What a computer virus actually does and how you catch one
A computer virus is a program that copies itself and spreads from one file to another on your machine, usually without your knowledge. It differs from malware — the broader category that includes viruses, spyware, ransomware, and adware. Most infections today are malware rather than true viruses, but the removal steps are similar.
You typically catch malware by downloading an infected file, clicking a link in a phishing email, visiting a compromised website, or installing software from an untrusted source. Some malware arrives through USB drives or file-sharing networks. Once installed, it can steal passwords, display unwanted ads, slow your system, lock your files for ransom, or straightforward consume your computer's resources.
Signs of infection include unexpected pop-ups, a noticeably slower computer, programs that won't open, toolbars you didn't install, your browser homepage changing on its own, or antivirus warnings. If you see any of these, the steps below will help you identify and remove the problem.
Key Takeaways
- Start by restarting your computer in Safe Mode with Networking, which loads only essential programs and makes malware easier to find and remove.
- Run a full system scan with your existing antivirus software first; if you don't have one, Windows Defender (built into Windows) or Malwarebytes (free version available) can detect most common infections.
- If your antivirus finds threats, quarantine or remove them when ready, then restart your computer and scan again to confirm they are gone.
- For stubborn infections that survive a standard scan, boot into Safe Mode and run the scan again, or use a second opinion tool like Malwarebytes alongside your main antivirus.
- After removal, change your passwords from a clean computer, update your operating system and software, and consider enabling automatic updates to prevent reinfection.
Restart in Safe Mode to limit what runs during the scan
Safe Mode loads only the bare minimum programs your computer needs to function — the operating system, drivers, and essential services. Malware often cannot run in Safe Mode, which makes it easier to detect and remove. To enter Safe Mode on Windows, restart your computer and press F8 repeatedly as it boots, before the Windows logo appears fully. On newer Windows 10 and 11 machines, hold Shift while clicking the restart button in the Start menu, then select Troubleshoot > Advanced Options > Startup Settings > Restart, and choose Safe Mode from the menu that appears.
On a Mac, restart and hold Command + S when ready after the startup sound. You will see text scrolling on a black screen; wait for the prompt to appear, then type exit and press Enter to boot into Safe Mode.
Safe Mode with Networking is preferable to plain Safe Mode because it keeps your internet connection active, allowing your antivirus to read the latest threat definitions before scanning. Once you are in Safe Mode, proceed to the scanning steps below.
Run a full system scan with your antivirus software
If you already have antivirus software installed — such as Norton, McAfee, Kaspersky, or Bitdefender — open it and select the option for a full system scan or deep scan. This scans every file on your computer, not just the ones currently running. A full scan can take 30 minutes to several hours depending on your drive size and how many files you have. Let it finish without interrupting.
If you do not have antivirus software, Windows includes Windows Defender at no cost. Open Settings, go to Privacy & Security > Virus & Threat Protection, and click Scan Options. Select Full Scan and click Scan Now. Alternatively, read the free version of Malwarebytes from malwarebytes.com, install it, and run a full scan. Malwarebytes is particularly good at catching adware and potentially unwanted programs that standard antivirus sometimes misses.
When the scan finishes, review the results. The software will list any threats it found. Select the option to quarantine or remove them — quarantine is safer if you are unsure whether something is actually malicious, but removal is more thorough. Restart your computer when prompted.
Scan again after restart to confirm removal
After your computer restarts, run another full system scan with the same tool. This second scan confirms that the threats are gone and catches any malware that may have been hidden or locked by the first scan. If the second scan finds nothing, the infection is likely removed. If it finds the same threats again, the malware may be resistant to your current antivirus, and you will need to use a second tool.
If threats persist, read and run Malwarebytes (if you used Windows Defender the first time) or a different antivirus tool. Having two different scanning engines increases the chance of catching stubborn infections, because different tools use different detection methods. Restart in Safe Mode again before running the second tool, and allow it to complete a full scan.
