CYBERSECURITY

If a computer looks infected

Signs of malware, and what to do before you call for help.

A slow computer, a screen full of pop-ups, or programs that crash can mean malware. Do not panic. Check the signs, then take the next steps.

Signs

  • Slowdowns or freezes you cannot explain. Malware often uses the machine’s resources.
  • Ads or fake warnings that will not stop. Those point to adware or spyware.
  • Apps that open, close, or crash on their own, or software you did not install.
  • Antivirus turned off, or updates blocked.
  • The browser sending you to unfamiliar sites or opening pages you did not request.

Steps to take

1. Disconnect

Leave Wi-Fi or unplug the Ethernet cable. This stops the malware from talking to outside servers, spreading to other devices, or taking more data.

2. Restart in Safe Mode

Safe Mode turns off extra processes, including many kinds of malware, so you can work without them running.

  • Windows: restart and press F8, or hold Shift while clicking Restart. Choose Safe Mode with Networking.
  • Mac: restart and hold the Shift key until the Apple logo appears, or press and hold the power button until the startup options menu appears.

3. Scan

Use an antivirus or anti-malware tool, and update it before the scan. Malwarebytes and Microsoft Defender are options that detect and remove many kinds of malware. Scan external hard drives and USB drives too.

4. Quarantine or delete

After the scan, the tool will usually offer to quarantine the files, which isolates them, or to delete them. Restart if the tool asks you to.

5. Update the system and the apps

Old software is full of holes malware can use. After the cleanup, update the operating system, the antivirus, and the other applications, and turn on automatic updates.

6. Change passwords

Treat logins as exposed. Change email, banking, and social accounts. Use strong, unique passwords, and turn on two-factor authentication where the account offers it.

7. Restore from a clean backup

If files were corrupted, encrypted, or deleted, restore from a backup. Scan the backup before you restore it. Regular copies, on an external drive or in the cloud, are how you limit ransomware damage.

If those steps are not enough

  • A bootable antivirus tool such as Avast Rescue Disk starts the computer from a USB drive or a CD to remove malware that is buried deeper.
  • A cybersecurity professional or a data-recovery specialist, which may be required for advanced ransomware or a badly damaged system.

How to prevent the next one

  • Keep a reputable antivirus updated. Some tools also include anti-malware and endpoint detection and response.
  • Leave the built-in firewall on. Both Windows and macOS have one.
  • Do not click suspicious links or open attachments from people you do not know. Most infections start with phishing.
  • Keep both an offline backup and an online one.
  • Turn on automatic updates for the system, browsers, and apps.
  • Use multi-factor authentication on sensitive accounts.
  • If you run a business, train people to recognize threats and follow the practices you set.

What a breach costs

System infections cost time and money. In 2024 the average cost of a data breach was $4.35 million. Losses of that scale are often devastating for a small business.

If the signs remain after those steps, call a professional. Advanced ransomware and rootkits need specialized tools. Removing the infection, securing the data, and preventing the next one are the three parts of the job.

Back to the blog