Skip to content

How to respond to a suspected malware infection

Short answer. Disconnect that computer from the network immediately, and leave it powered on. Disconnecting limits the spread, which is the thing you can still control. Do not turn it off: shutting down can destroy evidence and, with ransomware, can make recovery harder. Then change passwords from a different device, not the affected one.

The first ten minutes

What you do in the first few minutes matters more than anything afterwards. The aim is containment, not diagnosis. You are trying to stop it reaching the other machines and the shared drives.

  1. 1Unplug the network cable and switch off Wi-Fi on that machine.
  2. 2Leave it powered on. This is the step people get wrong: instinct says shut it down, and that instinct destroys information and can worsen a ransomware outcome.
  3. 3Do not log in to anything else from that computer.
  4. 4From a different device, change passwords for email first, then banking. Email is how every other password gets reset.
  5. 5Tell whoever handles IT, and say honestly what was clicked. Nobody is going to be cross, and it narrows the search enormously.

What not to do

  1. 1Do not plug a USB drive into it to rescue files. That is how the infection reaches the next machine.
  2. 2Do not run three different cleanup tools you found by searching. Some of the top results for malware removal are themselves malware.
  3. 3Do not pay a ransom demand before speaking to someone. Payment often produces nothing, and it marks the business as willing to pay.
  4. 4Do not call a phone number that the warning message itself displays. That is the scam, not the rescue.

Telling a real infection from a fake warning

A large share of "your computer is infected" alerts are browser pop-ups pretending to be system warnings. They are loud, they use countdown timers, and they always show a phone number. A genuine antivirus alert comes from software you installed, appears in the system notification area, and never asks you to ring anyone.

  1. 1If it is a full-screen page in a browser, close the browser. Use Task Manager if it will not close normally.
  2. 2If it shows a support phone number, it is a scam, without exception.
  3. 3If it appeared after downloading something, treat it as real and disconnect.
  4. 4If files are renamed, encrypted, or will not open, treat it as ransomware and disconnect immediately.

Afterwards, once it is contained

Cleanup is the beginning, not the end. The questions worth answering are how it arrived and what else it reached, because otherwise the same thing happens again next month.

  1. 1Have the machine examined before it goes back on the network.
  2. 2Check whether shared drives or cloud storage were touched.
  3. 3Check whether email rules were added. Attackers often create a hidden forwarding rule so they keep receiving mail after being removed.
  4. 4Turn on multi-factor authentication if it is not already on, because a stolen password is usually the entry point.
  5. 5Test a restore from backup. Discovering that backups do not work during an incident is the worst possible time.

When to stop and call someone

  • Files have been encrypted or renamed, or there is a ransom message
  • More than one computer is affected
  • The machine holds customer, financial or regulated data
  • You found an email forwarding rule nobody created
  • It appears cleaned, but you cannot say how it got in — that is not finished

Want this handled for you?

A technician can look at it directly. First session is $49, up to 45 minutes, and we confirm the scope and price before any work starts.