ο»Ώ

How to Recover From a Malware Infection

A calm, step-by-step recovery guide for suspected malware on personal devices: confirm, contain, clean or rebuild, secure accounts, restore safely, and harden afterward.

Updated July 2026Reviewed by Editorial TeamEditorial review

If you think malware is on your computer or phone, you need a clear recovery path β€” not panic, and not a random "cleaner" from a pop-up. This guide walks you through confirming the problem, limiting damage, cleaning or rebuilding the device, securing accounts and sessions, restoring files safely, and reducing the chance of getting reinfected.

This is for everyday personal devices. It is not an enterprise incident-response playbook.

Related situations (different guides):

This guide is for device infections

Why: Malware recovery is about a device that may already be compromised β€” not only about a bad click, and not only about ransomware.

Do:

  • Use this guide when antivirus reports an infection, the device behaves in clearly abnormal ways, or you installed something you no longer trust.
  • Treat ransomware (locked/encrypted files + payment demand) as a branch: contain here if needed, then follow the ransomware guide for payment, decryptors, and encryption-specific recovery.
  • Treat "I only clicked a link" without infection signs as a phishing-recovery problem first.

Avoid:

  • Assuming every slow computer is malware.
  • Buying tools or calling numbers from scareware pop-ups.
  • Skipping ahead to wipe everything before you know what you are dealing with β€” unless the device is a managed work/school device (see below).

Next: Confirm whether infection is likely.

Confirm it is likely malware

Why: Fake alerts and scam phone calls often invent infections to trick you into paying or giving remote access.

Do:

  • If your antivirus or Windows Security already reports a threat, treat that as a strong signal and continue.
  • On a PC or laptop without a clear alert, run a full antivirus scan with software you already trust (or Windows Security on Windows).
  • Watch for common warning signs described by consumer guidance such as the UK National Cyber Security Centre (NCSC): unexpected pop-ups, programs opening or closing on their own, frequent unexplained restarts, or friends receiving odd messages from your accounts.
  • If someone calls claiming to be Microsoft, Apple, your ISP, or "Windows support" and says your device is infected, hang up. That pattern is a common scam. Do not give remote access or pay them.
  • Use a short triage lens β€” you do not need to name the exact malware family to act:

- Adware / browser hijack: unwanted toolbars, search redirects, or pop-ups that push installs or "support" numbers β€” annoying, but still worth cleaning; can hide worse problems. - Trojan / unwanted app: something you installed (or that appeared) that you do not recognize, often bundled with downloads or fake updates. - Spyware / infostealer: signs that passwords, banking, or session cookies may have been captured β€” prioritize account and session hardening even while you clean the device. - Ransomware handoff: files suddenly encrypted or unreadable plus a payment demand β€” contain here if needed, then switch to the ransomware guide for the encryption-specific path.

Avoid:

  • Downloading a "fixer" recommended by a pop-up or cold caller.
  • Assuming Macs or iPhones cannot be affected by malware or malicious configuration. The recovery steps differ by platform, but the risk is not zero.
  • Turning this section into a malware encyclopedia β€” confirm likelihood, then move to containment.

Next: If infection looks likely, contain the damage. If the main issue is encrypted files and a ransom note, switch to the ransomware guide after basic containment.

Contain the problem now

Why: Active malware can spread to other devices, shared drives, or cloud-synced folders while you are still deciding what to do.

Do:

  • Stop interacting with attackers, pop-up "support" numbers, and any remote-access requests.
  • If the device is actively misbehaving (unexpected remote control, rapid file changes, repeated malicious prompts), disconnect Wi-Fi or unplug ethernet. This limits spread; it does not remove malware by itself.
  • If cloud sync (OneDrive, Google Drive, iCloud Drive, and similar) seems to be pushing unwanted or locked files, pause sync until the device is cleaned or rebuilt.
  • On a phone, stop installing new apps and avoid entering passwords until you know whether a reset is needed.

Avoid:

  • Believing that disconnecting from the internet "cures" the infection.
  • Plugging the same USB drives into other computers while the situation is unclear.

Next: Check whether this is a personal device you can remediate yourself.

Personal device or work/school device?

