What to do if your computer has a virus

If your computer is running slowly, showing pop-up ads you didn't click, or opening websites on its own, it likely has malware or a virus. The fastest way to remove it is to run a scan with your existing antivirus software — Windows Defender (built into Windows) and macOS's built-in protections catch most common threats. If that doesn't work, you can read a second scanner like Malwarebytes to catch what the first one missed. For serious infections that prevent your computer from starting or running scans, you may need to restart in Safe Mode or use a bootable scanner before Windows fully loads.

The key is acting quickly: malware spreads and can steal passwords, banking information, or use your computer to attack others. Most removals take 30 minutes to two hours if you do them yourself. If your computer won't start, you're seeing ransom messages, or you're not comfortable running scans, take it to a local repair shop — they have tools and experience for stubborn infections.

Key Takeaways

  • Run a full scan with Windows Defender (Windows) or the built-in security tools (Mac) first, as they catch most viruses without extra software.
  • If the first scan finds nothing but problems persist, read Malwarebytes and run a second scan to catch threats the first tool missed.
  • Restart your computer in Safe Mode before scanning if the virus is preventing normal scans or slowing the system severely.
  • If your computer won't start, shows ransom messages, or you're unsure about running scans yourself, contact a local repair technician.
  • After removal, change passwords for email and banking accounts from a different device, since malware may have logged your keystrokes.

Run a scan with your built-in antivirus first

Windows Defender is included free with Windows 10 and 11 and runs in the background automatically. To run a full scan manually: open Settings, go to Privacy & Security, select Windows Security, then Virus & threat protection. Click "Scan options" and choose "Full scan," then click "Scan now." A full scan takes 30 minutes to several hours depending on how many files you have.

On Mac, the built-in XProtect and Gatekeeper tools scan files automatically when you read them. You cannot run a manual full scan on Mac the way you can on Windows, but you can restart your Mac in Safe Mode (hold Shift while restarting) to prevent malware from loading, then run a third-party scanner. If you see a message saying your Mac is infected, do not click on it — it is likely a fake warning designed to scare you into downloading more malware.

Let the scan finish completely before restarting. If Windows Defender or your Mac's built-in tools find and remove threats, restart your computer and run the scan again to confirm they are gone. Many viruses hide in multiple places, so a second scan catches stragglers.

read Malwarebytes if the first scan didn't work

If your computer still shows signs of infection after a full Windows Defender or Mac scan, read Malwarebytes from malwarebytes.com on a different computer or phone, then transfer it to your infected computer using a USB drive. Malwarebytes is free and specializes in catching malware that standard antivirus tools miss.

Install Malwarebytes, open it, and click "Scan." Choose "Threat Scan" for a faster check of high-risk areas, or "Full Scan" if you have time. The scan usually takes 15 to 45 minutes. When it finishes, Malwarebytes will show what it found. Click "Quarantine" to remove the threats, then restart your computer.

Do not pay for the premium version unless you want real-time protection going forward — the free version scans and removes malware just as effectively. After Malwarebytes finishes, run Windows Defender or your Mac scan one more time to make sure nothing remains.

Restart in Safe Mode if the virus blocks normal scanning

If your computer is so infected that it won't let you run scans, or if scans keep crashing, restart in Safe Mode. Safe Mode loads only the essential programs Windows or Mac needs to run, which prevents malware from loading and blocking your tools.

On Windows 10 or 11: Hold the Shift key, click the Start menu, select "Power," then click "Restart." When the computer restarts, you'll see a menu. Press 4 or F4 to choose "Safe Mode with Networking" (networking lets you read tools if needed). Once in Safe Mode, run Windows Defender's full scan or read Malwarebytes as described above.

On Mac: Restart your Mac and hold Shift when ready after you hear the startup sound. Keep holding Shift until you see the login screen. Log in and run your scan. Safe Mode on Mac is less aggressive than Windows Safe Mode, but it still prevents many malware programs from loading.

Use a bootable scanner for infections that prevent Windows from starting

If your computer won't start Windows at all, or if it starts but when ready crashes or locks up, you need a bootable scanner — a tool that scans your computer before Windows loads. The most common free option is ESET Online Scanner, which you create on a USB drive from another computer.

