A computer that suddenly becomes slow, damages files, opens unfamiliar programs, or sends strange messages may be infected with malicious software. People often describe every digital infection as a “virus,” but a computer virus is actually one specific type of malware.
Its defining behavior is replication. A virus attaches itself to a legitimate file, document, or program and creates additional copies when the infected content runs. Those copies may spread to other files, removable drives, or computers.
Some viruses are designed to cause obvious damage. Others attempt to remain hidden while stealing information, changing system settings, or delivering additional malware.
What Is a Computer Virus?
A computer virus is malicious code that attaches itself to another file or program and reproduces when the infected host is executed.
Like a biological virus, it depends on a host. It cannot normally become active until someone opens the infected file, launches the compromised application, or performs another action that allows the code to run.
After activation, a computer virus may:
- Copy itself into other files
- Corrupt documents and programs
- Delete or modify information
- Change system settings
- Disable security tools
- Slow down the device
- Display unwanted messages
- Steal sensitive information
- Download additional malware
- Spread through USB drives or shared storage
Not every virus performs destructive actions immediately. Some remain inactive until a particular date, system event, or user action triggers their payload.
How Does a Computer Virus Work?
A computer virus typically moves through four stages.
Dormant Stage
Some viruses remain inactive after reaching a device. They wait for a specific condition before doing anything noticeable.
The trigger might be a date, number of restarts, application launch, or command received from another program.
Not every virus includes a dormant stage.
Propagation Stage
The virus copies itself into additional files, applications, documents, or storage locations.
Each infected copy may then create more copies when opened.
Triggering Stage
A particular condition activates the virus’s main behavior.
This can happen immediately or long after the original infection.
Execution Stage
The virus performs its intended action. It may damage files, display a message, collect information, or install another form of malware.
Common Types of Computer Viruses
File-Infector Virus
A file-infector virus attaches itself to executable files or applications.
When the infected program runs, the virus activates and may infect other executable files on the device.
Removing the virus without damaging the original program can sometimes be difficult because the malicious code has become part of the file.
Macro Virus
A macro virus is written using the scripting features built into applications such as word processors and spreadsheets.
It may hide inside a document and activate when the user enables macros or opens the file under unsafe settings.
Macro viruses are often distributed through email attachments disguised as invoices, reports, resumes, or business documents.
Boot-Sector Virus
A boot-sector virus infects the portion of a storage device used during the startup process.
It may activate before the operating system fully loads, making detection and removal more challenging.
Historically, these viruses spread through infected floppy disks. Modern versions may target boot records, removable drives, or other startup components.
Multipartite Virus
A multipartite virus infects more than one part of a system.
For example, it may infect both executable files and the boot sector. Removing only one part can allow the remaining infection to restore it.
Resident Virus
A resident virus loads itself into the device’s memory.
Once active, it can infect files as they are opened, copied, renamed, or executed. It may continue operating until the system shuts down or the malware is removed.
Direct-Action Virus
A direct-action virus activates when an infected file runs, searches for other files to infect, and then stops.
Unlike a resident virus, it does not necessarily remain continuously active in memory.
Polymorphic Virus
A polymorphic virus changes parts of its code or appearance as it creates new copies.
The underlying malicious behavior remains similar, but each copy may look different to a security scanner. Modern security software uses behavior analysis and other techniques to detect these changing variants.
Metamorphic Virus
A metamorphic virus rewrites its own code more extensively while preserving its purpose.
This makes copies more difficult to compare and can help the virus avoid simple signature-based detection.
Overwriting Virus
An overwriting virus replaces legitimate file contents with its own code.
Affected files may become unusable. Recovery can require deleting the damaged files and restoring clean copies from a backup.
Companion Virus
A companion virus creates a malicious program with a name or location designed to make the operating system run it instead of the legitimate application.
The original file may remain unchanged, but the malicious companion launches first.
Web-Scripting Virus
A web-scripting virus uses malicious scripts placed on a compromised or fraudulent website.
It may exploit a vulnerable browser, redirect visitors, steal session information, or attempt to download additional malware.
Computer Virus vs. Malware
Malware is the broad term for software created to damage, disrupt, spy on, steal from, or gain unauthorized access to a device.
Viruses are one category within malware. Other categories include:
- Ransomware
- Spyware
- Trojans
- Adware
- Worms
- Rootkits
- Keyloggers
- Botnet malware
Every computer virus is malware, but not every form of malware is a virus.
