Unexpected Signs Your Computer Has a Virus (and What to Do)

The signs your computer has a virus are not diagnoses. A slow computer can have a full disk, a failing drive, a bad update, or malware. Treat sudden, unexplained combinations of symptoms as a reason to isolate and investigate, not as proof of one cause.

If accounts are being used without you, files are encrypted, security tools are disabled, or the device is contacting destinations you do not recognize, act now. For an employer-owned device, stop and call the security team. A well-meant cleanup can destroy evidence or spread the incident.

signs your computer has a virus shown on an infected laptop screen

What to Do First

  1. Disconnect the affected device from networks. Turn off Wi-Fi, unplug Ethernet, and disconnect shared storage. In a business incident, the FTC advises disconnecting an infected device without powering it down because shutdown can remove useful investigative evidence.
  2. Use a separate, clean device. Change the email password first, then financial, cloud, and administrative accounts. Revoke active sessions and recovery tokens; a password change alone may not invalidate every stolen session.
  3. Record what happened. Note warnings, filenames, extensions, timestamps, account alerts, recent downloads, and affected systems. Do not forward a suspicious attachment to colleagues.
  4. Update the scanner and run the appropriate scan. On Windows, use a full scan and consider an offline scan for persistent threats.
  5. Escalate when the impact is material. Contact qualified incident-response help, the account provider, financial institution, insurer, and relevant authorities when money, regulated data, or multiple systems are involved.

The FTC small-business cybersecurity guidance organizes the work as prevention, detection, response, and recovery. That sequence is more useful than guessing the malware family from one symptom.

Unexpected Signs and Their Non-Malware Alternatives

Observed signMalware is possible whenAlso test
Sudden slowdown or fan activityAn unfamiliar process uses CPU, disk, or network at idleUpdates, indexing, thermal throttling, low memory, or failing storage
Unexpected network usageUsage continues after normal sync and update tools are closedCloud backup, game updates, operating-system delivery optimization
Browser redirects or changed searchExtensions or policies appeared without approvalNotification permissions, adware, changed DNS, or a compromised router
Files renamed or inaccessibleMany files gain the same strange extension or a ransom note appearsSync conflicts, disk corruption, permission errors, or failed encryption software
Security tools disabledProtection cannot be re-enabled and settings change againExpired license, organization policy, incompatible security products
Account alerts and sent messagesNew sessions, rules, recovery methods, or messages appearCredential reuse, phishing, delegated access, or provider-side compromise
slow PC performance as a sign of malware infection

Open Task Manager on Windows or Activity Monitor on macOS and record the process name, publisher, path, CPU, disk, and network use. Do not delete a file merely because its name looks odd. Search the publisher and path, scan it, and use the operating system’s quarantine flow.

If the slowdown remains after a clean scan, use my guide to boosting the performance of a low-end computer to test ordinary resource limits.

corrupted and duplicated files caused by a computer virus

Choose the Scan for the Situation

ScanUseful forLimit
Quick scanCommon persistence locations and a routine health checkIt does not inspect every file.
Full scanA deeper check after suspicious behavior or exposureLarge archives and disks can make it slow.
Offline scanPersistent threats that may hide while Windows is runningThe computer restarts; save work first.
Second-opinion on-demand scanIndependent confirmation after the primary tool completesDo not run multiple real-time engines together.
Microsoft documents the scan choices and recommends an offline scan as the most complete option in its Defender workflow.

Microsoft Defender is built into current Windows security. An on-demand tool such as Malwarebytes can provide a second opinion. If you want a paid real-time suite, compare Bitdefender and Surfshark Antivirus on detection, platform coverage, renewal price, support, and what is actually included.

hard drive storage filling up unexpectedly from malware

Recovery Is More Than Removing One File

  • Confirm: run the updated scan again and inspect protection history.
  • Restore: use a known-good backup made before the compromise. Scan restored files before opening them.
  • Patch: update the operating system, browser, extensions, document tools, router, and exposed applications.
  • Reset access: rotate credentials from a clean device, revoke sessions, remove unknown recovery methods, and review forwarding rules.
  • Monitor: watch financial accounts, email rules, cloud logs, and security alerts for renewed activity.
  • Reinstall when trust cannot be restored: a clean operating-system installation is safer than an endless sequence of uncertain removals.

If Malwarebytes or another scanner reports a detection, save the exact detection name and path before deleting it. A generic “threat found” message is not enough for a business incident report.

computer crashing repeatedly as a malware symptom

Prevent the Next Incident

  • Turn on automatic operating-system, browser, and application updates.
  • Use unique passwords, a guide to password managers, and phishing-resistant multi-factor authentication where available.
  • Keep at least one backup version isolated from the device or network it protects.
  • Remove unused browser extensions and software; restrict administrator access.
  • Test restore steps and account-recovery contacts before an incident.

A VPN can protect traffic on an untrusted network, but it does not disinfect a computer, block every phishing page, or make a malicious download safe. Use why you should use a VPN for that narrower decision.

email account hijacked by malware sending spam to contacts

For the surrounding controls, continue with five tips to ensure defense from cyber threats, WiFi security measurements every user should know, and best practices to secure your business. The historical term is associated with researcher Frederick Cohen; today’s practical problem is broader malware, account theft, and recovery.

Safety boundary: do not upload confidential files to public scanners, pay a ransom on your own, or keep experimenting on a company device. When regulated data, money, or multiple systems are involved, preserve evidence and bring in qualified help.

Tell Google you want more of this.

Add Gaurav Tiwari as a preferred source

One tap, and this site shows up more often in your own Top Stories, AI Overviews and AI Mode. Remove it any time.