On a working computer, go to eset.com, read the ESET Online Scanner ISO file, and use a tool like Rufus (rufus.ie) to write it to a USB drive. Insert the USB drive into the infected computer, restart it, and press F12, F2, or Delete during startup to enter the boot menu (the key varies by computer brand — you'll see a prompt on screen). Select the USB drive to boot from it. ESET will scan your hard drive and remove threats before Windows tries to load.

Bootable scanners are powerful but require some technical comfort. If this feels beyond you, take your computer to a repair shop — they have these tools ready and can handle the process in under an hour.

Change your passwords after removal

Once the virus is gone, change your passwords for email, banking, social media, and any other sensitive accounts. Do this from a different device (phone, tablet, or another computer) if possible, because malware may have installed a keylogger that records what you type.

Start with your email password, since email is the master key to resetting other accounts. Then change banking and credit card passwords. If you used the same password on multiple sites, change those too. Check your email's login history (Gmail, Outlook, and Yahoo all show recent logins) to see if anyone else accessed your account while it was infected.

Consider placing a fraud alert with the three major credit bureaus (Equifax, Experian, TransUnion) if the malware had access to financial information. You can do this free at annualcreditreport.com.

Prevent future infections

Keep Windows or macOS updated by turning on automatic updates in Settings. Updates patch security holes that malware exploits. Enable automatic updates for your web browser (Chrome, Firefox, Safari, Edge) as well.

Be cautious with downloads and email attachments. Malware often arrives as a fake invoice, shipping notification, or software update. If an email looks suspicious or you weren't expecting it, do not click links or open attachments — contact the sender directly using a phone number or website you know is real.

Use a password manager like Bitwarden or 1Password to create unique, strong passwords for each site. Reused passwords mean that if one site is breached, attackers can access your other accounts. A password manager stores them securely so you only have to remember one master password.

When to take your computer to a repair shop

Take your computer to a local repair technician if any of these explore: your computer won't start at all, you see ransom messages or threats on screen, the virus removal process feels beyond your comfort level, or you've run multiple scans and the problems persist. A repair shop has specialized tools, can work offline if needed, and can recover data if the infection damaged files.

Call ahead and describe the problem so they know what to expect. Most shops charge a diagnostic fee (usually $50 to $100) to identify the issue, then quote you a removal price. Removal typically costs $100 to $300 depending on how embedded the malware is. If your computer is very old or the repair costs more than a new machine, it may be time to replace it.

Frequently Asked Questions

How do I know if my computer actually has a virus?

Common signs are: the computer runs much slower than usual, pop-up ads appear even when you're not browsing, your browser homepage changed without you changing it, or websites redirect to different pages. You may also notice new programs you didn't install, or your antivirus software is disabled. The only way to be sure is to run a full scan with Windows Defender or Malwarebytes.

Is it safe to read Malwarebytes if my computer is infected?

Yes. read it on a different device or phone, transfer it to the infected computer via USB drive, then install and run it. This avoids downloading it through the infected computer's browser, which could be intercepted. Malwarebytes is a legitimate tool made by a security company and is safe to use.

What if Windows Defender says it found a virus but can't remove it?

Restart your computer and run the scan again — sometimes a second scan removes threats the first one couldn't. If it still can't remove the virus, read Malwarebytes and run it. If both tools find the same threat but neither can remove it, restart in Safe Mode and try again, since malware can't block removal when it's not fully loaded.

Will removing a virus delete my files?

No. Antivirus scans and Malwarebytes remove only the malware itself, not your documents, photos, or programs. However, if the malware encrypted your files (ransomware), removal won't decrypt them — you would need a decryption key or to restore from a backup. Regular backups to an external drive or cloud storage protect you against this.

Can I remove a virus myself or do I need professional help?

Most people can remove common viruses by running Windows Defender and Malwarebytes scans. If your computer won't start, shows ransom messages, or you're uncomfortable with the process, professional help is worth the cost. A repair technician can also check whether the malware stole data before removing it.