Why: Managed devices often have policies, monitoring, and recovery paths you should not bypass.

Do:

  • If this is a work or school laptop/phone, contact IT or security immediately. Tell them what you saw (antivirus alerts, ransom note, odd behavior). Preserve screenshots if you can do so safely.
  • Follow their instructions instead of self-remediating against policy.
  • If this is your personal device, continue with the steps below.

Avoid:

  • Hiding the incident from IT on a managed device.
  • Running random cleanup tools that your organization has not approved.

Next (personal devices): Preserve a little evidence, then clean or rebuild.

Keep useful evidence before you wipe

Why: A factory reset or reinstall can erase details that help you report fraud or understand what was detected.

Do (lightweight):

  • Screenshot antivirus detections or Windows Security protection history.
  • Note odd file names, extensions, or messages β€” without repeatedly opening unknown executables.
  • Save bank or fraud emails related to the incident.
  • If a ransom note is present, photograph or copy the text for specialists/authorities, then use the ransomware guide for the encryption-specific path.

Avoid:

  • Treating home users as if they must create full forensic disk images.
  • Delaying urgent containment forever "to collect more evidence."

Next: Choose cleanup versus reinstall/reset.

Clean, reinstall, or factory reset

Why: Some infections can be removed by trusted scanning tools; others persist until you rebuild the device. No consumer scan can honestly promise that a device is 100% clean.

Windows PC or laptop

  1. Update Windows and your antivirus definitions.
  2. Run a full scan in Windows Security (Virus & threat protection) or your existing reputable antivirus, then follow its quarantine/removal actions.
  3. If problems continue, run Microsoft Defender Offline scan from Windows Security scan options. This restarts the PC and scans outside a normal Windows session β€” useful when malware tries to hide while Windows is running. Save open work first.
  4. Microsoft's Malicious Software Removal Tool (MSRT) can help with some prevalent families, but it is not a replacement for full antivirus protection.
  5. If trusted tools cannot clean the device, or infection keeps returning, back up personal files carefully (see file recovery below), then reinstall Windows from official media / recovery, or reset the PC and reinstall apps from trusted sources only.

macOS

  1. Update macOS to the latest version your Mac supports (System Settings β†’ General β†’ Software Update). Updated security fixes matter before and after cleanup.
  2. Remove unknown items: delete recently installed apps you do not recognize; remove unfamiliar login items (System Settings β†’ General β†’ Login Items); remove unknown browser extensions and reset the browser profile if it was hijacked.
  3. Check configuration profiles: in System Settings β†’ Privacy & Security (or Profiles, depending on your macOS version), review and remove configuration profiles you did not install intentionally β€” especially if a download or "support" session added them.
  4. Reassess trust: if the Mac still shows pop-ups, redirects, unexpected remote-control behavior, or you cannot account for what was installed, assume the system may still be compromised even after partial cleanup.
  5. Erase and reinstall via Apple's official recovery: if problems persist or you cannot trust the system, back up personal files carefully (see file recovery below), then erase the Mac and reinstall macOS using Apple's official recovery process (restart and hold the appropriate key combination for your Mac model until recovery options appear β€” Apple documents the current steps for your hardware).
  6. After rebuild: reinstall apps only from trusted sources; restore personal data from a known-good backup made before the infection when possible; run Software Update again before heavy use.

Uncertainty note: Apple menu labels and recovery key combinations change between macOS versions and Mac models. Follow Apple's current support documentation for your device rather than memorizing exact button names from this guide.

Android phone or tablet

Antivirus apps do not work the same way as on PCs. Consumer guidance from the NCSC treats a factory reset as the safest typical fix when a phone or tablet is infected. After reset, restore apps from official stores only, and be cautious restoring backups that may include the bad app or profile.

