Malware · guide
How to tell if your computer has a virus
By Alberto Gulotta · Updated · 17 min read
How to tell if your computer has a virus depends on sorting the signs rather than counting them. Some are events — you were signed out, your antivirus stopped running, your homepage changed itself. Those need a cause. The rest are measurements, and a slow, warm, loud machine proves nothing at all.
Sort the list before you read it
Every checklist on this question is a single flat list: slow computer, pop-ups, crashes, high fan noise, unfamiliar programs, security software not working. Read that way it is useless in both directions — it makes a six-year-old laptop look infected, and it gives a genuinely compromised machine several ways to look normal.
The signs divide cleanly into two kinds, and the division is not a matter of opinion.
Some are events. They happened or they did not, and there is nothing to judge. You were signed out of your account to protect the device. Your antivirus no longer runs. Your homepage changed and changing it back does not stick. People received messages from you that you did not send. Each of these needs a cause, and the ordinary causes are few.
The rest are measurements. Slow, warm, loud, hungry for battery or data. These have a range rather than a state, and everything from a full disk to a browser tab to a five-year-old battery moves them. They are worth noticing and they are worth almost nothing alone.
Microsoft makes this distinction on its own page, and it is the sentence to take away. Having listed running much slower than usual, a significant decrease in battery life and an unexpected increase in data usage, it adds: “any of those symptoms may indicate that an unknown process is running in the background and consuming your device resources”. Not that you have malware — that something is using the machine. Which is a real clue and a different claim.
| Sign | What it proves on its own | Where it comes from |
|---|---|---|
| You were signed out of your account to protect the device | It happened or it did not. No judgement needed. | Google names it as a sign of malware |
| Your security software no longer works | Something disabled it, and ordinary faults rarely do. | Google’s list of signs on the device |
| Contacts get messages you did not send | Something is acting as you. Often the account, not the machine. | Google’s list, in a group of its own |
| Homepage or search engine changed by itself; redirects | Something is rewriting what the browser does. | Google and Microsoft both list it |
| Ads and pop-ups when the browser is closed | The browser is not the source, so something else is. | Microsoft and Google both list it |
| Suddenly much slower; battery drain; more data used | Nothing on its own. Microsoft says it “may indicate” a process using resources. | Microsoft, with that qualification attached |
The signs that are worth acting on immediately
You were signed out of your account. Google names this first on its own malware page, which is unusual and deliberate: your device might have malware if “Google signed you out of your Google account to protect your device”. And it attaches a consequence: “if you don’t get rid of malware from your device, you might get signed out again”. A second sign-out is not bad luck. It is the same alarm ringing twice.
Your security software will not run. Google lists “your anti-virus program no longer works” among the signs on the device. Software does break by itself, but it is the one category of program that something hostile has a specific reason to break, and it is trivial to check.
Your contacts got messages you did not send. Google keeps this in a group of its own, separate from device symptoms and browser symptoms, and the grouping is the point: this usually says the account was taken rather than the machine. Nothing you scan or remove locally will fix it, which is why what to do after a data breach is the page that follows from this one.
The browser does not stay where you put it. A homepage or search engine that changes on its own, extensions or toolbars that come back after removal, pages going somewhere you did not ask for — Google lists all four, and Microsoft independently lists “getting redirected to totally different sites when trying to browse the web”. Something is rewriting the browser’s behaviour and putting itself back afterwards.
Ads when the browser is closed. Microsoft and Google both list it. It matters because of what it rules out: if no browser is open, the browser is not showing them, so something else on the machine is.
The one everyone leads with, and why it belongs last
“My computer is slow” is the most common reason people arrive at this question, and it is the weakest evidence on the list. The strongest demonstration of that comes from Microsoft itself, on a different page, explaining why a Defender scan might be slow.
Its explanations are: “make sure you have enough available disk space”; “full scans can take a long time if you have a large disk with lots of files. Large files, especially archives such as zip files, take longer to scan”; and that “scanning takes system resources like processor and memory. If you have other programs running they may be creating a bit of a traffic jam”.
Four ordinary causes, none of them malware — offered by the company that makes both the operating system and the scanner. If those explain a slow scan, they explain a slow machine. A computer that has always been slow, or that got slower over a year, is describing its disk, its memory and its startup list. A computer that was fine on Tuesday and is unusable on Wednesday is describing something that changed, and that is worth following.
The useful version of the question is not “is it slow” but “is it suddenly and unexplainedly slow”, and even then the honest next step is Task Manager rather than a conclusion: something is either using the processor or it is not.
The question that narrows it faster than any symptom
Symptoms are ambiguous; entry points are not. It is usually quicker to ask what happened in the days before than to grade a list of behaviours, and the public guidance is specific about which doors exist.
One label belongs beside everything quoted from CISA below: the page is filed as “Archived Content”, and CISA says of the archive that it “contains outdated information that may not reflect current policy or programs” — released 14 July 2009, revised 19 November 2019. What is taken from it here is how malicious code gets in and what the categories are, not a current recommendation.
CISA’s description of malicious code names the categories plainly: viruses; worms, which CISA calls “a type of virus that self-propagates from computer to computer” and whose “functionality is to use all of your computer’s resources, which can cause your computer to stop responding”; and trojan horses, which hide inside something you wanted — “it is not uncommon that free software contains a trojan horse”.
The category CISA describes next is the least discussed of the four, and it is the reason “I did not install anything” is not a defence: “malicious data files are non-executable files — such as a Microsoft Word document, an Adobe PDF, a zip file, or an image file — that exploits weaknesses in the software program used to open it”. CISA adds that attackers “frequently use malicious data files to install malware on a victim’s system”, distributed by email, social media and websites.
