What are the genuine symptoms?
Not every computer that slows down has a virus; slowness has far more common causes, and we have gathered them in in a separate guide . The symptoms specific to malicious software, on the other hand, are more distinct:
Browser changes
The home page or search engine has changed by itself and returns after you remove it.
Unexpected adverts
Pop-up windows on sites that carry no advertising, notifications appearing on the desktop.
Programs you do not recognise
Applications you did not install, browser extensions you did not add.
Constant disk and network activity
The hard drive working and consuming data while you are not doing anything.
There are also more serious symptoms: the antivirus program shutting down by itself or failing to open, Task Manager being blocked, file extensions changing en masse, and password reset notifications arriving from accounts you do not recognise. The last item is particularly important; it is a direct sign that your information has leaked out.
Ransomware: the first moves are critical
If the extension of your files has changed, they will not open and there is a message on the screen demanding payment, this is ransomware. In this situation the first actions you take determine the outcome:
- Disconnect the device from the network. Unplug the Ethernet cable and switch Wi-Fi off. Ransomware spreads to other devices on the network and to connected storage units. This is the most urgent step.
- Disconnect external drives. If your backup disk is connected, disconnect it immediately; if it has not been encrypted, it can still be saved.
- Do not shut down and do not restart. With some types, the encryption key may be present in the memory; shutting down eliminates this possibility.
- Do not pay. There is no guarantee of regaining the files, and paying feeds this ecosystem.
- Do not rename the files and do not try random decryption tools; the wrong tool can cause permanent damage.
Keep a screenshot of the ransom note and a sample of an encrypted file; these are needed in order to identify the type of the malicious software. For some families, free decryption tools published by security companies are available.
Safe cleaning sequence
1. Disconnect from the network
Disconnecting the device from the network before starting the clean-up prevents the malware from communicating with the outside and from downloading additional components.
2. Change your passwords from another device
Carry out this step before cleaning and be sure to use a clean deviceChanging a password from an infected computer means giving away the new password as well. The order of priority is: e-mail, banking, social media.
3. Run a scan in safe mode
When you start Windows in safe mode, only the basic components are loaded; this makes it harder for the malware to protect itself. A full system scan works more effectively in this mode.
4. Review the installed programs
Sort the Settings → Apps list by installation date. Applications you do not recognise that were installed around the date the problem began are strong candidates. Additional software installed unintentionally while downloading free programs comes to light this way.
5. Clean up your browser extensions
In browser-related problems the actual source is usually extensions. Remove all extensions you do not recognise and reset the browser settings. Make sure that the home page and search engine settings do not revert.
6. Check the shortcuts
A frequently used method is adding an extra address to the target of the browser shortcut. Right-click the shortcut and look at its properties; if there is a web address after the program path on the target line, delete it. This is one of the common reasons why the problem returns after cleaning.
7. Review the programs that run at start-up
Disable the entries you do not recognise on the start-up tab of Task Manager. Most malware settles here in order to persist.
When is cleaning not enough?
A clean installation is recommended in the following cases: if the malicious software has obtained administrator rights, if a type that steals banking or password information has been identified, if the symptoms return after cleaning, or if there is corruption in the system files.
If you decide to format, the backup items that are easily overlooked in our pre-formatting guide . An important warning: scan the files you have backed up before transferring them to the new system, otherwise you may carry the malware back over.
Practical ways to protect yourself
- Do not postpone updates. Most malware exploits vulnerabilities that have already been closed; an up-to-date system is the most effective protection.
- Download software from its original source. Websites offering "free downloads" are the main distribution channel for unwanted software.
- Use a single antivirus program. A second real-time protection does not increase security; it creates conflicts.
- Be careful with email attachments. Invoices and shipping notifications that you were not expecting are the most common bait. Do genuinely check the sender's address.
- Enable two-step verification. It blocks access to your account even if your password is stolen.
- Back up regularly. This is the only real insurance against ransomware. Do not keep the backup permanently connected; a connected disk is encrypted as well.
On the corporate side
In businesses, protecting a single device is not sufficient; filtering at network level, centrally managed endpoint protection and a regular backup policy must be designed together. In ransomware cases, what determines the loss of business is most often how up to date the backup is.
In our service, when removing malicious software we first analyse the system, secure your data and decide between cleaning and reformatting on the basis of the findings. In corporate environments we also plan the firewall and backup configuration together.