Computer viruses: infection signs and safer recovery
A computer virus is malicious code that attaches to another file or program and can spread when that host is run. Not all malware is a virus: worms, trojans and ransomware may spread or operate differently. The distinction matters when choosing a response to suspicious behaviour.
How infection can happen
A virus needs a way to execute and replicate, such as an infected program, unsafe active document content or another executable carrier. Modern attacks may also use phishing, unpatched vulnerabilities and fake installers. Merely seeing a web page does not prove an infection; a successful exploit or harmful content must actually run.
An attachment claiming urgency, an unexpected installer or a request to disable security software deserves scrutiny. Download programs from trusted sources, verify updates through the vendor’s official channel and avoid opening unsolicited active documents. No single habit guarantees protection, but layered precautions lower the risk.
Signs and reliable checks
Unexpected processes, changed security settings, encrypted files or protection alerts can justify an investigation. Each sign can also have a harmless cause, so do not identify malware from one symptom alone. Update the operating system and security definitions, then run a scan with reputable installed tools.
If a suspicious program may capture credentials, avoid entering passwords on that device. Disconnect it from sensitive accounts or networks where practical, but consider whether isolation would interrupt a critical service. Preserve useful evidence if an organisation needs incident analysis.
Recovery and prevention
Follow the security tool’s guidance and check its findings. For a serious compromise, restoring from a known clean backup or reinstalling may be safer than trusting a partial cleanup. Change affected passwords from another trusted device and enable multi-factor authentication where available. Check account activity and revoke suspicious sessions.
Keep software and browsers updated, make tested backups and use accounts with only necessary privileges. A firewall can limit some traffic but cannot replace updates or judgment about files. If a work device is involved, contact the responsible administrator before deleting evidence or resetting systems.
Watch for persistence after a restart, unexpected browser extensions and unauthorised account changes. These observations help guide the investigation, but none of them establishes a specific malware family without further evidence.