iPhone or iPad

  1. Update iOS or iPadOS (Settings β†’ General β†’ Software Update). Install the latest update your device supports.
  2. Remove unknown configuration profiles: Settings β†’ General β†’ VPN & Device Management (wording may vary). Delete profiles you did not install through work/school or a service you trust.
  3. Review installed apps: remove apps you do not recognize or that appeared after a suspicious download, profile, or "support" session. Check Settings β†’ Apps (or the home screen) for anything unfamiliar.
  4. Check Apple ID security: on a second device you trust, sign in at appleid.apple.com and review devices, trusted phone numbers, and recent account activity. Change your Apple ID password if the compromised device may have seen it.
  5. Erase all content and settings if unwanted profiles, persistent pop-ups, or suspicious apps remain: Settings β†’ General β†’ Transfer or Reset β†’ Erase All Content and Settings (exact path may vary by iOS version). Set up as new, or restore from a backup made before the problem β€” not from a backup you suspect includes the bad profile or app.
  6. Prefer Apple support over third-party cleaners: Apple's official erase and setup guidance is the consumer-safe path. Avoid "iPhone cleaner" apps promoted in ads or scare pages β€” they rarely fix root compromise and may add risk.

Uncertainty note: Settings menu names shift between iOS/iPadOS versions. If a label here does not match your screen, use Apple's support site for your exact version rather than hunting for unofficial tools.

Avoid:

  • Installing multiple unknown "optimizer" or "cleaner" apps.
  • Restoring a full system image taken while the device was infected and assuming it is safe.

Next: Secure accounts β€” malware removal does not automatically end stolen logins or sessions.

Secure passwords, sessions, and cookies

Why: Infostealers and other malware can capture passwords and browser session cookies. Stolen "remember this device" cookies can sometimes let attackers into accounts without your password or MFA prompt.

Do:

  • Prefer a second device you trust (or a cleaned/rebuilt device) to change passwords.
  • Prioritize: email, Apple/Google/Microsoft account, banking, password manager master password, shopping accounts, and any work logins stored on the personal device.
  • Turn on or confirm multi-factor authentication (MFA). MFA still helps, but it is not perfect against stolen session cookies.
  • Sign out other sessions / remove unknown devices in account security settings where available.
  • Clear browser cookies and site data for important sites, or reset the browser profile after the device is clean.
  • Check recent login history for locations or devices you do not recognize.

Avoid:

  • Changing all your passwords on a device you still believe is infected, if you have any alternative.
  • Assuming "I have MFA, so cookie theft cannot matter."

Next: Check whether accounts or money were already abused.

Check accounts and money

Why: Cleanup fixes the device; it does not undo actions attackers already took.

Do:

  • Review email forwarding rules, recovery email/phone numbers, and third-party app access (OAuth grants).
  • Check banking and card accounts for unfamiliar charges; contact your bank or card issuer immediately if you see unauthorized payments.
  • If you suspect identity theft (new credit accounts, tax issues, or clear misuse of personal data), use official consumer recovery paths such as IdentityTheft.gov in the United States.

Avoid:

  • Waiting "to see if it happens again" when money has already moved.
  • Assuming a clean scan means no account abuse occurred.

Next: Restore files only after the device path is clean or rebuilt.

Recover files without reinfecting

Why: Restoring from a dirty backup can bring malware back.

Do:

  • Restore personal documents from a last known good backup β€” one made before the infection when possible.
  • Prefer offline or versioned backups. After a rebuild, scan restored installers and unusual executables before opening them.
  • If cloud files were encrypted by ransomware, pause sync, clean devices first, then use version history where available β€” and follow the ransomware guide for encryption-specific recovery.
  • Accept that files never backed up may be gone.

Avoid:

  • Copying every file from the infected disk onto a clean PC without sorting out programs and unknown executables.
  • Paying a ransom as a "file recovery plan" (see the ransomware guide for that decision).

Next: Know when to escalate beyond DIY.

Get help and report when needed

Why: Some situations are unsafe or impractical to finish alone.

Do seek expert or organizational help when:

  • You cannot install or run antivirus because the browser or system is blocked (NCSC notes this as a cue for expert help).
  • Infection returns after reasonable cleanup attempts.
  • The device is managed by work or school.
  • You are not comfortable reinstalling an operating system.

Do contact banks / authorities when:

  • Money was stolen or accounts show fraud β€” tell your bank or card issuer right away.
  • In the UK, report fraud through the channels recommended for consumers (for example Report Fraud / Action Fraud guidance as applicable in your nation).
  • In the US, report cybercrime through IC3 when appropriate, and use IdentityTheft.gov for identity-theft recovery planning.
  • Preserve notes and screenshots when you report.

