Table of Contents
Malware is software or code designed to compromise a device, account, data, or network. It can steal credentials, encrypt files, spy on activity, display unwanted ads, abuse computing resources, or give an attacker remote control. Infection is not always obvious, so prevention and layered detection matter more than waiting for visible symptoms.

Common malware categories
| Type | What distinguishes it |
|---|---|
| Virus | Attaches to other files and spreads when the infected host runs. |
| Worm | Self-propagates, often by exploiting network or software weaknesses. |
| Trojan | Pretends to be legitimate software or content. |
| Ransomware | Encrypts or steals data and demands payment. |
| Spyware/infostealer | Collects activity, credentials, cookies, or financial data. |
| Rootkit | Hides malicious activity or provides privileged persistence. |
| Adware/PUP | Displays unwanted ads or changes settings; not every unwanted program is classified identically by vendors. |
Possible warning signs
- Security tools are disabled or updates fail unexpectedly.
- Unknown logins, password-reset messages, or new account rules appear.
- Files gain unfamiliar extensions or ransom notes appear.
- Browser settings, extensions, or search results change without consent.
- Unexplained processes, network traffic, pop-ups, or high resource use persist.
- Contacts receive messages you did not send.
Slow performance or crashes alone do not prove malware; hardware faults, full storage, updates, and ordinary software bugs can look similar.

How infections commonly begin
Frequent routes include phishing attachments and links, fake updates, cracked software, malicious ads, stolen remote-access credentials, compromised websites, unpatched vulnerabilities, and infected removable media. A VPN does not stop a user from installing malware or entering credentials on a phishing page.
What to do if you suspect malware
- Disconnect the device from networks if files are being encrypted, accounts are being used, or data theft appears active. Do not power off a business system if incident responders need volatile evidence unless safety requires it.
- Use a separate clean device to change important passwords, starting with email and identity-provider accounts. Revoke sessions and enable phishing-resistant MFA where available.
- Run trusted security scans. Update the installed security tool, run a full scan, and use its offline scan when persistent malware is suspected.
- Preserve evidence. Record alerts, filenames, times, ransom notes, and suspicious messages. Report workplace devices to IT immediately.
- Restore confidence. For confirmed high-impact or deeply persistent compromise, wiping and reinstalling from trusted media may be safer than trying to clean individual files.
Do not pay or communicate with an extortionist without involving appropriate legal, insurance, security, and law-enforcement contacts. Payment does not guarantee recovery or deletion.

Prevent malware
- Install operating-system, browser, app, router, and firmware security updates.
- Use built-in or reputable endpoint protection and keep the firewall enabled.
- Install software from official stores or publishers; avoid cracks and “driver updater” bundles.
- Use a password manager, unique passwords, and MFA.
- Limit administrator privileges and disable unused remote access.
- Keep offline or immutable backups and test restoration.
- Verify unexpected requests through a separate channel before opening files or signing in.
Backups that resist ransomware
A continuously connected drive or synced folder can be encrypted or have damaged files synchronized. Follow the 3-2-1 backup rule, keep at least one copy offline or protected from routine account access, and test that files can be restored.

Scan a Windows PC
Open Windows Security > Virus & threat protection > Scan options. Start with a Quick scan for routine checks, use Full scan when compromise is plausible, and use Microsoft Defender Offline for malware that may persist while Windows runs. Review detections before removing legitimate files and see how to scan with Microsoft Defender.
Phones and tablets
Mobile malware can abuse accessibility permissions, device administration, sideloaded apps, configuration profiles, or stolen accounts. Remove unknown apps and profiles, update the device, review permissions, and contact the platform or organization for managed devices. A factory reset may be appropriate for confirmed compromise, but secure the accounts first and avoid restoring the same malicious app.
Reader Comments 0
Sign in with email or Google to join the discussion.