First: How Serious Is It?
Not every pop-up or slow computer means you have malware. But if your antivirus found something, or you're seeing classic malware symptoms (browser redirects, pop-ups you can't close, disabled antivirus, or unexplained account activity), take it seriously and act quickly.
Step 1: Disconnect from the Internet
The moment you suspect active malware, disconnect from Wi-Fi or unplug the ethernet cable. This stops malware from:
- Sending your data to an attacker
- Downloading additional malicious software
- Spreading to other devices on your network
- Receiving commands from a remote controller
You can stay disconnected while running your antivirus scan, since most scanners don't need internet access to work.
Step 2: Don't Use the Computer for Sensitive Tasks
Until your computer is confirmed clean, avoid:
- Online banking or financial accounts
- Work email or company systems
- Entering passwords or payment information
- Accessing cloud storage with sensitive files
Use your phone or a separate device for urgent tasks in the meantime.
Step 3: Run a Full Antivirus Scan
Don't just run a quick scan. Run a full system scan. This takes longer (30–90 minutes) but checks every file.
Recommended tools
- Windows Defender: Built into Windows 10 and 11. Go to Windows Security → Virus & threat protection → Scan options → Full scan.
- Malwarebytes Free: Excellent at catching malware that Defender misses. Run it alongside Defender, since they don't conflict.
- Malwarebytes AdwCleaner: Specifically targets adware and browser hijackers.
What to do with what it finds
Follow the scanner's recommendations to quarantine or remove threats. After removal, restart the computer and run the scan again to confirm nothing remained.
Step 4: Change Your Passwords From a Different Device
If malware was on your computer, assume your passwords may have been captured by a keylogger. Change passwords for your most sensitive accounts from your phone or a known-clean computer, not from the infected machine.
Priority order for password changes
- Email: Attackers use this to reset every other account.
- Banking and financial accounts
- Password manager (if you use one)
- Work or business accounts
- Any account where you saved payment info
See our password security guide for tips on creating strong replacements.
Step 5: Review Accounts for Unauthorized Access
After changing passwords, check your account activity:
- Email: Review sent items, filters, forwarding rules, and connected apps. Attackers often set up forwarding to silently receive copies of your email.
- Bank and credit cards: Look for unfamiliar transactions from the past 30 days.
- Social media: Check connected apps and recent login locations.
- Apple ID / Google Account: Check what devices are logged in and remove any you don't recognize.
Step 6: Enable Two-Factor Authentication
Once you've secured your accounts, add two-factor authentication (2FA) to all of them. Even if an attacker knows your new password, they can't log in without the second factor. See our security guide for setup instructions.
Step 7: Restore from Backup if Needed
If malware has encrypted your files (ransomware) or corrupted important documents, your best recovery option is restoring from a backup. This is why we always recommend maintaining current backups. See our backup guide for how to set one up.
If you don't have a backup
Professional data recovery may be able to help in some ransomware cases, though it's not guaranteed and can be expensive. Don't pay the ransom, because it doesn't guarantee file recovery and encourages further attacks.
Step 8: Prevent It From Happening Again
Most malware infections are preventable. After cleaning up, take these steps:
- Keep Windows and macOS updated: Security patches close vulnerabilities that malware exploits.
- Update your browser: Chrome, Firefox, and Edge release security updates frequently.
- Be cautious with email attachments: Don't open attachments from unknown senders. Verify unexpected attachments even from known contacts.
- Avoid suspicious downloads: Only download software from official websites or trusted sources like the Microsoft Store or App Store.
- Use a password manager: Reduces reuse and helps you spot phishing sites that mimic legitimate ones.
- Set up regular backups: So the next incident, whatever it is, doesn't cost you your data.
When to Call a Professional
Some malware is designed to survive removal attempts, hiding in system files or firmware. If your computer is still behaving strangely after running scans and removing threats, or if you're not comfortable doing these steps yourself, professional help is the right call.
Professional virus and malware removal can assess the device, remove detected unwanted software, and recommend protections to reduce repeat problems. Timing depends on the symptoms and current availability.