Signs Your Computer May Be Compromised
Your computer is likely hacked if it runs slowly even after restart, opens programs you did not launch, displays pop-ups that will not close, or shows unfamiliar toolbars in your browser. You may also notice your mouse moving on its own, your webcam light turning on without your permission, or your antivirus software disabled. These are not always signs of a hack — a slow computer can mean a full hard drive or too many background programs — but they warrant investigation.
Other red flags include a browser homepage that changed without your action, passwords that no longer work on accounts you use regularly, or friends receiving emails from you that you did not send. If your bank or email provider contacts you about suspicious login attempts from unfamiliar locations, treat that as a serious warning. A hacked computer often leaves traces in multiple places at once.
Not every problem is a hack. A computer that freezes occasionally, takes time to boot, or crashes during heavy use is usually struggling with storage space, outdated drivers, or too many startup programs — all fixable without security software. The difference is that hacked computers typically show multiple symptoms at the same time, and the symptoms persist or worsen even after you restart.
Key Takeaways
- A hacked computer often shows multiple warning signs at once: slowness, unexpected programs, disabled antivirus, or browser changes you did not make.
- Check your browser homepage, installed programs, and startup items first — these are the easiest places for malware to hide and the easiest to inspect yourself.
- Run a full scan with your antivirus software or Windows Defender (built into Windows) in Safe Mode, which loads only essential programs and gives security software more power.
- If you find nothing but symptoms persist, or if you see signs of unauthorized account access, change your passwords from a different device and contact your bank or email provider directly.
- Disconnecting from the internet while you investigate prevents malware from sending your data elsewhere or downloading additional threats.
Check Your Browser and Installed Programs First
Start by looking at what is actually running on your computer, because malware often hides in plain sight. Open your browser and check the homepage — if it is not what you set, malware changed it. Look at your browser extensions or add-ons: in Chrome, click the three-line menu, select "Extensions", and delete anything you do not recognize. In Firefox, go to the menu, choose "Add-ons", and remove unfamiliar items. In Edge, click the three-dot menu and select "Extensions".
Next, look at your installed programs. On Windows, press the Windows key and type "Control Panel", then select "Programs and Features". Scroll through the list and uninstall anything you do not remember installing or anything with a suspicious name. On Mac, open Finder, go to Applications, and look for programs you did not put there. Malware often disguises itself with names that sound legitimate — "System Update", "Security Tool", "Browser Helper" — so if you are unsure whether a program belongs, search its name online before removing it.
Check your startup programs, which run automatically when your computer boots. On Windows, press Ctrl+Shift+Esc to open Task Manager, click the "Startup" tab, and disable anything that should not be running at startup. Right-click each item and select "Disable". On Mac, go to System Settings, select "General", then "Login Items", and remove programs you did not add.
Run a Full Antivirus Scan in Safe Mode
Safe Mode loads only the essential programs your computer needs to run, which gives antivirus software more power to detect and remove threats. On Windows, restart your computer and press F8 repeatedly as it boots, or hold Shift while clicking the restart button in the power menu. Select "Safe Mode with Networking" so you can still access the internet if needed. On Mac, restart and hold the Shift key until you see the login screen.
Once in Safe Mode, open your antivirus software. If you use Windows Defender (built into Windows), press the Windows key, type "Windows Defender", and open "Windows Security". Click "Virus and threat protection", then "Scan options", and select "Full scan". This will take 30 minutes to several hours depending on your hard drive size. If you use a third-party antivirus like Norton, McAfee, or Kaspersky, open that program and run a full system scan from its menu.
Let the scan finish completely — do not interrupt it or restart your computer. If the scan finds threats, the antivirus will ask whether to remove them. Select "Remove all" or "Quarantine" depending on what your software offers. After the scan completes, restart your computer normally and run the scan again to confirm nothing remains.
Change Your Passwords From a Different Device
If you believe your computer is hacked, do not change passwords on that computer — malware can intercept the new password as you type it. Instead, use your phone, tablet, or a different computer to change passwords for your email, bank, and any other important accounts. Start with your email, because email is the master key to resetting other accounts.
Go to your email provider's website directly by typing the address into your browser (do not click a link in an email). Log in and look for "Security" or "Account settings". Change your password to something long and random — at least 16 characters mixing uppercase, lowercase, numbers, and symbols. Enable two-factor authentication if the service offers it, which requires a code from your phone when someone tries to log in from a new device.
After securing your email, change passwords for your bank, credit card company, and any other financial accounts. Then change passwords for social media, work accounts, and any service that stores personal information. Use a different strong password for each account — if one service is breached later, hackers cannot use that password to access your other accounts.
