Signs that suggest your computer may be compromised
A hacked computer usually shows itself through slowness, unexpected pop-ups, or programs running without your permission. Your mouse may move on its own, your browser may redirect to unfamiliar websites, or your antivirus software may be disabled. You might notice new user accounts you did not create, or find that your passwords no longer work even though you know them. These are not always signs of a hack — a slow computer can mean a failing hard drive, and pop-ups can come from legitimate websites — but they are worth investigating.
The most reliable sign is behavior you did not cause. If your computer is doing something you did not ask it to do, and it continues after a restart, something is wrong. That something may be malware, a virus, spyware, or a rootkit — each works differently and requires different removal steps.
Key Takeaways
- Unexplained slowness, pop-ups that appear even when you are not browsing, and disabled antivirus software are common signs of infection.
- Check your running programs, user accounts, and browser homepage — hackers often change these without asking.
- Restart your computer in Safe Mode with Networking to see which programs load without your interference.
- If you find signs of compromise, disconnect from the internet, change your passwords from a different device, and run a full antivirus scan.
- Some infections require professional removal or a complete reinstall of Windows or macOS.
Check what programs are running right now
Open Task Manager on Windows by pressing Ctrl+Shift+Esc, or Activity Monitor on Mac by pressing Command+Space, typing "Activity Monitor," and pressing Enter. Look at the list of running programs. Most will be unfamiliar — that is normal — but look for anything with a name that seems random or misspelled, or anything you do not remember installing.
If you see a program you do not recognize, search its name online before closing it. Some legitimate programs use confusing names. If you are certain it should not be there, right-click it and select "End Task" (Windows) or click it and press the X button (Mac). Do not delete the file yet — just stop it from running. If your computer becomes unstable after closing it, restart and try again.
Look at your browser settings and homepage
Open your web browser and check what your homepage is set to. If it is not what you chose, someone may have changed it. Check your browser extensions or add-ons — on Chrome, click the three vertical dots, go to "More tools," then "Extensions." On Firefox, click the menu button and select "Add-ons." Look for anything you do not remember installing, especially anything with a vague name or no clear purpose.
Delete any extension you do not recognize. Then check your browser's search engine setting. On Chrome, click the three dots, go to "Settings," then "Search engine," and confirm it is set to Google, Bing, or whatever you chose. If it has been changed to something unfamiliar, change it back.
Review your user accounts and recent logins
On Windows, open Settings, go to "Accounts," and click "Other people." Look for any user account you did not create. If you find one, right-click it and select "Delete." On Mac, open System Settings, click "General," then "Users & Groups," and look for unfamiliar accounts. Click the lock icon to unlock the list, select any unknown account, and click the minus button to remove it.
If you have a Microsoft account (Windows) or Apple ID (Mac), sign in to your account online and check the "Recent activity" or "Devices" section. This shows where your account has been accessed from and when. If you see logins from places you were not, or at times you were not using your computer, your account may have been compromised. Change your password when ready from a different device.
Restart in Safe Mode and run a full scan
Safe Mode loads only the essential programs Windows or macOS needs to run, which makes it easier to spot infections. On Windows 10 or 11, hold Shift and click the power button in the Start menu, then select "Restart." When the blue menu appears, click "Troubleshoot," then "Advanced options," then "Startup Settings," and press 4 or F4 to enter Safe Mode. On Mac, restart your computer and hold Command+S until you see text on the screen, then type fsck -fy and press Enter.
Once in Safe Mode, open your antivirus software and run a full system scan. This may take an hour or more. If your antivirus is disabled or missing, read Malwarebytes (free version) from a different computer, transfer it on a USB drive, and run it in Safe Mode. Let the scan finish completely before restarting.
Change your passwords from a different device
If you believe your computer is hacked, do not change your passwords on that computer — a hacker with access can intercept them. Instead, use your phone, tablet, or a different computer to change the passwords for your email, banking, social media, and any other important accounts. Start with your email, since that is the master key to resetting other accounts.
Use a strong password: at least 12 characters, mixing uppercase and lowercase letters, numbers, and symbols. Avoid words from the dictionary or information a hacker might know about you. If any of your accounts show suspicious activity — logins you did not make, password changes you did not authorize, or emails sent from your account — contact the service when ready and ask them to review the account for unauthorized access.
When to disconnect and seek professional help
If your computer is infected with ransomware (software that locks your files and demands payment), do not pay. Disconnect the computer from the internet when ready and contact a local computer repair shop or your IT department if you are at work. Ransomware spreads to other devices on your network, so unplug the ethernet cable or turn off Wi-Fi right away.
If a full antivirus scan in Safe Mode does not remove the infection, or if your computer remains unstable after removal, a professional may need to reinstall Windows or macOS from scratch. This erases everything on the drive, so back up your files first if possible — but only if you are certain the files themselves are not infected. A repair technician can help you decide whether reinstalling is necessary.
Frequently Asked Questions
Can a hacker see me through my webcam?
Yes, if malware has infected your computer. If you are concerned, cover your webcam with tape or a sliding cover. Check your antivirus scan results to see whether any spyware was found. If you find evidence of spyware, change all your passwords from a different device after removing it.
What if I cannot restart in Safe Mode?
Some infections prevent Safe Mode from loading. Try restarting and pressing F8 repeatedly before Windows loads — this may open an older boot menu. If that does not work, you may need to use a bootable antivirus USB drive created on another computer, or take your computer to a repair shop.
Will restarting my computer remove a hack?
A restart stops most malware temporarily, but it will start again when your computer boots. Restarting is useful for seeing what loads automatically, but it does not remove infections. You need antivirus software or professional removal to eliminate the threat permanently.
Is my data safe if my computer was hacked?
Not necessarily. A hacker with access to your computer can steal files, passwords, banking information, and personal documents. Change your passwords when ready from another device, monitor your bank and credit accounts for unauthorized charges, and consider placing a fraud alert with the credit bureaus if financial information was exposed.
What is the difference between a virus and malware?
A virus is a type of malware that copies itself and spreads to other files. Malware is the broader category — it includes viruses, spyware, ransomware, and other harmful software. Antivirus software removes both, so the distinction does not matter much for removal purposes.