Computer Viruses and Malware: Recognize, Respond, and Recover - Yenra

Distinguish malware symptoms from evidence, choose an appropriate response, and verify recovery on Windows or macOS.

A navy laptop beside an amber warning symbol in a glass inspection cube, a detached cable and an ivory backup drive.
Conceptual diagnostic workspace: contain the problem, preserve useful information and verify recovery.

Malware is software used to cause harm or gain unauthorized access. A computer virus is one type that spreads by infecting other code or files. An unexpected pop-up, slow computer or security alert deserves investigation, but each points to a different next step.

Use this guide for computers you own or administer. For a work device, suspected ransomware, sensitive-data exposure or several affected machines, contact the designated incident responder before cleanup. Cleaning or resetting a machine can remove information needed to understand the incident.

Match the evidence to the first action

Common situations and first steps
ObservationWhat it establishesFirst useful action
A webpage says the computer is infected and gives a phone numberThe page is displaying a claim.Close the page without calling or installing anything; open the actual security app independently.
A security app identifies a threatThe scanner detected something under its current rules.Record the detection, file and action; check whether it was blocked, quarantined or allowed.
Files change unexpectedly or a ransom note appearsThere may be an active incident affecting data.Disconnect the affected device from networks and contact the responder from a separate trusted device.
An account has unfamiliar activityThe account may be compromised, with or without local malware.Secure it from a trusted device and review sessions, recovery and forwarding settings.
The computer is slow or crashesThere is a symptom with several possible causes.Record when it happens; review storage, updates and security results before choosing a remedy.

A browser notification may persist because a site has notification permission. Removing that permission and scanning through the real security app is more useful than following the alert's sales pitch. The FTC's tech-support scam guidance explains why unexpected support warnings deserve an independent check.

Contain an apparent active incident

Disconnect Wi-Fi and wired networking on the affected machine to reduce communication and spread. Keep backup drives disconnected and avoid attaching them for an improvised rescue. Use another trusted device or phone to contact help and record the time, symptoms and recent actions.

The CISA-led ransomware response guide prioritizes isolation and preserving evidence. It treats power-down as a fallback when network disconnection is impossible because shutdown loses volatile evidence. Follow your responder's instructions for a business incident; avoid experimenting with removal tools or deleting files before they assess the system.

Record the visible message or detection name without opening more suspicious content. Note affected accounts and shared storage. A ransom note or scanner result is a starting point for investigation; it does not establish that every affected file or account has been found.

Windows: use the actual protection interface

For an ordinary personal-device investigation, open Windows Security from Windows itself and choose Virus & threat protection. Check which antivirus provider is active. Update its security intelligence, run the appropriate scan and review the recorded actions. When another provider manages protection, use its supported procedure.

Microsoft documents quick, full, custom and offline scans. A full scan covers the device more broadly than a quick scan. Microsoft Defender Offline restarts into the Windows Recovery Environment; save work first and have any required device-recovery information available. Read the result after Windows returns.

Inspect Protection History and resolve allowed threats only through the documented controls. If the same detection returns, protection is disabled unexpectedly or the machine remains unreliable, stop repeating scans and seek qualified help or a supported clean reinstall. Verify the support status of the installed Windows edition and update channel as part of recovery.

macOS: preserve its built-in protections

Install supported macOS and security updates, and inspect any warning through the operating system. Avoid overriding an untrusted-app warning simply to make a downloaded program run. Review unexpected login items, browser extensions and notification permissions, recording changes you make.

Apple describes Gatekeeper, notarization and XProtect as layers for preventing, detecting and remediating malware. Their presence reduces risk while leaving a need to investigate persistent symptoms. macOS does not use the Windows Security scan workflow.

If an untrusted program executed, remote-control access was granted or problems persist, contact Apple support or a qualified responder through a channel you find independently. On a managed Mac, let the administrator inspect device management and security tooling before removing it.

Recover the device and the accounts

  1. Establish a trustworthy system. Follow the security provider's remediation or the manufacturer's clean-reinstallation process. Preserve needed incident evidence before erasure.
  2. Secure exposed accounts from a trusted device. Change exposed or reused passwords, revoke unauthorized sessions, and review recovery methods and mailbox rules.
  3. Restore from a suitable backup. Choose a known-good point, inspect the data and reinstall applications from trusted sources. Avoid restoring the suspicious installer or automatically recreating the same unwanted setup.
  4. Verify normal operation. Check updates, active protection, scan results, restored files and important account activity. Keep watching for recurrence.
  5. Close the entry point. Address the unsafe download, exposed remote access, compromised credential or missing update that the investigation identified.

Older outbreaks as historical reading

Worm outbreaks illustrate why exposed services, patching and network controls matter. The historical articles below retain their original-era product and threat context; use current official guidance for present-day remediation.

For the everyday next steps, use the spam and phishing guide and account authentication guide. The incident record below helps capture observations and actions without placing passwords or recovery codes in a troubleshooting note.

Related security guides