Avoid:

  • Hiring whoever appears in a scareware pop-up or unsolicited call.
  • Sending cryptocurrency or gift cards to anyone promising remote cleanup.

Next: Reduce the chance of a repeat infection.

Reduce the chance of reinfection

Why: Cleanup without aftercare leaves the same door open.

Do:

  • Keep the operating system, browsers, and apps updated.
  • On PCs and laptops, keep antivirus protection on and updating.
  • Maintain backups you can actually restore.
  • Use device encryption where your platform offers it.
  • Revisit how the infection started β€” cracked software, malicious email attachment, fake installer β€” and close that habit. If a deceptive message started this, read the phishing recovery guide for prevention habits around links and logins.

Avoid:

  • Turning off security tools "for performance" right after an infection.
  • Restoring the exact untrusted program that started the problem.

Next: Check the FAQ if you still have an edge-case question.

FAQ

Antivirus found something, but the PC seems fine. Should I still act?

Yes. A detection is a strong reason to quarantine/remove the threat, update the system, and review accounts β€” especially email and banking.

Can I change passwords on the infected computer?

Only if you have no safer option. Prefer a clean phone, tablet, or another computer. If you must use the infected device, change critical passwords again later from a clean device and revoke sessions.

Do I need to wipe after Microsoft Defender Offline removes malware?

Not always. If Offline scan cleaned the threat and the device behaves normally, continue with account/session hardening and monitoring. If problems return, escalate to reinstall/reset.

My phone is full of pop-ups. Do I need antivirus or a reset?

For phones and tablets, consumer guidance generally favors a factory reset over relying on "mobile antivirus" the way you would on a PC. Afterward, reinstall only from official app stores.

Will disconnecting Wi-Fi delete malware?

No. It can reduce spread and remote abuse while you prepare cleanup. You still need to clean or rebuild.

My backup drive was plugged in while I was infected. Is it safe?

Treat it as risky. Prefer restoring documents from versions or backups known to predate the infection, and avoid restoring unknown programs from that drive onto a clean system without scanning and careful selection.

Is adware as serious as an infostealer?

Adware can be "only" annoying, but it can coexist with worse malware, and browser hijacks still deserve cleanup. If passwords or banking may have been exposed, still rotate credentials and review sessions.

Closing next steps

Work this list in order:

  1. Confirm infection vs scareware/scam call.
  2. Contain (disconnect if needed; pause risky sync; stop attacker contact).
  3. Escalate work/school devices to IT.
  4. Save light evidence (screenshots/notes).
  5. Clean with trusted tools β€” or reinstall / factory reset when cleanup fails.
  6. Change important passwords from a clean device; revoke sessions; clear critical cookies.
  7. Check accounts and money; report fraud if needed.
  8. Restore files only from known-good backups.
  9. Update, back up, and close the original entry path.

If this was ransomware encryption, continue with What to Do If You Get Ransomware. If it started with a deceptive link or login page, use What to Do If You Clicked a Phishing Link.

Sources

SourceRole in this draft
NCSC β€” How to recover an infected deviceConfirmation cues; PC scan vs wipe; phone/tablet factory reset; last-known-good backup; tech-support call scam; aftercare
Microsoft Windows Security / Defender OfflineWindows scan options and offline scan behavior
Microsoft Malicious Software Removal Tool notesSupplemental tool; not full AV replacement
CISA StopRansomware / isolation-restore principlesContainment and clean-before-restore ideas, translated for household wording
FBI public warning on cookie theft bypassing MFASession/cookie risk after compromise
FTC IdentityTheft.gov / identity recovery guidanceUS identity-theft and password/account recovery paths
Apple platform support (macOS recovery, iOS/iPadOS erase and profile management)macOS ordered cleanup/reinstall path; iPhone/iPad profile removal and erase guidance; UI labels version-dependent
StaySecureHub ransomware & phishing recovery articlesInternal handoffs for specialized scenarios
Sandro C.

Sandro C.

Verified Expert

Founder & Cybersecurity Researcher at StaySecureHub

At StaySecureHub, he tests and compares services based on security, performance, and transparency, helping users make informed decisions to protect their online lives.