Decide whether the device is high risk
Disconnect the device from networks if files are being encrypted, the pointer moves by itself, security tools are disabled or unfamiliar payments appear. Do not keep signing into accounts from a device you believe is compromised.
For a work device, regulated information or suspected stalking, stop and contact the responsible security team or qualified professional. Unstructured cleaning can destroy evidence.
Preserve what you may need
Photograph ransom notes or unusual messages and record when symptoms began. From a separate trusted device, check recent account activity and financial transactions.
Do not copy executable files or unknown archives into a clean backup. If valuable documents are not backed up, professional recovery may be safer than repeated repair attempts.
Update and scan
On Windows, update Microsoft Defender or a reputable installed antivirus, then run a full scan. An offline scan can inspect the system before much of Windows loads. On macOS, remove suspicious configuration profiles, login items and browser extensions before scanning with a reputable tool.
Android users should check device-administrator and accessibility permissions and remove apps installed outside trusted stores. On iPhone, most incidents involve malicious profiles, calendars, subscriptions or stolen credentials rather than a conventional virus.
Remove persistence and unwanted changes
After quarantine, review startup entries, browser extensions, notification permissions, proxy settings and DNS configuration. Reset a browser only after recording needed bookmarks and understanding what will be removed.
Avoid random registry cleaners and unfamiliar removal tools advertised in pop-ups. They can add risk and rarely address the underlying account compromise.
Recover accounts from a clean device
Change important passwords, beginning with email, password manager, banking and cloud accounts. Revoke sessions, regenerate recovery codes and verify that forwarding rules, recovery addresses and multifactor methods were not changed.
If the same password was reused, every account using it should be treated as exposed. A password manager can generate and store unique replacements.
When to reset or seek help
A full reset or clean operating-system installation is appropriate when security tools cannot run, privileged access may be compromised or symptoms return. Restore only known personal files, reinstall applications from official sources and apply updates before reconnecting broadly.
Seek specialist help for ransomware, business systems, intimate-partner surveillance, cryptocurrency theft or evidence that highly sensitive data was accessed.
Recognising the main categories of malware
Knowing roughly what you are dealing with changes the correct response. Adware and browser hijackers alter search results, inject advertising and add extensions; they are annoying rather than catastrophic and usually clear after removing the extension and resetting browser settings. Information stealers are far more serious: they harvest saved passwords, session cookies, cryptocurrency wallets and autofill data within minutes of execution, which means account recovery matters more than cleaning the machine.
Remote-access trojans give an attacker interactive control, often arriving through cracked software, fake job documents or bogus support calls. Ransomware encrypts files and demands payment, and increasingly copies data before encrypting it so that refusal to pay is met with a leak threat. Cryptominers quietly consume processing power, showing up as heat, fan noise and poor battery life rather than obvious damage.
Mobile threats follow a different pattern. On Android, most damage comes from applications installed outside official stores that request accessibility or device-administrator permissions and then overlay banking apps. On iPhone, conventional viruses are rare and the realistic risks are configuration profiles, calendar spam, subscription traps and stolen credentials reused elsewhere.
- Adware and browser hijackers
- Information stealers and keyloggers
- Remote-access trojans
- Ransomware with data-leak extortion
- Cryptominers and mobile overlay apps
Why account recovery matters more than the scan
If an information stealer ran on your device, the most valuable losses have already happened. Saved browser passwords, authentication cookies and stored card details are packaged and sold within hours, often before any antivirus scan finishes. A stolen session cookie can let an attacker resume your logged-in session without needing your password or your second factor at all.
That is why the order of operations matters. From a separate clean device, change the email password first, because email controls the reset of everything else. Then sign out of all sessions in each important account, regenerate recovery codes, and check that recovery phone numbers, forwarding rules and connected applications have not been altered. Only then move on to banking, cloud storage and social accounts.
Keep a written list as you go. People routinely forget older accounts that share a reused password, and those accounts are exactly what attackers use later to rebuild access.
Preventing reinfection
Most repeat infections come from the same route as the first one. Pirated software and activation tools are the single most common source on home computers, followed by search advertisements impersonating popular downloads and by browser extensions that change ownership after installation. Download applications from the vendor's own site or an official store, and re-check the address rather than the advertisement.
Keep automatic updates enabled for the operating system, browser and any security software, because unpatched browsers and plugins remain a reliable infection route. Use a standard user account rather than an administrator account for daily work, which limits what a careless click can install.
Finally, build a backup you could actually restore from. Follow the principle of keeping at least two copies plus one that is offline or otherwise not writable by your everyday computer, then test a restore once. Ransomware negotiations mostly happen because a backup existed in theory but not in a usable, disconnected form.
- Avoid cracked software and activators
- Download from official sources only
- Keep automatic updates enabled
- Use a non-administrator daily account
- Maintain one offline, tested backup
