Malware does not always announce itself with a dramatic warning. On a Windows computer, it may look like a browser problem, a slow startup, a failed update, or an unfamiliar charge on an online account. Some infections are noisy, while others try to remain unnoticed.
The signs below are useful clues, not proof by themselves. A failing drive, an unwanted browser extension, a damaged Windows installation, a bad update, or an overheating computer can produce similar symptoms. Look for several changes that began around the same time, especially if you cannot explain them by a recent installation or update.
Before investigating: protect your data and accounts
Do not enter passwords, banking details, or recovery codes on a computer you suspect is compromised. If you need to change a password, use a separate, trusted device. For banking, payroll, email, or business accounts, contact the provider promptly if you see unauthorized activity.
Avoid randomly deleting files, registry entries, browser folders, or security software. Those actions can remove evidence, damage Windows, or make an important file unrecoverable. If the computer contains irreplaceable business or personal data, stop before attempting aggressive cleanup and consider professional diagnosis.
1. Pop-ups appear when the browser is closed
Unexpected advertising, fake virus alerts, or system-looking messages that appear outside the normal browser can indicate adware or a malicious program. Be especially cautious when a pop-up tells you to call a phone number, install remote-access software, or pay immediately to “unlock” the computer.
However, not every pop-up means the computer is infected. A website may have permission to send browser notifications, or a legitimate application may be displaying an alert. Do not click the warning to investigate. Close it using the window controls if possible, then review browser notification permissions from the browser’s settings.
2. Your browser opens unfamiliar pages or changes its search engine
Repeated redirects, a new home page, or search results that pass through unfamiliar websites may point to a malicious extension, unwanted application, or changed browser setting. Check the browser’s installed extensions and remove only items you recognize as unnecessary. If an extension is required for work, confirm with the administrator before removing it.
Redirects can also come from a damaged browser profile, a changed DNS setting, or a network-level issue. Testing another trusted browser can help separate a browser problem from a wider computer or network problem, but it does not prove the system is clean.
3. New programs, extensions, or icons appear without your permission
Look for unfamiliar applications in Windows Settings under installed apps, new browser extensions, and shortcuts on the desktop or taskbar. A program you do not recognize deserves investigation, particularly if it appeared shortly before other symptoms.
Do not assume every unfamiliar item is malware. Hardware utilities, printer software, update components, and workplace tools may use names that are not obvious. Search for the publisher and installation date, and avoid downloading an “uninstaller” from an untrusted pop-up.
4. Security tools are disabled or will not update
Malware sometimes attempts to weaken antivirus protection, Windows Security, firewall settings, or update services. Warning signs include a security dashboard that will not open, protection that repeatedly turns off, or updates that fail only on the affected computer.
There are ordinary explanations too: another antivirus product may be managing protection, an expired subscription may be involved, or a company policy may control the settings. If you cannot restore protection through the normal Windows interface, avoid installing several security products at once. They can conflict and make diagnosis harder.
5. The computer becomes unusually slow or busy when you are doing very little
A sudden increase in processor, memory, disk, or network use may be consistent with malware running in the background. Fans may run more often, the cursor may lag, or simple programs may take longer to open.
Open Task Manager with Ctrl + Shift + Esc and note which processes are using resources. Do not end a process merely because its name looks unfamiliar. Many legitimate Windows components have technical names, and stopping the wrong process can cause instability. High disk use can also result from updates, cloud synchronization, low free space, a failing drive, or an aging hard disk.
6. Files are renamed, encrypted, missing, or suddenly inaccessible
Unexpected file extensions, ransom notes, files that will not open, or large numbers of changed filenames are urgent warning signs. They can be associated with ransomware, but file-system damage, synchronization conflicts, and accidental bulk changes can look similar.
If you suspect ransomware, disconnect the computer from Wi-Fi and wired networks, but do not begin deleting or renaming affected files. Do not attach backup drives until you understand whether they could also be exposed. Contact your organization’s IT administrator or a qualified repair and data-recovery professional. Recovery options depend on what happened, whether backups are available, and whether the files are intact.
7. Friends or coworkers receive messages you did not send
Messages sent from your email or social accounts without your knowledge may indicate malware, a stolen password, an active browser session, or a compromised contact’s account. Check the account’s sent items and sign-in activity from a trusted device, then change the password and enable multifactor authentication if the provider supports it.
Changing the password alone may not end every session. Use the provider’s option to sign out other devices, review recovery email addresses and phone numbers, and remove unfamiliar connected applications. For a business account, notify the administrator before making changes that could affect shared access.
8. You see unfamiliar sign-ins, password-reset notices, or account changes
Unexpected login alerts, password-reset emails you did not request, or changes to account recovery details should be treated seriously. These alerts may come from a stolen password rather than malware on the computer, so investigate the account and the computer separately.
Use a clean device to visit the service through its known address—not a link in the alert email. Change reused passwords on important accounts, starting with email because it may control password resets. If an account has financial or workplace access, follow the provider’s incident process.
9. Windows or applications show unusual restrictions
Malware may interfere with Task Manager, Registry Editor, Windows Security, system settings, or common repair tools. Repeated “access denied” messages or settings that immediately change back are worth investigating.
Still, restrictions can be intentional. A company-managed computer, school device, or standard user account may block these tools by policy. Do not try to bypass those controls. Ask the administrator to review the computer, especially if it connects to business systems or contains regulated information.
10. The computer connects to unfamiliar websites or networks
Unexplained outbound traffic, repeated connections while the computer is idle, or data usage that does not match your normal activity can be a warning sign. Network activity alone does not identify malware: Windows services, cloud storage, browsers, updates, and security products all communicate in the background.
If you manage a home router, review connected devices and change the Wi-Fi password only if you understand the effect on household or business equipment. A router issue is not the same as a malware infection on the computer, and changing several network settings at once can make the original problem harder to trace.
What to do if several signs match
- Stop online banking, shopping, and sensitive account work on the suspected computer.
- Disconnect it from the network if you see active file changes, ransomware messages, or obvious unauthorized activity.
- Write down what changed, when it started, and any messages or unfamiliar programs you observed.
- From a trusted device, secure important accounts and notify the relevant bank, employer, or service provider.
- Run a full scan with the security software already installed, after confirming it is genuine and up to date.
- Use an offline malware scan only when you understand that it will restart the computer and may require a BitLocker recovery key. Save open work first and make sure the recovery key is available.
- Back up essential files carefully. If ransomware or active file changes are suspected, do not connect a backup drive until the situation has been assessed.
A scan that finds nothing does not prove that the computer is clean, and removing one detected item does not confirm that accounts or files are safe. If symptoms continue, the computer contains sensitive records, or the infection may involve ransomware or remote access, professional examination is the safer stopping point. A technician can help distinguish malware from drive failure, corrupted Windows files, unwanted software, or an account-only compromise without making assumptions that risk your data.
For home users and small businesses in Bellevue, Omaha, Papillion, La Vista, and nearby communities, the most useful starting information is usually a timeline of the symptoms, recent software installations, security alerts, and whether other devices or accounts are affected. That information can make the next diagnostic step more focused and less disruptive.
When to call a professional
If the problem continues, the data is important, or the repair requires work beyond your comfort level, AME Computers can provide professional diagnosis and repair or call 402-505-6600.
Free repair guidance
Get New Computer Repair Guides by Email
Practical PC and Mac help from AME Computers. Confirm your email once and unsubscribe anytime.

