Every day people search for strange file names they found on their PC, in a download folder or inside a game mod, asking "is this a virus?" A file name alone rarely answers that: malware often copies the names of legitimate Windows files, and many legitimate files have random-looking names. Here is how to actually find out.
Step 1: Don't run it, and don't delete it yet
Opening an unknown executable is the one thing that can make things worse. Deleting a file you don't understand can also break a program or Windows itself. Investigate first.
Step 2: Check the file's hash
Drag the file onto the iMalware scanner, or compute its MD5 and paste it into the hash lookup. If it matches a known malware hash, stop here: quarantine or delete it and run a full antivirus scan. If you have a SHA-256 hash, you can also search it on VirusTotal without uploading the file.
Step 3: Look at where it lives
- Normal places for programs:
C:\Program Files,C:\Program Files (x86),C:\Windows\System32(for genuine Windows components). - Suspicious for executables:
%AppData%,%LocalAppData%\Temp,C:\Users\Public,C:\ProgramDataor the Startup folder, especially with random names. Note that some legitimate apps (browsers, chat apps, updaters) also install per-user into AppData, so location alone is not proof. - A system file name in the wrong place — for example
svchost.exeorexplorer.exeoutsideC:\Windows— is a classic red flag.
Step 4: Check the digital signature and details
On Windows, right-click the file, choose Properties, and open the Digital Signatures tab (it only appears on signed files) and the Details tab. A valid signature from a known publisher is reassuring; an unsigned executable claiming to be from Microsoft, Google or a game studio is not. On a Mac, run codesign -dv --verbose=4 on the app.
Step 5: Watch for disguises
- Double extensions:
invoice.pdf.exeorphoto.jpg.scr. Turn on File name extensions in File Explorer's View menu so you see the real type. - Executable types pretending to be documents:
.exe,.scr,.com,.bat,.cmd,.js,.vbs,.hta,.lnkand.msican all run code. A "lease agreement" or "invoice" that is really one of these is almost certainly malicious. - Unexpected archives and disk images (
.zip,.rar,.iso,.img) in email are a common way to smuggle these files. See scanning ZIP files.
Step 6: Check what is running
In Task Manager, right-click a process and choose Open file location to see where it lives, then check that file as above. The Startup apps page in Task Manager (or Settings > Apps > Startup) shows what launches with Windows. Microsoft's free Sysinternals Autoruns tool shows every autostart location in detail.
Game mods, cheats, cracks and old games
Cheats, "free" paid software, key generators, skin changers and cracked games are among the most common ways people install malware, because the user deliberately runs an unsigned program and often disables their antivirus to do it. An app that asks for administrator rights is not proof of malware, but it does mean it can change anything on your PC. Abandonware and old game files from archive sites are usually just old, but check every executable before running it, and prefer official re-releases where they exist.
When the file is flagged
Follow the steps in what to do if a file is flagged: don't open it, quarantine or delete it, and run a full scan if it has already been executed.
Frequently Asked Questions
Can I tell if a file is malware just from its name?
No. Malware often borrows legitimate names like svchost.exe, and many legitimate files have random names. Check the hash, location and digital signature instead.
Should I delete a file I don't recognise?
Not before investigating. Check its hash and signature first. If it is a known malware file, delete or quarantine it. If it belongs to Windows or an installed program, deleting it can break things; uninstall the program properly instead.
Is a file that needs administrator rights a virus?
Not necessarily. Installers, drivers and launchers often need admin rights. But it does mean the program can change anything on your system, so only grant it to software from a source you trust.
If I open an unknown file in Notepad, can it infect my PC?
Opening a file in Notepad only displays its bytes as text; it does not run the file. It is generally a safe way to peek inside a small text-like file, though you won't learn much from a binary file this way.