How to remove malware without making things worse

    Unexpected adverts or a slow computer do not automatically prove malware, while some serious infections show almost no symptoms. The safest response separates containment, evidence, removal and account recovery.

    By Rui Matos · Cybersecurity Editor · Updated 18 September 2026

    Decide whether the device is high risk

    Disconnect the device from networks if files are being encrypted, the pointer moves by itself, security tools are disabled or unfamiliar payments appear. Do not keep signing into accounts from a device you believe is compromised.

    For a work device, regulated information or suspected stalking, stop and contact the responsible security team or qualified professional. Unstructured cleaning can destroy evidence.

    Preserve what you may need

    Photograph ransom notes or unusual messages and record when symptoms began. From a separate trusted device, check recent account activity and financial transactions.

    Do not copy executable files or unknown archives into a clean backup. If valuable documents are not backed up, professional recovery may be safer than repeated repair attempts.

    Update and scan

    On Windows, update Microsoft Defender or a reputable installed antivirus, then run a full scan. An offline scan can inspect the system before much of Windows loads. On macOS, remove suspicious configuration profiles, login items and browser extensions before scanning with a reputable tool.

    Android users should check device-administrator and accessibility permissions and remove apps installed outside trusted stores. On iPhone, most incidents involve malicious profiles, calendars, subscriptions or stolen credentials rather than a conventional virus.

    Remove persistence and unwanted changes

    After quarantine, review startup entries, browser extensions, notification permissions, proxy settings and DNS configuration. Reset a browser only after recording needed bookmarks and understanding what will be removed.

    Avoid random registry cleaners and unfamiliar removal tools advertised in pop-ups. They can add risk and rarely address the underlying account compromise.

    Recover accounts from a clean device

    Change important passwords, beginning with email, password manager, banking and cloud accounts. Revoke sessions, regenerate recovery codes and verify that forwarding rules, recovery addresses and multifactor methods were not changed.

    If the same password was reused, every account using it should be treated as exposed. A password manager can generate and store unique replacements.

    When to reset or seek help

    A full reset or clean operating-system installation is appropriate when security tools cannot run, privileged access may be compromised or symptoms return. Restore only known personal files, reinstall applications from official sources and apply updates before reconnecting broadly.

    Seek specialist help for ransomware, business systems, intimate-partner surveillance, cryptocurrency theft or evidence that highly sensitive data was accessed.

    Recognising the main categories of malware

    Knowing roughly what you are dealing with changes the correct response. Adware and browser hijackers alter search results, inject advertising and add extensions; they are annoying rather than catastrophic and usually clear after removing the extension and resetting browser settings. Information stealers are far more serious: they harvest saved passwords, session cookies, cryptocurrency wallets and autofill data within minutes of execution, which means account recovery matters more than cleaning the machine.

    Remote-access trojans give an attacker interactive control, often arriving through cracked software, fake job documents or bogus support calls. Ransomware encrypts files and demands payment, and increasingly copies data before encrypting it so that refusal to pay is met with a leak threat. Cryptominers quietly consume processing power, showing up as heat, fan noise and poor battery life rather than obvious damage.

    Mobile threats follow a different pattern. On Android, most damage comes from applications installed outside official stores that request accessibility or device-administrator permissions and then overlay banking apps. On iPhone, conventional viruses are rare and the realistic risks are configuration profiles, calendar spam, subscription traps and stolen credentials reused elsewhere.

    • Adware and browser hijackers
    • Information stealers and keyloggers
    • Remote-access trojans
    • Ransomware with data-leak extortion
    • Cryptominers and mobile overlay apps

    Why account recovery matters more than the scan

    If an information stealer ran on your device, the most valuable losses have already happened. Saved browser passwords, authentication cookies and stored card details are packaged and sold within hours, often before any antivirus scan finishes. A stolen session cookie can let an attacker resume your logged-in session without needing your password or your second factor at all.

    That is why the order of operations matters. From a separate clean device, change the email password first, because email controls the reset of everything else. Then sign out of all sessions in each important account, regenerate recovery codes, and check that recovery phone numbers, forwarding rules and connected applications have not been altered. Only then move on to banking, cloud storage and social accounts.

    Keep a written list as you go. People routinely forget older accounts that share a reused password, and those accounts are exactly what attackers use later to rebuild access.

    Preventing reinfection

    Most repeat infections come from the same route as the first one. Pirated software and activation tools are the single most common source on home computers, followed by search advertisements impersonating popular downloads and by browser extensions that change ownership after installation. Download applications from the vendor's own site or an official store, and re-check the address rather than the advertisement.

    Keep automatic updates enabled for the operating system, browser and any security software, because unpatched browsers and plugins remain a reliable infection route. Use a standard user account rather than an administrator account for daily work, which limits what a careless click can install.

    Finally, build a backup you could actually restore from. Follow the principle of keeping at least two copies plus one that is offline or otherwise not writable by your everyday computer, then test a restore once. Ransomware negotiations mostly happen because a backup existed in theory but not in a usable, disconnected form.

    • Avoid cracked software and activators
    • Download from official sources only
    • Keep automatic updates enabled
    • Use a non-administrator daily account
    • Maintain one offline, tested backup

    Frequently asked questions

    Can one antivirus scan prove the device is clean?

    No. A clean result reduces concern but cannot prove absence. Persistent symptoms, privileged compromise or sensitive use may justify a reset or professional examination.

    Should I pay a ransomware demand?

    Payment does not guarantee recovery and can create legal or sanctions issues. Disconnect affected systems and contact qualified incident-response and law-enforcement resources.

    Does an iPhone need an antivirus scan?

    iOS restricts conventional system-wide scanning. Focus on updates, profiles, account security, malicious sites and restoring the device when compromise is credible.

    Is Microsoft Defender enough on its own?

    Defender provides a reasonable baseline and scores well in independent laboratory tests. A paid suite mainly adds stronger web and phishing filtering, ransomware controls and support, which matters most for shared family devices or anyone who downloads software frequently.

    Should I restore from a backup made before the infection?

    Usually yes, provided the backup predates the first symptoms and you restore documents rather than programs. Scan restored files afterwards and change account passwords regardless, because a stored credential may already be circulating.