Signs that point to an infection
Malware is never invisible, because it runs on the same CPU, disk and network as everything else — and most of what home users actually catch is adware, browser hijackers and other junk rather than cinematic spyware. The signs below are ordered roughly from “annoying” to “serious”, and ransomware is the loudest of all: it renames files in bulk, adds strange extensions and leaves a ransom note on the desktop. A single sign can have a harmless explanation; three or four together are a diagnosis.
It also helps to know the modern delivery routes: fake “Download” buttons on download sites, installers bundled with extra “offers”, pirated software and cracks, and email attachments you were not expecting. If any of those ran on your PC with administrator rights in the last weeks, move the checks below up your to-do list.
- The PC suddenly crawls: fans spin, the disk sits at 100% in Task Manager, although you launched nothing
- Ads and pop-ups appear outside the browser, or the browser opens pages you never asked for
- Unknown programs appear in the installed-apps list, plus a new toolbar or a search engine you never chose
- Friends receive spam and strange links from your email or messengers that you did not send
- Microsoft Defender turns itself off, or real-time protection dies after every reboot
- Files get renamed en masse with strange extensions and the desktop shows a ransom note
How to check the PC systematically
Start with Task Manager (Ctrl+Shift+Esc) on the Processes tab: look for unfamiliar names eating CPU, disk or network while the PC is otherwise idle. Right-click a suspicious process → Open file location — malware loves to camp in AppData\Temp and AppData\Roaming rather than Program Files; a process running from there with a generic name is a red flag. Next, check the Startup apps tab and Settings → Apps → Installed apps sorted by install date: anything you cannot place, installed around the time the trouble began, is the prime suspect.
Then audit the browser: extensions you do not recognize, a homepage or search engine that changed on its own, unknown site permissions. Finish with Windows Security → Virus & threat protection → Scan options → Full scan — on a busy disk it can run an hour or more, so let it work while you do something else. If the behavior persists although the scan comes back clean, that is precisely the case for a Microsoft Defender offline scan, which reboots the PC and checks the disk before Windows loads.
If you do find something
Let Defender remove what it found, then uninstall the program that brought the infection in — the “carrier” is usually visible in the installed-apps list with a recent date. Reset the browser settings, remove unfamiliar extensions, and change your important passwords from another, clean device, because an infostealer may already have your browser-saved logins. Keep Windows and your browser updated afterwards; most infections walk in through doors that updates had already closed.
After the antivirus does its job, the files the malware dropped in %TEMP% and the leftover folders of removed “offers” often stay behind, and a cleaner such as Kleaner PRO sweeps those traces out so nothing of the visit remains. For ransomware the script is different: disconnect from the network immediately, do not pay, and check whether OneDrive version history or your backups can restore the files — reinstalling Windows is the last step, not the first.
Questions and Answers
Can a PC have malware without slowing down?
Yes — infostealers that quietly copy saved passwords and cookies are designed to be silent. The reliable check is a full Defender scan plus a review of startup items and installed apps, not how the PC feels.
Is Microsoft Defender enough to catch malware?
For a typical home user, real-time Defender plus current updates catches the overwhelming majority of threats. The weak spot is the human: fake installers approved with “Run anyway” and pirated software bypass any antivirus.
What should I do first if I suspect ransomware?
Disconnect from the network — unplug the cable or turn off Wi-Fi — and do not pay and do not reinstall yet. Check OneDrive version history or backups for your files first, then disinfect with a Defender offline scan.
Know what is included before you buy.
The one-time 30-minute trial covers core tools. PRO-labelled features stay locked until a paid license is activated.
Read next
Write to us: [email protected]