“`markdown
What to Do in the First Hour After You Suspect a Malware Infection
Your laptop is running slow, ads are popping up where they shouldn’t, or a file just appeared on your desktop asking for money. Something feels wrong. Your first instinct might be to panic, close everything, and hope it goes away. Don’t. The first hour after you suspect an infection matters more than almost any other part of dealing with it, and what you do (or don’t do) in that window can be the difference between a minor cleanup and a much bigger mess.
This isn’t about preventing malware. That’s a different conversation, and one worth having on a calmer day. This is about what to do right now, in order, if you think something has already gotten in.
Stop and assess before you touch anything
The instinct to start clicking things, closing windows, or running a random scan you found online is understandable. Resist it for thirty seconds.
Figure out what you’re actually seeing. Is it a pop-up claiming your computer is infected and demanding you call a phone number? That’s almost always a scam on its own, separate from real malware. Is it a full-screen message saying your files are encrypted and locked? That’s a strong sign of ransomware, and it changes what comes next. Is your device just acting strange, slow, crashing, or sending messages you didn’t write? That points to something already running in the background.
Knowing which situation you’re in shapes every decision after this.
Don’t pay, don’t call, don’t enter information. If there’s a message asking for payment, a phone number, gift cards, or login credentials, don’t act on it yet. Scammers rely on the fear of the moment to get you moving before you think.
Disconnect the device from the internet
This is the single most important early step, and it’s often skipped because people want to keep working or keep looking for answers online.
Turn off Wi-Fi or unplug the ethernet cable. Most malware needs a connection to communicate with whoever is controlling it, whether that’s sending your data out or receiving new instructions. Cutting that connection can stop the bleeding, even if it doesn’t undo damage already done.
Don’t shut the device down yet, if you can avoid it. This feels counterintuitive, but shutting down too early can sometimes make it harder to recover files or diagnose what happened, especially in ransomware cases where evidence and recovery options can be lost. Disconnecting from the network is the priority; powering off entirely can come later, once you’ve thought it through or spoken with someone who can help.
Don’t scan yet, think about what else is connected
Before you rush to run antivirus software, take stock of what else might be exposed.
Check for other devices on the same network. Malware that spreads across a home network can move from one device to a phone, a smart TV, a partner’s laptop, or a shared drive. If you have a family media agreement or shared devices, this is a moment where it pays off to know what’s connected to what.
Think about what accounts were open. If you were logged into email, banking, or social media on the infected device, treat those accounts as potentially exposed too, not just the device itself.
Consider whether a child’s device is involved. If this happened on a device your kid uses, stay calm and matter-of-fact with them. Kids often hide the moment something goes wrong online because they’re afraid of getting in trouble, which can delay you finding out. If anything about the situation involves a stranger contacting your child, threats, or requests for images, that’s a different and more urgent situation. Read the warning signs of sextortion and what parents should do and don’t wait to involve authorities if a child is at risk.
Run a scan, but only after you’ve disconnected
Once the device is off the network, it’s reasonable to run a scan using trusted, already-installed security software. Avoid downloading a new “cleaner” tool you find through a search right now; scam tech-support sites and fake antivirus tools love to show up exactly when someone is panicking and searching for help. That’s the same pressure tactic covered in how to tell if a direct message is a scam before you click anything; urgency and fear are the tools, whether it arrives as a DM or a search result.
If you don’t already have security software installed, it’s safer to wait and use another device to research a reputable option rather than downloading anything on the device you suspect is compromised.
Let the scan run fully. Don’t interrupt it partway through because nothing seems to be happening. These scans can take time, especially on a slow, possibly overloaded device.
If it looks like ransomware, stop and get help
Ransomware, where files are encrypted and a payment is demanded to restore them, is a different category from most malware. Paying doesn’t guarantee you’ll get your files back, and it funds the same people who will likely target others.
Don’t pay. Don’t negotiate. Disconnect the device, avoid running random recovery tools you find online, and contact a professional or your local authorities. This is truly a “call someone” situation rather than a “fix it yourself tonight” one.
Change passwords, but from a different, clean device
Once the infected device is offline, use a separate, trusted device (a different computer or your phone, assuming it’s not affected) to change passwords for anything important: email, banking, social media.
Start with email first. Email is often the key to resetting everything else, so it’s the account attackers want most and the one you should secure first.
Use this as a moment to fix weak passwords, not just change them. If you’ve been reusing the same password across accounts, now’s a natural time to stop. Choosing a strong password that’s actually easy to remember is worth a few minutes, even in the middle of a stressful afternoon.
Once the device is clean, rebuild carefully
After the immediate scare is handled, whether that’s a successful scan, a factory reset, or professional help, take a few steps to reduce the odds of a repeat.
- Make sure automatic updates are turned on for your operating system and apps; outdated software is one of the easiest doors for malware to walk through, which is covered in why you should turn on automatic updates, even if they’re annoying.
- Review which apps have permissions you don’t recognize or remember granting, including location access; you can learn more in how to check if an app is selling your location data.
- Talk with your family about what happened, especially if kids share the device. A calm conversation now is more useful than a rule added after the fact. If screen habits or unsupervised downloads played a role, it may be worth revisiting how much screen time is too much as a family.
The hour that actually matters
None of this requires you to be a security expert. It requires you to slow down, disconnect before you scan, avoid paying or calling anyone a pop-up tells you to, and get help early when something looks like ransomware or involves a child. The first hour isn’t about fixing everything. It’s about not making the situation worse while you figure out what’s actually happening.
A quick safety note
This article is general information, not professional security, legal, or medical advice. No single tool or setting makes anyone completely safe; security works in layers. If you are dealing with a live incident, such as active fraud, ransomware, or a child in danger, contact the appropriate professionals or authorities. For a threat to a child, report it to the NCMEC CyberTipline at report.cybertip.org and to local law enforcement.


