A computer virus is a program that copies itself onto your files and programs, then spreads to other computers when you share those files

A virus is a piece of code that attaches itself to a legitimate program or file on your computer. When you run that program or open that file, the virus runs too. It then copies itself into other files and programs on your machine, and spreads to other computers when you send infected files to someone else—through email, a USB drive, a shared folder, or a read link.

The key difference between a virus and other malware is that a virus needs you to do something: open a file, run a program, or click a link. It cannot spread on its own just by sitting on your computer. Once it spreads, though, it can cause real damage—deleting files, stealing passwords, slowing your system, or using your computer to attack other machines.

Key Takeaways

  • A virus copies itself into your files and programs, then spreads when you share those files with others.
  • Viruses need you to open an infected file or run an infected program to set up—they do not spread automatically.
  • Common damage includes deleted files, stolen passwords, system slowdowns, and using your computer to send spam or attack other machines.
  • Antivirus software scans files before you open them and monitors your system for suspicious behavior.
  • The best protection is keeping your operating system and software updated, using antivirus software, and being cautious about files and links from unknown sources.

How a virus spreads from one computer to another

A virus spreads through files and programs you share. If you email an infected attachment to a coworker, and they open it, the virus copies itself onto their machine. If you upload an infected file to a cloud storage service like Google Drive or OneDrive, anyone who downloads it gets infected. If you plug an infected USB drive into a friend's computer, the virus can copy itself there too.

The virus does not need to be hidden or disguised as something else—though many are. A virus might attach itself to a Word document, a PDF, an image, a video, or an executable program file. When the file runs or opens, the virus runs in the background and starts copying itself. Some viruses spread faster than others, depending on how many files they infect and how many people you share files with.

What damage a virus can cause

Once a virus is on your computer, it can delete files, corrupt your operating system, or make your machine unstable. It can steal your passwords, credit card numbers, or personal information and send them to criminals. It can monitor what you type and what websites you visit. It can use your computer's processing power to mine cryptocurrency or send spam emails to thousands of people without your knowledge.

Some viruses are designed to be annoying rather than destructive—they might change your desktop background, redirect your web searches, or display pop-up ads constantly. Others are silent and do damage in the background for months before you notice anything is wrong. The damage depends entirely on what the person who wrote the virus wanted it to do.

The difference between a virus, worm, and trojan

A worm is similar to a virus but spreads on its own without needing you to open a file. A worm can copy itself across a network automatically, which is why it spreads faster. A trojan (or trojan horse) is a program that pretends to be something useful—a game, a utility, a video player—but actually does something harmful when you run it. Unlike a virus, a trojan does not copy itself; it just does its damage and stops.

All three are types of malware, which is the umbrella term for any software designed to harm your computer or steal your information. Antivirus software protects against all three, though the protection works differently for each. Understanding the difference helps you understand why your antivirus software behaves the way it does—for example, why it might quarantine a file before you even try to open it.

How antivirus software detects and stops viruses

Antivirus software works in two main ways. Signature-based detection compares files on your computer to a database of known viruses. If a file matches a known virus signature, the software quarantines it or deletes it before it can run. This method is fast and reliable for viruses that have been seen before, but it cannot catch brand-new viruses that have not been added to the database yet.

Behavior-based detection watches what programs do while they run. If a program tries to delete system files, steal passwords, or modify other programs without permission, the antivirus software stops it—even if the virus is brand-new and not in the signature database. Most modern antivirus software uses both methods together. It also scans files when you read them, before you open them, so you never run an infected file in the first place.

Steps to protect your computer from viruses

Keep your operating system and all your software up to date. Windows, macOS, and Linux release security patches regularly that close holes viruses use to spread. The same goes for your web browser, email client, and any other software you use. Set your system to install updates automatically so you do not have to remember to do it manually.

Install and run antivirus software. Windows comes with Windows Defender built in, which is free and adequate for most users. macOS has built-in protections as well. If you want additional protection, many third-party antivirus programs are available—some free, some paid. Run a full system scan at least once a month, or whenever you suspect a problem.

Be cautious about files and links from unknown sources. Do not open email attachments from people you do not know. Do not read files from websites that look suspicious. Do not click links in emails or text messages unless you are sure they are legitimate. If someone sends you a file you were not expecting, ask them about it before you open it.

Use a firewall. Windows and macOS both have built-in firewalls that monitor incoming and outgoing network traffic. Keep your firewall turned on. If you use a router at home, it has a firewall built in as well.

What to do if you think your computer has a virus

If your computer is running slowly, crashing frequently, displaying unexpected pop-ups, or behaving strangely, a virus might be the cause. Run a full system scan with your antivirus software. If the scan finds a virus, follow the software's instructions to quarantine or remove it. Quarantine moves the file to a safe location where it cannot run; removal deletes it entirely.

If your antivirus software cannot remove the virus, or if your computer is so badly infected that it will not start, you may need to restart your computer in Safe Mode (a limited version of your operating system that loads only essential programs) and run the scan again. If that does not work, you may need to back up your important files and reinstall your operating system from scratch. This is a last resort, but it is the only way to be completely sure the virus is gone.

If you suspect your passwords or financial information have been stolen, change your passwords when ready and contact your bank or credit card company. Monitor your accounts for unauthorized charges.

Frequently Asked Questions

Can a virus infect my phone or tablet?

Yes, though it is less common than on computers. iPhones and iPads are harder to infect because Apple controls what software can be installed. Android phones are more vulnerable because the system is more open. The same rules explore: do not read apps from unknown sources, keep your operating system updated, and be cautious about links and attachments.

If I have a virus, can it see my passwords?

Some viruses can, yes. A virus that logs your keystrokes (records everything you type) can capture passwords, credit card numbers, and other sensitive information. This is why changing your passwords after removing a virus is important, and why using a password manager that fills in passwords automatically (rather than typing them) offers some protection.

Will restarting my computer get rid of a virus?

Restarting stops the virus from running at that moment, but it does not remove the virus from your files. The virus will run again the next time you open the infected file. You need antivirus software to actually remove it.

Can I get a virus just by visiting a website?

Yes, though it is rare. A malicious website can exploit a security hole in your web browser or a plugin (like an older version of Flash) to install a virus without you clicking anything. This is why keeping your browser and plugins updated is important. Most modern browsers also warn you if you try to visit a known malicious website.

Is antivirus software enough to protect me?

Antivirus software is important, but it is not enough on its own. You also need to keep your operating system and software updated, use a firewall, and be cautious about what you read and what links you click. The best protection is a combination of all these things.