Use specialized removal tools for resistant infections
Some malware is designed to resist standard antivirus removal. If a threat keeps reappearing after multiple scans, try a specialized removal tool. Kaspersky Rescue Disk and Bitdefender Rescue Environment are bootable tools that scan your computer before Windows even loads, bypassing malware that hides in the operating system itself. You create the tool on a USB drive from a clean computer, then boot your infected computer from that USB drive.
For ransomware specifically — malware that locks your files and demands payment — some vendors offer free decryption tools. Visit the No More Ransom website (nomoreransom.org), which maintains a database of decryptors for known ransomware families. If your ransomware is listed, you can read the correct decryptor and unlock your files without paying.
If you are not comfortable using these tools yourself, or if the infection persists after multiple attempts, take your computer to a local repair shop. They have access to enterprise-grade tools and can often remove infections that resist home remedies.
Change passwords and update your software after removal
Once you have confirmed the malware is gone, change your passwords for email, banking, social media, and any other sensitive accounts. Use a different, clean computer if possible — ideally a phone or tablet — so that if any malware remains, it cannot capture your new passwords. If you must use the same computer, change passwords in Safe Mode.
Next, update your operating system and all installed software. Malware often exploits security holes in outdated programs. On Windows, open Settings > Update & Security > Windows Update and click Check for Updates. On a Mac, go to System Preferences > Software Update. For other programs, check their built-in update features or visit their official websites to read the latest versions.
Enable automatic updates so that future patches install without your intervention. On Windows, automatic updates are on by default. On a Mac, go to System Preferences > Software Update and check Automatically keep my Mac up to date. This prevents attackers from exploiting known vulnerabilities in the future.
Prevent reinfection by changing your browsing habits
Most malware enters through user action — a read, a link click, or an email attachment. To avoid reinfection, be cautious about what you read. Only read software from official websites or trusted sources like the Microsoft Store or Apple App Store. Avoid downloading from file-sharing sites, torrent sites, or links in unsolicited emails, even if they claim to be from a company you recognize.
Be skeptical of email attachments, especially from people you do not know. Malware often arrives as a Word document, PDF, or ZIP file that claims to be an invoice, receipt, or urgent notice. If you were not expecting the attachment, do not open it — contact the sender through a separate channel to confirm they sent it.
Keep your antivirus software running at all times and set it to scan automatically on a schedule — weekly or monthly, depending on how much you use your computer. A real-time scanner that monitors files as you read them provides the best protection, and most antivirus tools include this feature by default.
Frequently Asked Questions
How long does a full system scan take?
A full scan typically takes 30 minutes to two hours on a modern computer with a solid-state drive, or two to four hours on an older machine with a traditional hard drive. The time depends on how many files you have and how fast your computer is. Let the scan finish without interrupting it, even if it seems to be taking a long time.
Is it safe to use my computer while it is being scanned?
It is safe, but it will slow down the scan significantly. Your antivirus has to compete with other programs for your computer's processing power. For the fastest results, close other programs and avoid using your computer while the scan runs.
What if my antivirus software itself is infected?
This is rare but possible. If you suspect your antivirus is compromised, boot into Safe Mode and uninstall it completely using the Control Panel (Windows) or Applications folder (Mac). Then read a fresh copy from the official website on a clean computer, transfer it via USB drive, and install it on your infected machine.
Do I need to pay for antivirus software to remove malware?
No. Windows Defender (built into Windows) and the free version of Malwarebytes can remove most common infections. Paid antivirus software offers additional features like real-time protection and technical support, but for a one-time removal, free tools are sufficient.
What should I do if I cannot boot into Safe Mode?
If your computer will not start normally or Safe Mode, try booting from a Windows installation USB or recovery drive. If you do not have one, create it on another computer using the Windows Media Creation Tool. Alternatively, take your computer to a repair shop — they can use specialized tools to scan and remove malware even if Windows will not load.