Malware rarely announces itself anymore. Older viruses deleted files or splashed taunting messages across the screen, but most modern infections make money by staying hidden: they steal passwords, mine cryptocurrency, send spam, or wait quietly for the right moment to encrypt your files. That changes what the warning signs look like. Instead of one dramatic event, you usually get a pattern of small oddities that are easy to explain away one at a time.
The word virus has become everyday shorthand for all of this, so that is how this guide uses it. Strictly speaking, a virus is only one type of malware, alongside trojans, spyware, adware, and ransomware, and the signs below apply to the whole family. Our guide to malware types explains the differences if you want the full picture.
Keep one rule in mind as you read: a single symptom proves very little. Computers slow down as they age, disks fill up, and browsers struggle under too many open tabs. What deserves your suspicion is a sudden change, or several of these signs arriving together in the same week.
Your computer is suddenly, dramatically slower
A gradual slowdown over months or years is normal wear. What malware tends to cause is a step change: the machine was fine last week, and now it takes ages to start, freezes on simple tasks, or runs its fan at full speed while you are not doing anything. Cryptomining malware is a common culprit here, because it deliberately works your processor as hard as it can, all day, whether you are at the keyboard or not. A laptop that suddenly runs hot on your lap, drains its battery in a fraction of the usual time, or sounds like it is taking off while sitting idle is telling you something is working hard in the background.
You can see what that something is. On Windows, press Ctrl+Shift+Esc to open Task Manager, click the CPU column to sort by usage, then leave the computer alone for a minute. On a Mac, open Activity Monitor from the Utilities folder inside Applications. An idle computer should be mostly quiet. If a process you do not recognize, especially one with a random-looking name, stays pinned at the top of the list while you do nothing, write its name down and treat it as a lead worth scanning for.
Pop-ups and a browser that will not behave
The browser is where infections show themselves most often, because adware and browser hijackers are built to push ads and fake pages in front of you.
- Pop-ups outside the browser: ads or warnings that appear on your desktop when no browser window is open are a classic adware sign.
- A changed homepage or search engine: you open a new tab and land on a search page you never chose, and changing it back does not stick.
- Extensions or toolbars you never installed: open your browser's extensions or add-ons page and read the list. Anything you cannot account for should go.
- Constant redirects: you click an ordinary link and end up somewhere unrelated, often a sweepstakes page or a fake security alert.
- Fake virus warnings: a page that flashes red, plays an alarm sound, and tells you to call a support number is a scam every single time. Real security software does not ask you to call anyone.
One caveat: a stream of small notification bubbles in the corner of your screen is usually not malware at all, but a website you accidentally allowed to send notifications. You can revoke that permission in your browser's settings under notifications or site permissions, no antivirus required.
Programs and settings change on their own
Malware protects itself. Many infections switch off the very tools you would use to find them, so settings that change themselves back are a serious sign, not a quirk.
- Your antivirus turns itself off, refuses to update, or reports that its protection is managed by an organization on a personal computer.
- Task Manager or your security settings will not open, or close instantly every time you try.
- Unfamiliar programs appear in your installed apps list, on your desktop, or in the list of programs that start with the computer.
- Files go missing or change: documents renamed with a strange extension, folders that no longer open, or a text file appearing in every folder demanding payment. That last one is ransomware, and if you see it, disconnect the computer from the internet immediately and stop using it until it is cleaned.
Your accounts show activity you did not cause
Some of the strongest evidence of an infection never appears on the infected machine. Info-stealing malware grabs the passwords saved in your browser and ships them to the attacker, and the first visible sign is often an account misbehaving.
- Friends ask about strange messages or links you never sent.
- Your sent folder contains emails you did not write.
- Password reset emails arrive for accounts you were not touching.
- Login alerts mention devices or locations that are not yours.
If this is happening, assume every password saved on that computer is compromised. Change the important ones, email and banking first, from a different, clean device such as your phone. A quick email breach check is also worth running, because leaked credentials from an old data breach can cause identical symptoms without any infection on your machine at all.
Network activity when nothing should be happening
Malware needs to talk to the outside world, whether it is uploading your data, downloading more malware, or sending spam from your machine. That traffic leaves traces. Your internet may feel slower because the connection is busy in the background, and if you have a data cap, you may burn through it faster than usual.
On Windows you can see which programs are using your connection: open Settings, choose Network and internet, then look for Data usage. The list shows how much data each app has used recently. Your browser, video apps, and system updates belong near the top. A program you have never heard of quietly moving large amounts of data does not.
Signs that usually mean something else
Not every glitch is an attack, and knowing what is normal saves you from chasing ghosts. These symptoms usually have boring explanations:
- A slow, steady decline over years: aging hardware and a nearly full drive, not malware. Freeing up storage often helps more than any scan.
- Fans roaring during updates or backups: scheduled maintenance works the machine hard by design, usually at night or right after startup.
- Lots of ads on websites: the modern web is simply heavy with ads. It only points to adware when ads appear on pages that never had them, or outside the browser entirely.
- A single crash or freeze: every computer has bad days. Patterns matter, not one-off events.
How to check for sure
Symptoms can only take you so far. The way to settle the question is a full scan with software you trust, and you probably already have it.
On Windows, the built-in protection is genuinely capable. Open the Windows Security app, choose Virus & threat protection, click Scan options, and pick Full scan rather than the quick version. If the scan finds something it cannot remove, or malware keeps blocking your tools, the same menu offers an offline scan that restarts the computer and examines it before Windows fully loads, which catches threats that hide while the system is running.
On a Mac, the built-in protections quietly remove much of the common junk on their own, and a reputable antivirus from the official app store can run a deeper scan when you want certainty. On either system, let the operating system and the security software update before you scan: a scanner with outdated definitions misses the newest threats.
If the scan finds something: your first steps
Finding malware feels alarming, but the cleanup is usually straightforward. Work through this list in order.
- Disconnect from the internet while you clean up, especially if you saw signs of data theft or a ransom demand. Turn off Wi-Fi or unplug the network cable.
- Let the scanner quarantine or remove everything it flagged, restart, then run a second full scan to confirm the machine comes back clean.
- Change your passwords from a different device, starting with your email account, since password resets for everything else flow through it. This is a good moment to move them into a password manager such as Bitwarden or 1Password so every account gets its own.
- Turn on two-factor authentication for email and banking, so a stolen password is no longer enough on its own.
- Check your email settings for forwarding rules or recovery addresses you did not add. Attackers plant these to keep access after a cleanup.
- Update everything: operating system, browser, and apps. Infections often enter through holes that a patch closed months ago.
- Back up your important files once the machine scans clean, so the next incident cannot take your documents and photos with it.
- If the infection keeps returning, copy your personal files to an external drive and reinstall the operating system. It sounds drastic, but it is the one cleanup no ordinary malware survives.