Home AI Threats Free Help Services About IT Support Contact Book Consultation →
Back to Free Help
15 minutes to read9 signs to check

How to Tell If Your Computer Is Infected

Malware doesn't always announce itself with scary pop-ups and skull-and-crossbones screens. Modern infections are designed to be invisible — quietly stealing passwords, mining cryptocurrency, or watching what you type. But they always leave traces. This guide teaches you what to look for and exactly what to do if you spot the signs.

1

Your computer is suddenly much slower

If your computer recently became noticeably sluggish without you installing anything new, malware could be running in the background. Cryptominers use your processor to mine cryptocurrency for someone else. Spyware constantly monitors your activity. Both consume CPU and memory that would normally go to your programs.

What to do: Open Task Manager (Ctrl + Shift + Esc) and click the CPU column to sort by usage. If a process you don't recognize is using 20%+ of your CPU consistently, Google its name. If it's unfamiliar or suspicious, note it and run the scans from our virus removal guide.

2

Unexpected pop-ups, even with your browser closed

Legitimate software almost never shows pop-ups when you're not using it. If you're seeing ads, fake virus warnings ("Your computer is infected! Call this number!"), or system alerts when your browser isn't open — that's adware or scareware. These pop-ups often try to get you to install more malware disguised as "security software" or call a fake support number.

What to do: Never click the pop-up or call any number it shows. Never install anything it recommends. Check your installed programs list for anything unfamiliar (Settings → Apps → Installed apps, sorted by date). Run Malwarebytes — it's particularly good at catching adware.

Warning: "Your computer has a virus!" pop-ups that appear in your web browser are almost always scams themselves. Real antivirus software doesn't communicate through browser pop-ups.
3

Unknown processes in Task Manager

Malware often disguises itself as legitimate-sounding processes. Names like svchost.exe (real, but sometimes impersonated), systemupdate.exe, or helper.exe can be malware hiding in plain sight. Some malware even names itself after popular software brands.

What to do: In Task Manager, right-click a suspicious process and select "Open file location." Legitimate Windows processes live in C:\Windows\System32. If the file is in a random folder, a temp directory, or your Downloads folder — that's a red flag. Right-click → "Search online" to look up the process name.

Tip: For deeper investigation, download Microsoft's free Process Explorer tool — it shows more detail than Task Manager and can verify whether a process is digitally signed by a trusted company.
4

Your browser homepage or search engine changed

If your browser suddenly opens to a different homepage, your search engine switched to something you've never heard of, or you're seeing an extra toolbar you didn't add — a browser hijacker has modified your settings. These redirect your searches through malicious sites that track everything you do and inject ads into every page.

What to do: Check your browser extensions and remove anything unfamiliar. Reset your browser settings to defaults. Check your installed programs for recently added toolbars or "search assistants" and uninstall them.

5

Programs crashing or behaving strangely

Frequent crashes, applications freezing, or the dreaded Blue Screen of Death (BSOD) appearing more often than usual can indicate malware interfering with system processes. Some malware conflicts with legitimate software, corrupts system files, or deliberately crashes security tools to prevent detection.

What to do: If your antivirus or Windows Security keeps crashing or won't open, that's a strong indicator of active malware trying to protect itself. Boot into Safe Mode (see our virus removal guide, Step 2) and run scans from there, where the malware can't block your tools.

6

Your hard drive is unusually active

If your hard drive light is constantly blinking or your disk usage shows near 100% in Task Manager when you're not doing anything — something is writing or reading large amounts of data. This could be malware encrypting your files (ransomware), exfiltrating your documents, or scanning your drive for passwords and financial data.

What to do: In Task Manager, click the Disk column to sort by disk usage. Identify which process is causing the activity. If it's something you don't recognize, investigate it using the process location technique from Step 3.

7

Unusual network activity during idle times

If your internet activity light is blinking when you're not browsing, or your data usage has spiked without explanation, malware may be transmitting stolen data to an external server or participating in a botnet. Some malware uses your computer to attack other systems without your knowledge.

What to do: Open Task Manager → Performance tab → Open Resource Monitor → Network tab. This shows every process making network connections. Look for unfamiliar processes sending data to unknown IP addresses, especially when you're not actively using the internet.

8

Friends receive messages you didn't send

If people in your contacts report receiving strange messages, links, or emails from you that you didn't send — your account or device has been compromised. Malware often spreads by sending itself to your contacts via email, social media, or messaging apps. It uses your trusted relationships to trick others into clicking.

What to do: Change your passwords immediately from a different, clean device. Enable two-factor authentication. Check your email's "Sent" folder and social media message history for messages you didn't write. Warn your contacts not to click any links they received from you. Follow our "What to Do If You've Been Hacked" guide.

9

Your antivirus is disabled and you didn't do it

This is one of the strongest signs of active malware. If Windows Security shows "Threat protection is off" or your antivirus shows as disabled without you turning it off — malware is actively defending itself by shutting down your defenses. Some sophisticated malware modifies Windows Registry keys to prevent security tools from restarting.

What to do: This is serious. Don't try to fix it from normal Windows — the malware will likely block your attempts. Boot into Safe Mode immediately and follow our full virus removal guide. If the antivirus still won't re-enable in Safe Mode, a clean OS reinstall is recommended — see our "What to Do If You've Been Hacked" guide.

Red alert: If your antivirus was disabled and you had saved passwords in your browser, treat this as a credential theft incident. Change all passwords from a separate clean device immediately.

Not sure what you're seeing? We can take a look.

Distinguishing between a normal slow computer and an active infection isn't always obvious. In a session, we can screen-share and walk through your Task Manager, startup programs, and network activity together to figure out exactly what's going on.