Signs that suggest your computer may have been compromised

A hacked computer usually shows one or more obvious signs: your mouse moves on its own, programs open without you clicking them, your browser homepage changed without your action, or your antivirus software is disabled. You might see unfamiliar programs in your installed software list, notice your computer running much slower than normal, or find that websites look wrong or redirect to different pages. Some infections cause your keyboard to stop responding or your screen to display warnings and pop-ups you cannot close.

Less obvious signs include a spike in your internet data usage (visible in your router or monthly bill), your friends reporting that they received emails from your address that you did not send, or your login passwords no longer working even though you are certain you typed them correctly. Your computer might also restart on its own, freeze frequently, or make unusual noises from the hard drive or fan running constantly.

Key Takeaways

  • Visible signs of compromise include a mouse that moves by itself, programs opening without your input, a changed browser homepage, or disabled antivirus software.
  • Check your installed programs list, browser extensions, and startup folder for unfamiliar software that you did not install.
  • Run a full scan with your antivirus software or a dedicated malware scanner like Malwarebytes to detect infections that may not show obvious symptoms.
  • Change all your passwords from a different device after confirming your computer is clean, because malware often captures keystrokes.
  • If your antivirus is disabled or will not run, restart your computer in Safe Mode with Networking before attempting a scan.

Check your installed programs and browser extensions

Open your Control Panel (Windows) or System Preferences (Mac) and look at your list of installed programs. Write down anything you do not recognize or do not remember installing. Malware often hides under names that sound legitimate—like "System Update" or "Security Tool"—so search the program name online if you are unsure. Uninstall anything suspicious, but do not delete it yet; keep a note of the names in case you need them later.

Next, check your browser extensions. In Chrome, click the puzzle-piece icon in the top right, then click the three dots next to any extension and select "Remove." In Firefox, click the menu button (three horizontal lines), select "Add-ons and themes," then "Extensions," and remove anything unfamiliar. In Edge, click the three-dot menu, select "Extensions," and remove suspicious ones. Malware often installs extensions that redirect your searches or inject ads into websites.

Run a full antivirus and malware scan

If your antivirus software is still running, open it and select the option for a "Full Scan" or "Deep Scan." This will take 30 minutes to several hours depending on your hard drive size. Let it finish completely and quarantine (isolate) anything it finds. If your antivirus is disabled or will not open, restart your computer in Safe Mode with Networking: on Windows, hold Shift while clicking the restart button, then select "Troubleshoot" > "Advanced options" > "Startup Settings" > "Safe Mode with Networking." On Mac, restart and hold Command+S, then type `fsck -fy` and press Enter.

If your built-in antivirus (Windows Defender or Mac's built-in protection) is not catching anything but you still suspect infection, read Malwarebytes on a USB drive from a different computer and run it on the suspected machine. Malwarebytes is designed to catch infections that standard antivirus software misses. After the scan completes, restart your computer normally and run the scan again to confirm nothing remains.

Check your browser homepage and search engine settings

Open your browser and look at the homepage that loads when you start it. If it is not the page you set, your browser has been hijacked. In Chrome, click the three-dot menu, select "Settings," then "On startup," and make sure "Open the New Tab page" is selected. Check the "Home" section and set it to your preferred page. In Firefox, click the menu button, select "Settings," then "Home," and set your homepage. In Edge, click the three-dot menu, select "Settings," then "Startup," and choose your homepage.

Also check your search engine. In Chrome, click the three-dot menu, select "Settings," then "Search engine," and make sure Google (or your preferred engine) is selected. In Firefox, click the menu button, select "Settings," then "Search," and verify your search engine. Malware often changes these settings to redirect your searches through sites that collect your data or display unwanted ads.

Look at your startup folder and running processes

On Windows, press Windows key + R, type `msconfig`, and press Enter. Click the "Startup" tab and look for programs you do not recognize. Uncheck anything suspicious (do not delete it). On Mac, go to System Preferences > General > Login Items and remove any programs you did not add. These are programs that run automatically when your computer starts, and malware often hides here.

For a more detailed view, open Task Manager on Windows (Ctrl+Shift+Esc) and look at the "Processes" tab. Malware sometimes runs under names that mimic legitimate Windows processes—for example, "svchost.exe" is real, but "svchosts.exe" (with an extra 's') is not. Search any unfamiliar process name online to verify it is legitimate. On Mac, open Activity Monitor (Applications > Utilities > Activity Monitor) and look for unfamiliar processes in the CPU or Memory tabs.

Change all your passwords from a clean device

Once you have confirmed your computer is clean, do not change your passwords on that computer yet. Instead, use a phone, tablet, or different computer to change every password you use: email, banking, social media, work accounts, and any other important login. Malware often includes keyloggers that record everything you type, so passwords changed on an infected computer are still compromised.

When you change passwords, use a password manager like Bitwarden or 1Password to generate strong, unique passwords for each account. If you do not have a password manager, write passwords down on paper temporarily and type them into your computer only after you are confident it is clean. After changing passwords, enable two-factor authentication on any account that offers it—this adds a second layer of protection even if a password is stolen.

Know when to seek professional help

If your antivirus software will not run even in Safe Mode, your keyboard or mouse does not respond, or your computer will not start at all, the infection is severe enough that you should take it to a repair technician. Do not attempt to fix it yourself, because some malware is designed to prevent removal and can spread to other devices on your network if you keep using it.

Similarly, if you notice that your bank account or credit card has unauthorized charges, or if your email has been used to send messages you did not write, contact your bank and email provider when ready in addition to cleaning your computer. They can help you find your accounts and monitor for further fraud. A technician can also help if you are unsure whether your computer is truly clean after running scans.

Frequently Asked Questions

Can a hacked computer infect other devices on my network?

Yes, some malware spreads to phones, tablets, and other computers connected to your Wi-Fi. After you clean your computer, change your Wi-Fi password from your router (usually by typing your router's IP address into a browser). This forces all devices to reconnect and prevents malware from spreading further. If you have other devices, run a scan on them as well.

What if I think my email account was hacked, not my computer?

Check your email's login history and connected devices. In Gmail, scroll to the bottom of your inbox and click "Details" next to "Last account activity." In Outlook, go to Security > Recent activity. If you see logins from places you do not recognize, change your password when ready and remove unknown devices. However, if your computer is also showing signs of infection, clean it first—otherwise a keylogger will capture your new password.

Is it safe to use my computer while it is infected?

No. Avoid logging into banking, email, or other sensitive accounts on an infected computer, because malware can capture your passwords and personal information. If you must use it, use your phone or a different computer for anything involving money or sensitive data. The longer you use an infected computer, the more information malware can steal.

Do I need to replace my hard drive if it was hacked?

Not usually. A full scan and removal of malware is enough for most infections. However, if a technician tells you that your hard drive has physical damage, or if malware has encrypted your files and demands payment (ransomware), you may need to replace the drive or restore from a backup. For routine malware, cleaning is sufficient.

How can I prevent my computer from being hacked in the future?

Keep your operating system and all software updated, because updates patch security holes that malware exploits. Use strong, unique passwords for every account. Do not open email attachments or click links from senders you do not recognize. Avoid downloading software from websites other than the official source. Run regular antivirus scans and keep your antivirus definitions updated. Consider using a password manager to generate and store complex passwords.