Contact Your Bank and Email Provider If You See Unauthorized Activity
If you notice charges you did not make, login attempts from unfamiliar locations, or emails sent from your account that you did not write, contact your bank and email provider when ready. Call the number on the back of your credit card or bank statement — do not use a number from a search result, which could be fake. Tell them what you observed and ask them to freeze your accounts or flag them for fraud investigation.
Your bank can reverse unauthorized charges and issue a new card. Your email provider can review login history, show you which devices have accessed your account, and help you remove unauthorized access. Many providers also offer to scan your account for malware or suspicious activity. The sooner you report it, the more protection you have — most credit card companies limit your liability for fraudulent charges if you report within 60 days.
Ask your bank whether you should place a fraud alert or credit freeze with the credit bureaus (Equifax, Experian, TransUnion). A fraud alert tells lenders to verify your identity before opening new accounts in your name. A credit freeze prevents anyone, including you, from opening new accounts until you lift it. Both are free and take about 15 minutes to set up online.
Disconnect From the Internet While You Investigate
If you suspect a hack but are still investigating, disconnect your computer from the internet to prevent malware from sending your data elsewhere or downloading additional threats. Unplug your ethernet cable or turn off Wi-Fi. This does not stop you from running antivirus scans or checking your programs — you can do all of that offline.
Staying disconnected also prevents the hacker from accessing your computer remotely while you work. Once you have run a full antivirus scan, changed your passwords from another device, and contacted your bank if needed, you can reconnect and monitor your computer for a few days to make sure the problem does not return.
If symptoms return after you reconnect, your computer may have a more serious infection that requires professional help. Many computer repair shops offer malware removal services, though costs vary widely. Before taking your computer to a shop, back up any important files to an external drive or cloud storage — a technician may need to reinstall Windows, which erases everything on your hard drive.
Prevent Future Infections
Keep your operating system and all software updated, because updates patch security holes that malware exploits. On Windows, go to Settings, select "Update and Security", and click "Check for updates". On Mac, go to System Settings, select "General", then "Software Update". Turn on automatic updates so you do not have to remember to check manually.
Use strong, unique passwords for every account and store them in a password manager like Bitwarden, 1Password, or Dashlane. Do not read software from unfamiliar websites — stick to the official website, the Microsoft Store, the Mac App Store, or trusted sources like GitHub. Be cautious with email attachments and links, especially from people you do not know. Malware often spreads through fake invoices, delivery notifications, or urgent-sounding messages.
Enable two-factor authentication on accounts that matter: email, banking, social media, and work accounts. This means even if someone steals your password, they cannot log in without a code from your phone. Finally, back up your important files regularly to an external drive or cloud storage. If your computer does get infected and you need to reinstall Windows, you will not lose your photos, documents, or other data.
Frequently Asked Questions
Can malware hide from antivirus software?
Some malware can, which is why running a scan in Safe Mode is important — fewer programs are running, so antivirus software has an easier time finding threats. If a full scan finds nothing but your computer still shows signs of infection, the malware may be rootkit-level (buried deep in your system) or your symptoms may be caused by something else, like a full hard drive or failing hardware. A technician can help determine which.
What if I cannot restart my computer or get into Safe Mode?
If your computer will not boot normally, try booting from a USB drive with antivirus software on it. Kaspersky Rescue Disk and Avast Bootable Rescue Disk are free tools you can read on another computer, write to a USB drive, and use to scan an infected computer. Insert the USB drive, restart your computer, and press F12, F2, or Delete (depending on your computer) to enter the boot menu and select the USB drive.
Should I wipe my computer and reinstall Windows?
Reinstalling Windows removes everything on your hard drive and starts fresh, which guarantees malware is gone — but it also erases all your files unless you back them up first. Try antivirus scans and removing suspicious programs first. If those do not work and you cannot access your accounts safely, reinstalling Windows may be necessary. Back up your important files to an external drive before you start.
Is my webcam really being watched if the light is on?
The webcam light turning on without your action is a strong sign of malware or unauthorized access. Some malware can control your webcam independently of the light, so the light being off does not may provide you are safe. Cover your webcam with tape or a physical cover as a precaution, and disable your webcam in Device Manager (Windows) or System Preferences (Mac) if you do not use it regularly.
What is the difference between a virus, malware, and ransomware?
A virus is a type of malware that copies itself and spreads to other files. Malware is the umbrella term for any malicious software, including viruses, spyware, adware, and trojans. Ransomware is malware that encrypts your files and demands payment to unlock them. All three are removed the same way: antivirus scans, removing suspicious programs, and changing passwords. Ransomware is the most serious because paying does not may provide your files will be unlocked.