Computer Virus vs. Trojan Horse
A Trojan horse disguises itself as a legitimate program or file. It depends on deception to persuade someone to install it.
A computer virus attaches itself to a host file and reproduces when that file runs.
A Trojan does not normally copy itself, although it may install a virus after entering the device.
Computer Virus vs. Worm
A virus typically needs a user to run an infected host file. A computer worm can spread automatically through networks, messaging services, removable drives, or vulnerable systems.
Worms can move very quickly because each new infection may immediately search for additional targets.
Computer Virus vs. Ransomware
A virus describes how malicious code attaches to files and replicates. Ransomware describes malware that locks a device, encrypts files, or steals data before demanding payment.
Ransomware does not need to be a virus. However, a virus could theoretically deliver ransomware as its payload.
How Do Computer Viruses Spread?
Email Attachments
An attacker may send an infected document or program disguised as an invoice, delivery notice, photograph, resume, or security update.
The virus activates when the recipient opens the file or enables unsafe content.
Untrusted Downloads
Free programs, cracked software, key generators, game modifications, and unofficial installers can contain infected files.
A virus may be included even when the promised application appears to work correctly.
Removable Drives
USB drives and other removable storage can carry infected files between computers.
Some malicious programs create deceptive shortcuts or hide legitimate files so the user opens the virus instead.
Shared Files and Networks
An infected file stored in a shared folder may reach multiple people.
Each person who runs the file can activate another copy of the virus.
Compromised Websites
A hacked or fraudulent website may use malicious scripts, misleading download buttons, or software vulnerabilities to distribute infected content.
Pirated Media and Applications
Websites offering pirated software and media frequently expose visitors to malware through unsafe advertisements, fake download buttons, and modified installers.
Microsoft’s malware-prevention guidance warns that sites offering pirated material are often used to distribute malware and intrusive browser software. Microsoft Learn
Infected Documents
A document can contain macros, embedded objects, scripts, or links that activate malicious content.
Unexpected instructions to “Enable Editing” or “Enable Content” should be treated cautiously.
Warning Signs of a Computer Virus
A virus may not produce obvious symptoms. Possible warning signs include:
- Computer becoming unusually slow
- Frequent crashes or freezes
- Files disappearing or becoming corrupted
- Programs opening or closing unexpectedly
- Unknown applications appearing
- Security software being disabled
- Browser homepage changing
- Unwanted pop-ups
- Storage space disappearing
- High network activity while idle
- Files changing size or extension
- Unexpected error messages
- Emails or messages sent without permission
- USB drives behaving strangely
- Computer restarting repeatedly
- Fans running heavily without an obvious reason
- Settings changing without permission
These symptoms do not always prove that a virus is present. Hardware problems, failed updates, low storage, and ordinary software bugs can cause similar behavior.
An updated security scan is the safest way to begin investigating.
What Should You Do If You Suspect a Virus?
Disconnect the Device
Disconnect the computer from Wi-Fi, Ethernet, shared drives, and removable storage.
This may prevent the infection from spreading or communicating with an attacker.
Stop Using Sensitive Accounts
Avoid banking, shopping, email, and password changes on the suspected device.
If the virus includes password-stealing features, any newly entered information may also be exposed.
Inform Other Users
If you shared files or removable drives with other people, tell them that the content may be infected.
Businesses should notify their IT or security team immediately.
Preserve Important Information Carefully
Do not copy executable programs or unknown files to a backup drive.
If essential documents must be preserved, scan them before opening them on another device.
How to Remove a Computer Virus
Update the Antivirus Software
Connect only if necessary to update trusted security software, or obtain the update through a clean device using the vendor’s instructions.
Current threat definitions improve detection of recently identified viruses.
Run a Full System Scan
A quick scan checks common infection locations. A full scan examines more files and usually provides a more complete review.
Quarantine or remove confirmed threats according to the antivirus instructions.
Use an Offline Scan
Some viruses hide or defend themselves while the operating system is running.
An offline scan starts in a separate recovery environment, making it harder for active malware to interfere. Windows includes a Defender Offline option for persistent threats. Microsoft Support
Scan Removable Storage
Check every USB drive, external disk, and memory card connected to the computer.
Otherwise, an infected drive may restore the virus after the computer has been cleaned.
Remove Infected Applications
If the antivirus cannot safely repair an infected application, uninstall it and download a clean copy from the official source.
Do not reinstall the same suspicious or modified installer.
