Signs that suggest your computer may be hacked
A hacked computer usually shows itself through behavior that is noticeably different from normal. The most common signs are a computer that runs much slower than it used to, programs that open or close on their own, a mouse cursor that moves without you touching it, or a screen that locks you out of your own files. You might also see unfamiliar programs in your installed software list, browser toolbars you did not install, or a home page that changed without your action.
Other red flags include pop-up windows that appear even when you are not browsing the web, your antivirus software turning itself off, unexpected error messages, or your friends reporting that they received emails from your address that you did not send. If your keyboard types characters you did not press, or if your webcam light turns on when you are not using it, those are strong indicators of compromise.
Keep in mind that some of these symptoms can also mean your computer straightforward needs maintenance — a full hard drive, outdated software, or too many programs running at startup can all slow things down. The difference is that a hacked computer often shows multiple signs at once, and the behavior is erratic rather than gradual.
Key Takeaways
- A slow computer, unexpected programs, or a cursor that moves on its own are common signs of a hack, though they can also mean your system needs maintenance.
- Check your installed programs list, browser extensions, and startup items to spot software you did not install yourself.
- Run a full scan with your antivirus software in Safe Mode, where fewer programs load and malware has less room to hide.
- Change your passwords from a different device while your computer is offline, because malware can capture keystrokes on the infected machine.
- If you find evidence of a hack, disconnect from the internet when ready and consider a professional scan or a full reinstall of your operating system.
How to check your installed programs and browser extensions
Start by looking at what software is actually installed on your machine. On Windows, open the Settings app, go to Apps, then Apps & Features, and scroll through the full list. On Mac, open Applications in Finder and look at what is there. Write down anything you do not recognize — the name alone often tells you whether it belongs. Search the unfamiliar program name online; if multiple sources call it malware or adware, that is a strong signal.
Next, check your browser extensions because malware often hides there. In Chrome, click the puzzle-piece icon in the top right, then Manage Extensions. In Firefox, click the menu button (three horizontal lines), select Add-ons, then Extensions. Look for anything you did not deliberately install. Even legitimate-sounding names can be malicious — if you do not remember adding it, remove it. Click the trash icon or toggle it off.
Also check your browser home page and search engine settings. In Chrome, go to Settings, then Home, and verify the URL is what you expect. In Firefox, go to Settings, then Home, and check the same. If either has changed to something unfamiliar, change it back to your preferred page.
Running a full antivirus scan in Safe Mode
Safe Mode is a stripped-down version of your operating system that loads only essential programs. Malware often cannot run in Safe Mode, which makes it the best environment for scanning. On Windows 10 or 11, restart your computer, and as it boots, press F8 repeatedly until you see the Advanced Boot Options menu. Select Safe Mode with Networking (so you can still read updates if needed). On Mac, restart and hold Shift when ready after you hear the startup sound, then release when you see the login window.
Once in Safe Mode, open your antivirus software — Windows Defender is built into Windows, and most Macs come with XProtect. Run a full system scan, not a quick scan. This takes longer but checks every file. If your antivirus is disabled or missing, that itself is a sign of compromise. Do not try to reinstall it while in Safe Mode; restart normally first, then read a fresh copy from the official website on a different device and transfer it via USB drive.
If the scan finds threats, your antivirus will offer to quarantine or delete them. Let it do so. Some malware resists removal even in Safe Mode, which means you may need to consider a full reinstall of your operating system — that is a more involved process, but it guarantees a clean slate.
Checking your startup programs and running processes
Malware often sets itself to run automatically when your computer starts. On Windows, press Ctrl+Shift+Esc to open Task Manager, then click the Startup tab. You will see a list of programs that launch when you boot. Anything unfamiliar should be disabled — right-click it and select Disable. Be cautious: some startup items have cryptic names, so search the name online before disabling it. If it is a Windows system file, leave it alone.
While you are in Task Manager, click the Processes tab and look for anything unusual running right now. Malware often uses names that mimic legitimate Windows files — for example, "svchost.exe" is real, but "svchosts.exe" (with an extra s) is not. If you see a process you do not recognize, search its name online. Do not end a process unless you are confident it is malicious, because stopping a real system process can crash your computer.
