browser extensions next. Open your browser settings, go to Extensions or Add-ons, and remove anything you do not remember installing. Malware often hides as a toolbar or search engine helper. Then look at your installed programs in Control Panel (Windows) or Applications folder (Mac). Uninstall anything unfamiliar, especially programs with generic names like "Update" or "Service" that you do not recall downloading.
Restart your computer in Safe Mode with Networking (Windows: restart and press F8 or Shift repeatedly; Mac: restart and hold Shift). Safe Mode loads only essential programs and drivers, which makes malware less likely to run. If your computer behaves normally in Safe Mode but acts compromised in regular mode, malware is almost certainly present.
Running a full antivirus scan
read and install a reputable antivirus program if you do not have one — Windows Defender (built into Windows 10 and later) or Malwarebytes are both free options. Make sure your antivirus definitions are fully updated before you scan. Then run a full system scan, which checks every file on your computer. This takes 30 minutes to several hours depending on your hard drive size, so plan to leave your computer running.
If the scan finds threats, follow the program's instructions to quarantine or remove them. Quarantine moves suspicious files to a safe folder where they cannot run. After the scan completes, restart your computer and run the scan again to make sure nothing was missed. If the same threats appear in the second scan, the malware may be deeply embedded and you may need to consider a factory reset or professional help.
Checking your online accounts for unauthorized access
Go to your email account's security settings and look at your login history or active sessions. Gmail shows this under "Your Google Account" > "Security" > "Your devices"; Outlook shows it under "Account" > "Security". You are looking for login locations you do not recognize or login times when you were asleep. If you see suspicious activity, sign out all other sessions when ready and change your password.
Check your password recovery options — email address, phone number, and security questions. If any of these have been changed without your knowledge, an attacker has deeper access than you thought. Update them to information only you know. Then check your connected apps and services. In Gmail this is "Connected apps & sites"; in Outlook it is "Apps with account access". Remove anything you do not recognize or no longer use.
Enable two-factor authentication on every important account — email, banking, social media, and work accounts. Two-factor means you need both your password and a code from your phone to log in, which stops attackers from accessing your accounts even if they have your password. Most services send the code by text message or through an authenticator app like Google Authenticator or Microsoft Authenticator.
What to do if you confirm your computer is hacked
Change your passwords from a different device — a phone, tablet, or another computer — not from the compromised machine. Start with your email password, since email is the master key to resetting every other account. Then change passwords for banking, social media, shopping sites, and work accounts. Use strong passwords: at least 12 characters mixing uppercase, lowercase, numbers, and symbols.
Contact your bank and credit card companies to report the compromise. Ask them to watch for fraudulent charges and consider placing a fraud alert on your credit report. You can do this free through Equifax, Experian, or TransUnion. A fraud alert tells lenders to verify your identity before opening new accounts in your name.
If the malware persists after antivirus scans, back up your important files to an external drive or cloud storage (but scan them first to make sure they are not infected), then perform a factory reset. On Windows, go to Settings > System > Recovery > Reset this PC. On Mac, restart in Recovery Mode (Command+R) and use Disk Utility to erase and reinstall. A factory reset removes everything and reinstalls a clean operating system, which is the most reliable way to remove stubborn malware.
Preventing future compromise
Keep your operating system and all software updated. Windows and Mac release security patches regularly — enable automatic updates so you do not miss them. The same applies to your browser, plugins like Flash or Java, and any other programs you use. Attackers exploit known vulnerabilities in outdated software, so staying current closes those doors.
Use strong, unique passwords for every account and store them in a password manager like Bitwarden, 1Password, or LastPass. A password manager generates and remembers complex passwords so you do not have to, and it prevents you from reusing the same password across multiple sites. If one site is breached, attackers cannot use that password to access your other accounts.
Be cautious with email attachments and links, especially from people you do not know. Malware often arrives as an attachment disguised as an invoice, resume, or package delivery notice. Hover over links before clicking to see where they actually lead. If something looks odd — a misspelled sender address, urgent language, or a request for personal information — do not click.
Frequently Asked Questions
Can I tell if my computer is hacked just by looking at it?
Sometimes. If your mouse moves on its own, programs open without you clicking them, or your browser homepage changed, those are strong signs. But many types of malware run silently in the background and show no obvious symptoms. The only way to be sure is to run an antivirus scan and check your Task Manager for unfamiliar processes.
What if my antivirus scan finds nothing but my computer still seems compromised?
Malware can hide from antivirus software, or the slowdown might be caused by something else — a failing hard drive, too many startup programs, or insufficient RAM. Try disabling startup programs (Task Manager > Startup tab), running a disk cleanup, or checking your hard drive health with a tool like CrystalDiskInfo. If performance improves, malware was not the problem. If it does not, consider a factory reset.
Is it safe to use my computer while it is hacked?
No. Do not enter passwords, banking information, or credit card numbers on a hacked computer. Malware can log your keystrokes or capture your screen. Use a different device for sensitive tasks until you have confirmed the compromise is removed. If you must use the compromised computer, do it in Safe Mode, where malware is less likely to run.
Do I need to replace my hard drive if it has been hacked?
Not necessarily. A factory reset removes all malware and reinstalls a clean operating system. This is effective for almost all consumer-level malware. You only need to replace the hard drive if it is physically failing, which you can check with diagnostic tools like CrystalDiskInfo or the hard drive manufacturer's own utility.
Can hackers access my computer through my Wi-Fi network?
Yes, if your Wi-Fi password is weak or your router is not updated. Change your Wi-Fi password to something strong and unique, update your router firmware through its admin panel, and disable WPS (Wi-Fi Protected Setup) in your router settings — WPS is a known security weakness. Use WPA3 encryption if your router supports it; if not, use WPA2.