Most malware today is built to stay quiet. A program that steals saved passwords, quietly rents out your internet connection or waits to encrypt your files does better when you never notice it. That makes the warning signs subtle, and it means many of the classic symptoms, such as a slow laptop, have perfectly innocent explanations too. This guide sets out the signs that official security agencies actually list, how to tell a real warning from an ordinary glitch or a scam, and exactly what to do, in order, if you think a computer or phone has been compromised.
Why infections are harder to spot than they used to be
Older viruses announced themselves by crashing machines or deleting files. Today's criminals are mostly after money, and money comes from access: your email, your bank login, your browser's saved sessions, your files held for ransom, or your device's internet connection resold to other criminals. A US investigation into one criminal proxy network, known as 911 S5, found that free VPN apps carrying a hidden backdoor had turned victims' Windows computers into relays for other people's crimes; the FBI says the network had over 19 million compromised IP addresses in more than 190 countries. Most of those owners would have seen nothing unusual at all.
The practical lesson is that the absence of symptoms proves little, and the presence of one symptom proves little either. Look for patterns, and treat some signs as far more serious than others.
The warning signs, ranked by how much they should worry you
Strong signs: act now
- Your security software reports a detection it could not remove, or ransomware has displayed a payment demand. The UK National Cyber Security Centre (NCSC) treats these as definitive.
- Messages you did not send: the US Federal Trade Commission (FTC) lists "emails you didn't write or social media messages you didn't post" as a sign of malware, and the NCSC gives the same sign for a hacked account. Friends asking about an odd message from you deserve a quick check.
- Security tools switched off: the FTC flags operating system tools such as Task Manager or Activity Monitor being disabled. Antivirus or automatic updates turning themselves off without your doing is a similar red flag.
- Account changes you did not make: the NCSC lists changed security settings, logins from strange places or unusual times, and purchases you do not recognise.
- A phone reporting it is "rooted" or "jailbroken" when you never did that yourself, another sign on the NCSC's list.
Moderate signs: investigate
- Your browser's home page or search engine changed, or you are redirected to sites you did not ask for.
- New toolbars, extensions or programs you do not remember installing.
- Pop-up adverts in unexpected places, including on sites that do not normally carry them, or ads appearing outside the browser.
Weak signs on their own
- Slowness, freezing, crashes or repeated error messages. Both the FTC and the NCSC include these, but failing storage, a full disk, an overdue update or too many startup programs cause the same symptoms far more often. Treat them as a reason to look, not a diagnosis.
- Unusually high data use or a hot, busy device at idle. Background mining or proxy software can cause this, but so can cloud sync and backups.
The fake warning that is not a sign at all
One "symptom" is itself the attack. A browser page or phone call claiming your computer is infected, often with a flashing warning, an alarm sound and a support number, is a tech support scam. The FTC explains how it works: the scammer asks for remote access, runs fake diagnostics, then charges for repairs you never needed, and its advice is simple: "Never call a phone number that appears in a pop-up window." The NCSC likewise says calls claiming your device is infected and demanding payment are scams, and that you should hang up. Close the browser tab (force-quit the browser if it will not close), and if you did give someone remote access or card details, treat the device as compromised and call your bank.
How to check a Windows PC, a Mac or a phone
Windows
- Open Task Manager (Ctrl+Shift+Esc) and sort by CPU, memory and network. Look up any unfamiliar process name from a trustworthy source before killing it, because many legitimate Windows processes have odd names.
- Check Settings, Apps for programs you did not install, and your browser's extensions page for add-ons you do not recognise.
- Open Windows Security, Virus & threat protection and run a full scan. If you suspect something persistent, Microsoft recommends the Microsoft Defender Offline scan, which restarts the PC and scans "without loading Windows, so any persistent malware has a more difficult time hiding or defending itself."
Mac
Use Activity Monitor to look for unfamiliar processes using heavy CPU or network, review your Login Items in System Settings, and check browser extensions. macOS's built-in XProtect checks for known malware and, according to Apple, can remediate malware that has already run, with signature updates delivered separately from system updates.
Android and iPhone
Review installed apps and remove anything you do not recognise or no longer use, check which apps have accessibility, device administrator or VPN permissions, and on Android run a Play Protect scan. The NCSC notes that phones and tablets "can't usually be fixed by an antivirus product in the same way as PCs and laptops", and that a factory reset is the safest fix for a phone you believe is infected.
What to do if you think you are infected
Order matters. Fixing your passwords on a machine that is still infected may simply hand the new ones to the attacker.
- Stop using the device for anything sensitive. The FTC's first step is to stop logging in to accounts that involve personal information or money.
- Disconnect it from the network if you suspect ransomware or active data theft, to limit what can be sent out or spread to other devices.
- From a different, clean device, secure your most important accounts. Start with email, because email can reset everything else, then banking. Change the passwords, turn on two-step verification, and sign out all other sessions. The NCSC also advises checking your email filters and forwarding rules, because criminals often add a rule that copies your mail, including password reset links, to themselves.
- Update and scan the infected device. On a PC, the NCSC's sequence is to update the device and its programs, run your antivirus, and follow its advice. Run an offline scan if one is available.
- If the scan cannot clean it, wipe and reinstall. For a PC, that means reinstalling the operating system from a trusted source; for a phone, a factory reset. It is slower but it is the only certain cure.
- Restore files from your last known good backup, made before the infection. The NCSC warns that rescuing files from a still-infected device risks bringing the infection back.
- Tell people who need to know: your bank if money or card details may be involved, contacts who may have received messages from you, and your employer if the device is used for work. In the UK, fraud can be reported to Report Fraud; elsewhere, use your national fraud reporting service or the police.
If your browser is so compromised that you cannot download a scanner, or the device holds business data, get professional help rather than improvising.
Common mistakes
- Installing several cleaners at once. Multiple real-time security products conflict with each other. Use one, plus an offline scan if needed.
- Downloading a "free virus removal tool" from an advert. Fake security software is a long-running way to deliver malware. Use the tool built into your system or download directly from a known vendor's own site.
- Paying a ransom. The NCSC points out that paying gives "no guarantee that you will get access to your data or computer", that the computer will still be infected, and that you are more likely to be targeted again. A tested backup is the real defence.
- Assuming a clean scan means clean accounts. If a password stealer ran even briefly, your credentials may already be gone. Change them anyway.
Preventing the next one
- Keep the operating system, browser and apps on automatic updates.
- Keep your security software on, updated, and set to scan new files automatically, as the FTC recommends.
- Install software only from official app stores or the developer's own website, and avoid pirated software and file-sharing downloads.
- Use a password manager, unique passwords and two-step verification.
- Back up regularly to a drive you disconnect afterwards or to a cloud service with version history, and test a restore occasionally.
- Turn on device encryption, which the NCSC includes in its recovery advice.
The bottom line
A slow computer is usually just a slow computer, and a pop-up shouting that you are infected is usually a scam. The signs that should make you act are concrete ones: a detection your security software cannot clear, messages or logins you did not make, security tools switched off, and account settings changed behind your back. When that happens, secure your email and bank from a clean device first, then clean or wipe the infected one and restore from a backup made before the trouble began. If you want more than the built-in tools, our antivirus comparison sets out the options.