Restore Damaged Files
Replace corrupted documents and programs using a clean backup created before the infection.
Scan the backup before restoring it.
Reinstall the Operating System
A clean operating-system installation may be necessary when:
- The virus repeatedly returns
- System files are heavily damaged
- Security software cannot remove it
- Administrator access was compromised
- Several malware types are present
- The device stores highly sensitive information
Back up personal documents carefully and avoid copying unknown programs or scripts.
Seek Professional Help
A qualified technician or incident-response specialist may be necessary when business systems, financial accounts, or irreplaceable data are involved.
CISA’s recovery guidance advises users to minimize further damage, remove malicious code, update protections, and use firewalls where appropriate. CISA
What to Do After Removing a Virus
Assume that private information may have been exposed while the infection was active.
From a trusted device:
- Change important passwords
- Enable multi-factor authentication
- Review account login history
- Sign out of unfamiliar sessions
- Check email forwarding rules
- Contact financial institutions if necessary
- Monitor card and banking transactions
- Install all security updates
- Confirm that the firewall is enabled
- Scan backup and removable drives
- Create a fresh clean backup
If the infected device was used for work, follow the organization’s incident-reporting requirements.
How to Prevent Computer Viruses
Use Updated Antivirus Software
Keep reputable antivirus or anti-malware software enabled.
CISA notes that antivirus software can identify and block many known viruses before they infect a device, but it must remain updated. CISA
Enable Real-Time Protection
Real-time protection scans files when they are downloaded, opened, or executed.
Disabling it to install an unknown program removes an important layer of defense.
Install Software Updates
Keep the operating system, browser, document software, media applications, and other programs updated.
Security patches repair vulnerabilities that malicious code may exploit.
Download From Official Sources
Use official application stores and developers’ verified websites.
Avoid cracked software, unofficial activation tools, modified installers, and unknown download portals.
Be Careful With Attachments
Confirm unexpected attachments through a separate communication method.
Do not enable macros or other active content unless the file comes from a trusted source and genuinely requires them.
Scan Removable Drives
Scan USB drives and external disks before opening their files, particularly if they were used on public or shared computers.
Disable automatic execution features where appropriate.
Use a Standard Account
Use a non-administrator account for ordinary browsing, email, and document work.
Microsoft recommends limiting privileges because most malware initially runs with the permissions of the active user.
Keep the Firewall Enabled
A firewall monitors network connections and can block certain unauthorized communications.
It does not replace antivirus protection, but it provides another defensive layer.
Back Up Important Files
Create regular backups of documents, photographs, and other valuable information.
Keep at least one backup disconnected or isolated so an infection cannot easily damage it.
Avoid Fake Virus Alerts
A website that displays a dramatic virus warning has not necessarily scanned the computer.
Do not call an unknown support number or install software recommended by a pop-up. Close the page and run a scan using trusted security software already installed on the device.
Can a Computer Virus Infect a Phone?
Traditional file-infecting viruses are less common on modern phones than on desktop computers.
However, smartphones can still be affected by Trojans, spyware, adware, ransomware, malicious profiles, and other malware. People often refer to these threats generally as phone viruses.
Use official app stores, review permissions, keep the phone updated, and avoid installing applications from unexpected links.
Can a Virus Spread Through Wi-Fi?
A traditional virus does not usually spread merely because several devices use the same Wi-Fi network.
However, malware on one device may access shared folders, exploit vulnerable systems, or install worm-like components capable of spreading across the network.
Isolating an infected computer helps protect other connected devices.
Can a Virus Infect an External Drive?
Yes. A virus may copy infected files, deceptive shortcuts, or malicious scripts onto a USB drive or external disk.
If the drive is connected to another computer and the infected content runs, the second computer may become infected.
Scan removable storage before opening files.
Does a Factory Reset Remove a Computer Virus?
A complete factory reset or clean operating-system installation removes most ordinary viruses from the main storage drive.
The infection may return if the user restores an infected backup, reconnects a contaminated external drive, or installs the same malicious program again.
Update the system and security software before restoring scanned personal files.
Is Antivirus Software Enough?
Antivirus protection is important, but it cannot guarantee that every threat will be blocked.
The strongest protection combines antivirus software with:
- Prompt security updates
- Safe download habits
- Careful handling of attachments
- Limited administrator access
- Multi-factor authentication
- Firewalls
- Clean offline backups
- Regular security scans
Security works best as several overlapping layers rather than one application expected to stop every possible attack.
