How malware gets in
Malware is the umbrella term for programs built to harm a computer or steal information. Ransomware that encrypts files and demands money, programs that secretly record what you type, programs that pop up ads or change browser settings: the types vary, but the ways in are similar. Typical routes are attachments in email or messages, installers from dubious sites, pirated copies of paid software, and security holes in programs that have not been updated. Most infections begin the moment the user opens or runs something.
- Attachments and links in email and messages
- Installers of unknown origin and pirated software
- Out-of-date operating systems, browsers and plug-ins
- USB drives of unknown origin
Updates are the strongest defence
When a security hole is found, the vendor closes it with an update. But publishing the update also reveals where the hole was, so a computer that postpones updates becomes an even easier target. Turn on automatic updates for the operating system and browser, and when a restart is requested, do it at a sensible moment rather than putting it off. An operating system past its end of support no longer gets security updates, so continuing to use it is a risk in itself. Programs you rarely use are easy to forget to update, so uninstalling them is another option.
Install only from official sources
Download programs only from the developer's official site or the operating system's official app store. Ad links at the top of search results are sometimes fakes imitating the official site, so get in the habit of checking the address. Files promising free use of paid software are a classic hiding place for malware. Clicking 'Next' repeatedly during installation makes it easy to install unwanted extras, so check and untick additional items. Install only the browser extensions you really need, and check that the permissions they ask for are not excessive for what they do.
The traps in attachments and documents
Be careful with attachments even when they appear to come from someone you know, because messages are often sent in the name of people whose accounts have been taken over. Do not open archives containing executable files, or files with a double extension that makes them look like documents. Turning on file extension display in the file manager makes this trick easier to spot. If a document asks you to 'enable content' or run macros when you open it, it is usually not a legitimate document. The phishing guide in the free web tools topic explains how to recognise phishing texts and emails.
Do not switch off built-in security
Modern operating systems include security features such as built-in antivirus, a firewall and warnings before running programs from unknown sources. If installation instructions tell you to 'turn off your antivirus temporarily', that in itself is a warning sign. The rule is to run only one antivirus program; running several at once can cause conflicts that weaken protection and slow the computer. Using a standard account without administrator rights for everyday work makes it harder for malware to embed itself deep in the system even if it runs.
Backups are the last safety net
Ransomware encrypts files so they will not open. Paying is no guarantee of recovery and may make you a target again. The surest preparation is keeping important files backed up somewhere separate from the computer. An external drive that is always connected, or an automatically synced folder, can be encrypted along with everything else, so it is safer to also use a drive you disconnect after backing up, or a backup method that keeps previous versions. See the backup guide for methods, and the two-factor authentication and password guides for protecting accounts.
What to do if you suspect an infection
Suspect an infection if unfamiliar programs appear, your browser start page or search engine changes by itself, ads keep popping up, or file names change strangely. Rather than panicking and installing one thing after another, follow a set order. If financial or work information is involved, tell the relevant institution or your company's security team straight away. Public reporting and advice services exist for ransomware, so check the official guidance.
- Turn off Wi-Fi or unplug the network cable
- Run a full scan with the built-in antivirus
- Change key account passwords from a clean device
- If unresolved, check backups, then reset or get professional help
Common misconceptions
Believing that Macs or smartphones are safe is risky. They may be targeted less often, but no operating system is free of malware. The same goes for thinking antivirus is all you need: brand-new malware may not yet be caught, so good habits have to back it up. A window that suddenly claims your computer is infected and tells you to call a number or install a program is almost always a scare scam. Do not call the number or allow remote access; just close the browser.
🌍 Search the web for this
Each button runs this keyword on that search engine