Signs that you are actually infected
Not every slow computer is infected. Ageing hardware, a full disk, too many startup programs and browser extensions produce the same symptoms as malware, so it helps to look for signs that point specifically at unwanted software rather than general wear.
The strongest indicators are things that change without your involvement: a new homepage or default search engine, extensions you never installed, pop-ups outside the browser, security software that will not start, or friends receiving messages you did not send.
- Browser homepage, search engine or extensions changed on their own
- Advertising appears on the desktop or outside a browser window
- Security software, Task Manager or system updates refuse to run
- Unknown programs launch at startup or unfamiliar processes use the CPU
- Accounts send messages, or logins arrive from places you have never been
Step 1: contain the device before cleaning it
Disconnect from the internet if you suspect data theft or ransomware. That stops most malware from receiving instructions, exfiltrating files or spreading to other devices on the same network, and it costs you nothing.
Do not log into banking or email from the affected machine while you work. If you need to change a password, use a phone or another computer you trust. If files have been encrypted and a ransom note appeared, stop and photograph the note before anything else: the file extension and note text sometimes identify a family with a free decryptor.
Step 2: remove the malicious software
On Windows, boot into Safe Mode with Networking, uninstall anything you do not recognise that was installed around the time symptoms began, then run a full scan with a reputable security suite. A second opinion scanner from a different vendor is worth running afterwards, because engines disagree on borderline adware and bundled software.
On macOS, check Login Items and Profiles in System Settings, remove unfamiliar entries, delete suspicious applications and clear browser extensions before running a full scan. On Android, restart in safe mode, revoke accessibility and device-administrator permissions from any unfamiliar app and then uninstall it. On iPhone, true viruses are extremely rare: clear website data, remove configuration profiles and delete any app installed outside the App Store.
- Windows: Safe Mode, uninstall, full scan, second-opinion scan
- macOS: Login Items, Profiles, extensions, then a full scan
- Android: safe mode, revoke accessibility permissions, uninstall
- iPhone: clear site data, remove profiles, delete unknown apps
- Every platform: reboot and rescan to confirm the device is clean
Step 3: assume your accounts were exposed
Malware that ran with your privileges may have read saved passwords, session cookies and authentication codes. Cleaning the device does not invalidate the credentials it captured, so the recovery is only complete once the accounts are secured.
Change the passwords for email first, because email resets everything else, then banking, then any account reusing the same password. Sign out of all sessions where the option exists, turn on two-factor authentication using an authenticator app or passkey, and review the recovery email addresses and phone numbers on each account for entries you did not add.
When to stop and reinstall instead
Reinstalling the operating system is the reliable answer when scans keep finding the same threat, the machine cannot boot normally, the infection had administrator rights, or ransomware encrypted files. It is faster than several days of uncertain cleaning and leaves no doubt about the result.
Back up documents and photos to external storage first, but do not restore programs or system settings from that backup. Scan the copied files before opening them, and reinstall applications from their official sources afterwards.
Stopping the next infection
Most home infections arrive through three routes: a pirated or cracked download, a fake update or codec prompt on a streaming site, and an attachment or link in a message that creates urgency. Removing those three habits eliminates the large majority of real-world risk.
Keep automatic updates on for the operating system and browser, use a standard rather than administrator account for daily work, install one real-time security product rather than several, and keep a backup you have tested by restoring a single file from it.
