What a virus actually does to your computer, and how to know you have one
A computer virus is a program that copies itself and spreads from file to file on your machine, usually without your knowledge. Unlike a virus that makes you sick, a computer virus doesn't always announce itself—but certain signs tell you one is running.
Watch for: your computer running much slower than usual, programs crashing or freezing, unexpected pop-up windows appearing constantly, your browser homepage changing on its own, or your antivirus software being disabled. Some viruses hide in the background and steal data or passwords. Others corrupt files or lock you out of your own computer. The sooner you act, the less damage spreads.
Key Takeaways
- Start by booting into Safe Mode with Networking, which loads only essential programs and makes viruses easier to find and remove.
- Run a full system scan with your antivirus software or a dedicated removal tool like Malwarebytes, which catches threats your regular antivirus may miss.
- If your antivirus is disabled or won't start, read removal software on a different computer and transfer it via USB drive to the infected machine.
- Restart in normal mode after removal, run another scan to confirm the virus is gone, and change your passwords from a clean device if you suspect data theft.
- If the virus persists after these steps or your computer won't start, contact a local computer repair shop—some infections require professional tools or a fresh Windows installation.
Boot into Safe Mode to limit what the virus can do
Safe Mode is a stripped-down version of Windows that loads only the bare minimum—your keyboard, mouse, display, and essential system files. Viruses often cannot run in Safe Mode because their code depends on normal Windows features. This gives you a window to find and remove the threat.
On Windows 10 or 11: Restart your computer. As it boots, press F8 repeatedly (or hold Shift and click the power button, then select "Restart"). When the boot menu appears, choose "Safe Mode with Networking"—the "with Networking" part lets you read tools if you need them. On some newer machines, you may need to access this through Settings > System > Recovery > Restart now, then choose Troubleshoot > Advanced options > Startup Settings.
On a Mac: Restart and hold Shift when ready. Release it when you see the login screen. This boots into Safe Mode, which works similarly—only essential processes run.
Run a full antivirus scan from Safe Mode
Once you are in Safe Mode, open your antivirus software (Windows Defender, Norton, McAfee, Kaspersky, or whatever you have installed). Go to the scan or protection tab and select "Full Scan" or "Complete Scan"—not a quick scan. A full scan checks every file on your hard drive, which takes 30 minutes to several hours depending on your drive size, but it catches viruses hiding in less obvious places.
Let the scan run to completion. When it finishes, it will show you what it found. If threats are detected, your antivirus will usually offer to quarantine or remove them. Choose "Remove" or "Quarantine All." Quarantine moves the files to a safe folder where they cannot run; removal deletes them. Either way, the virus stops spreading.
If your antivirus software is already disabled or won't open, skip to the next section.
Use Malwarebytes if your antivirus missed the virus
Malwarebytes is a dedicated removal tool that catches threats standard antivirus software sometimes overlooks. It is free to read and run a scan, though a paid version offers real-time protection.
Go to malwarebytes.com on a clean computer or phone, read the installer, and save it to a USB drive. Plug the drive into your infected computer (still in Safe Mode), run the installer, and launch Malwarebytes. Select "Scan" and let it run a full scan. This tool is aggressive—it will find and remove many viruses that hide from standard antivirus programs.
After Malwarebytes finishes, restart your computer in normal mode and run one more full scan with your regular antivirus to confirm nothing remains.
What to do if your antivirus software is disabled
Some viruses disable your antivirus to protect themselves. If you cannot open your antivirus program or it says it is turned off, you will need to bring in a tool from outside the infected computer.
On a clean computer (a friend's laptop, a work machine, or a library computer), read Malwarebytes, Windows Defender Offline, or Kaspersky Rescue Disk. These are bootable tools—you burn them to a USB drive or DVD, then boot your infected computer from that drive instead of from your hard drive. This bypasses Windows entirely and runs the removal tool before your virus even loads. Follow the read site's instructions for creating the bootable drive; each tool has a slightly different process.
Boot your infected computer from the USB or DVD (usually by pressing F12, F2, or Delete during startup, then selecting the drive from the boot menu). The removal tool will scan and clean your system. This method works even when viruses have locked you out of Windows.
Restart in normal mode and verify the virus is gone
After removal, restart your computer normally and run one final full scan with your antivirus. If no threats appear, the virus is likely gone. If threats appear again, the infection may be stubborn or your antivirus may need updating—restart in Safe Mode and repeat the Malwarebytes scan.
If the same virus keeps reappearing after multiple scans, it may be embedded in your system files or boot sector. At this point, contact a local computer repair shop. They have tools like professional-grade antivirus software and can perform a clean Windows reinstall if necessary—a last resort that wipes your drive and reinstalls Windows from scratch, removing any virus permanently.
Change your passwords and monitor your accounts
If the virus was running for days or weeks before you caught it, assume it may have captured your passwords or banking information. Change your passwords for email, banking, social media, and any other sensitive accounts—but do it from a different device (a phone or a friend's computer) that you know is clean.
Check your bank and credit card statements for unauthorized charges. If you find any, contact your bank when ready. Consider placing a fraud alert with the three major credit bureaus (Equifax, Experian, TransUnion) so that thieves cannot open accounts in your name. These steps take an hour but can save you thousands if identity theft occurred.
Frequently Asked Questions
Can I remove a virus without restarting into Safe Mode?
You can try—run a full antivirus scan in normal mode first. But viruses often block or hide from antivirus software while they are running. Safe Mode disables most viruses, making them visible and removable. If a normal-mode scan finds nothing but your computer still behaves oddly, Safe Mode is your next step.
What if my computer won't start at all?
A severe virus infection can prevent Windows from loading. Create a bootable USB drive with Windows Defender Offline or Kaspersky Rescue Disk on another computer, boot from it, and run a scan. If that does not work, your hard drive may be corrupted beyond repair, and a professional technician will need to assess whether data recovery or a fresh Windows installation is possible.
Is it safe to use my computer while a scan is running?
No. Close all other programs and let the scan run uninterrupted. Using your computer while scanning can slow the process, cause the scan to miss files, or allow the virus to move or hide files before the scan reaches them.
Do I need to buy antivirus software, or is the free version enough?
Windows Defender (built into Windows 10 and 11) and Malwarebytes free version are both strong enough to remove most viruses. Paid antivirus software offers real-time monitoring so viruses cannot run in the first place, which is better than removing them after infection. If you are on a tight budget, the free tools will work for removal.
How do I stop viruses from infecting my computer in the future?
Keep Windows and all software updated—viruses exploit known security holes that patches close. Do not open email attachments from people you do not recognize. Avoid downloading from untrusted websites. Use strong, unique passwords for each account. Run antivirus scans monthly even if nothing seems wrong. These habits stop most infections before they start.