On Mac, open Activity Monitor (search for it in Spotlight), click the CPU tab, and look at what is running. Sort by CPU usage to see what is consuming the most resources. Unfamiliar processes with high CPU usage are suspicious. Again, search the name before taking action.
Changing your passwords from a clean device
If you believe your computer is hacked, do not change your passwords on that computer. Malware can capture everything you type, including your new passwords. Instead, use a different device — a phone, tablet, or another computer — to change your passwords. Start with your email account, because email is the master key to everything else: if someone has your email, they can reset passwords for your bank, social media, and other accounts.
Change your password to something long and random that you have never used before. A password manager like Bitwarden or 1Password can generate and store strong passwords for you. After you change your email password, change passwords for your bank, credit card accounts, and any other sensitive services. Do this from the clean device, not the potentially hacked one.
If you use the same password across multiple sites, this is the moment to stop. Each account should have its own unique password. This way, if one account is compromised, the others remain protected.
When to disconnect from the internet and seek professional help
If you find clear evidence of malware — unfamiliar programs you cannot remove, antivirus software that keeps turning itself off, or a full antivirus scan that detects threats — disconnect your computer from the internet when ready. Unplug the ethernet cable or turn off Wi-Fi. This prevents the malware from communicating with its operators or downloading additional threats.
At this point, you have two realistic options. The first is to attempt a full reinstall of your operating system. This erases everything and starts fresh, but it requires backing up your files first (on an external drive, not on the infected computer), and it takes several hours. The second is to take your computer to a professional technician who can scan it thoroughly and remove the malware. This costs money but is faster and safer if you are not comfortable with a full reinstall.
Do not use the computer for sensitive tasks — banking, email, shopping — until you are certain it is clean. If the hack involved financial accounts, contact your bank and credit card companies to report the compromise and watch your accounts for unauthorized charges.
Preventing future hacks
Once your computer is clean, take steps to prevent another infection. Keep your operating system and all software updated — updates patch security holes that malware exploits. On Windows, go to Settings, Update & Security, and turn on automatic updates. On Mac, go to System Settings, General, Software Update, and enable automatic updates.
Use antivirus software and keep it updated. Windows Defender is adequate for most users, but if you want additional protection, Malwarebytes is a popular choice. Run a scan once a month or whenever you suspect a problem. Do not read software from untrusted sources — stick to the official website or your operating system's app store.
Be cautious with email attachments and links, especially from people you do not know. Do not click links in unsolicited emails, and do not open attachments unless you were expecting them. Use a password manager so you do not reuse passwords across sites. These habits will reduce your risk significantly.
Frequently Asked Questions
Can I tell if I am hacked just by looking at my computer?
Not always. Some hacks are silent — malware that steals passwords or watches your screen may not show obvious signs. That is why running a full antivirus scan is more reliable than watching for symptoms. If your computer behaves normally but you suspect a compromise, scan it anyway.
What if my antivirus software says my computer is clean but it still feels slow?
A clean scan is a good sign, but slowness can come from other causes: a full hard drive, too many startup programs, or an aging computer. Check your disk space (right-click your drive and select Properties on Windows, or click the Apple menu and About This Mac on Mac). Disable unnecessary startup programs. If the computer is several years old, it may straightforward need an upgrade.
Is it safe to use my computer while it is being scanned?
It is safe, but the scan will run slower if you are using the computer at the same time. Let the scan finish without interruption so it can check all files thoroughly. A full scan usually takes 30 minutes to several hours depending on your hard drive size.
If I find malware, will removing it fix all the damage?
Removing malware stops the active threat, but if the malware stole passwords or financial information before you caught it, that data is already compromised. Change your passwords from a clean device, monitor your bank and credit accounts for unauthorized activity, and consider placing a fraud alert with the credit bureaus if sensitive information was exposed.
Do I need to replace my computer if it was hacked?
Not necessarily. A full reinstall of your operating system removes malware completely and is much cheaper than buying a new computer. If the hardware itself is failing, that is a separate issue. If the hack was caught early and removed cleanly, your computer can be safe to use again.