So the more productive question than “which of these symptoms do I have” is: did you install free software from somewhere unfamiliar, open an attachment you were not expecting, or plug in someone else’s USB stick? CISA’s own list of defences is built around exactly those doors — including two that cost nothing: use an account with limited permissions, because “restricted permissions keep the malicious code from spreading and escalating to an administrative account”, and “disable external media AutoRun and AutoPlay features”.
What to do with the answer you now have
Three outcomes, and the honest next step for each.
Why the lists are all the same, and all flat. The five pages that answered this question best when the search results were read on 9 September 2026 give between about 460 and about 4,400 words, and every one of them is an unranked list of symptoms. That is not carelessness so much as a format: a list is easy to write and impossible to be wrong with, because every item on it really can accompany an infection. The cost falls on the reader, who has no way to tell which item settles anything. Both halves of the sort above come from the makers themselves — Microsoft grading its own symptoms, Google putting an event rather than a feeling at the top of its list — and both were a click away from the pages that rank.
Where to go once you have decided. If it looks real, removing malware from a computer is the sequence, including the four things a clean scan does not rule out. If an account rather than a machine is involved, what to do after a data breach starts from the right device. And if the only symptom is a frightening page, that is a fake security alert.
Where to start
Three ways in.
- “Which signs actually count?”
- The two kinds — two kinds
- “My computer is just slow”
- Why that is the weakest one — slow
- “How would it even have got in?”
- The doors, from CISA — how it got in
Once you have an answer
This page decides whether there is something to remove. These are the ones that remove it.
The duller explanations, which are usually the right ones
Almost every measurement on the checklist has a mundane cause that a scan will never find.
Questions people also ask
How can I detect computer viruses?
Two things, in this order. Sort the signs: an event, such as being signed out of an account or security software that no longer runs, is evidence; a measurement, such as slowness, is not. Then run one full scan to settle it, rather than several.
Where is a computer virus usually hidden?
CISA names the ordinary places: inside free software that also does something useful, and inside “malicious data files” — a Word document, a PDF, a zip or an image that exploits a weakness in the program opening it. That last category is why “I did not install anything” is not conclusive.
Does a slow computer mean it has a virus?
On its own, no. Microsoft explains a slow Defender scan by low disk space, a large disk with many files, big archives and other programs competing for resources. The same causes explain a slow computer. What is worth following is slowness that arrived suddenly.
Can a virus hide from antivirus software?
Some can, which is why security software that stops working is itself on the list of signs. The NCSC also notes that signature scanning has been limited by changes in platforms and malware, so a clean result narrows the question rather than closing it.
What should I do first if I think my computer has a virus?
Change nothing and note when the behaviour started, then run one full scan. If any of your accounts is involved, change those passwords from a different device: a password typed on a compromised machine is handed over as you set it.
Is a pop-up saying I have a virus proof that I do?
It is proof of a web page. A page cannot examine the machine it is drawn on, so a page that claims to have scanned yours is guessing in order to sell something or collect a click.
Not covered here. It does not name a product to scan with, and it does not rank scanners. What one scan can and cannot settle belongs to the page on removing malware, which covers the blind spots a clean result leaves.
It does not cover a work computer managed by an employer, where the machine reports to someone whose job this is and the right first step is to tell them rather than to scan.
And it does not diagnose hardware. A drive that is failing produces several of the same measurements as an infection, and no amount of scanning distinguishes them. What holds instead is simple: each sign is attributed to the documentation that names it rather than to a general list, the qualification Microsoft attaches to slowness is quoted rather than dropped, the ordinary causes of a slow machine come from Microsoft explaining its own scanner, and the entry points are quoted from CISA including the category of malicious data files.
Sources
- Microsoft Support — How to start a scan for viruses or malware in Microsoft Defender: the list of signs a device might have malware, including running much slower than usual, a significant decrease in battery life and an unexpected increase in data usage, together with the qualification that any of those symptoms “may indicate that an unknown process is running in the background”; and the separate signs of unexpected ads or pop-ups and redirection to different sites — support.microsoft.com, read 9 September 2026.
- Microsoft Support — Troubleshoot problems with detecting and removing malware: the ordinary causes Microsoft gives for a slow scan, namely insufficient available disk space, a large disk with many files, large archives such as zip files, and other programs competing for processor and memory — support.microsoft.com, read 9 September 2026.
- CISA — Protecting Against Malicious Code: the definitions of viruses, worms and trojan horses including that a worm uses all of a computer’s resources and can stop it responding; the category of malicious data files such as documents, PDFs, zips and images that exploit the program opening them; and the defences, including using an account with limited permissions and disabling AutoRun and AutoPlay — www.cisa.gov, read 9 September 2026.
- Google Account Help — Remove malware or unsafe software: that being signed out of your Google account to protect the device is named as a sign of malware and can recur if the malware is not removed, the grouped list of signs on the device and in the browser including an anti-virus program that no longer works, and the separate sign of contacts receiving messages you did not send — support.google.com, read 9 September 2026.
- National Cyber Security Centre — Antivirus and other security software, Device security guidance: that traditional signature-based scanning has been limited in effectiveness by advances in malware and changes in underlying platforms, and that running more than one antivirus product on a device offers minimal benefit — www.ncsc.gov.uk, read 9 September 2026.
Written by Alberto Gulotta
Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.
Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.
Written on 9 September 2026 · last checked 15 September 2026.
Independence and limits
No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.
This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.