Removing malicious software from your device

A person with short dark hair and glasses smiles at the camera while working on a laptop in a café.

Navigation

Your generosity can provide a lifeline to victims of cybercrime

If our chatbot has diagnosed you with a malicious software (malware) infection, pick the section below that matches your device and follow the steps. If you haven’t used the chatbot yet, we advise you to describe your issue to the chatbot and get an expert opinion on the problem.


Common signs of a malware infection include slow performance, the device not starting properly, remote use of your device, changes to where adverts are displayed, your homepage being redirected, and lots of pop-ups carrying warnings.
Before you start the process listed below, it is important to think about your level of IT knowledge. If you are not a confident IT user, we strongly advise you to seek expert help in finding and removing the malware. There is a risk of losing your data or harming your device if the steps below are not followed correctly.

We want to better understand the impact of you experiencing this issue, can you share your experience by filling in this online form? This will help us better protect future victims.


Malware infection - do this first!

  • Disconnect your device from other devices and the internet to reduce the risk of the infection spreading. This may also stop the malicious software communicating with cyber criminals or allow them to access your device. Unplug other devices such as external hard drives and USBs. Disconnect from the wireless or wired internet connection until you are ready to clean the device.

  • Be careful what you type – Many types of malware have a keylogger, which is software that copies what you type and sends it to cyber criminals. Do not log in to online accounts from the infected device.

  • Protect payment and identity details – If you entered card, banking or identity details on the infected device, contact your bank immediately using the number on the back of your card or the bank’s official app or website. If you are concerned about identity theft or impersonation, you may also wish to contact the Southern African Fraud Prevention Service (SAFPS) for fraud-prevention support and Protective Registration. SAFPS provides Protective Registration for people whose identity has been compromised or who have experienced identity fraud or impersonation.

  • If you paid for a fake malware scanner or clean-up tool, contact your bank as soon as possible and explain what happened. Ask the bank to check whether your card or account details may have been exposed and whether further action is required.

A screen displaying a security software "Quick Scan" prompt, with a Scan button and a scheduled scan icon.

Removing malware from a Windows device

  1. Remove unknown apps – You may be able to remove malicious software manually. For example, if you are infected with adware and are experiencing lots of adverts and redirects, review the installed applications in Windows settings and remove any software you do not recognise.

  2. Enter Safe Mode – Safe Mode starts Windows with a limited set of drivers and services, which can prevent some malware from running. The method for entering Safe Mode differs between Windows versions. Search Microsoft Support for the instructions for your version of Windows. Keep the PC disconnected from the internet while carrying out these steps.

  3. Delete temporary files – This is optional, but deleting temporary files may free up disk space and can make a malware scan faster.

  4. Download a malware scanner – If necessary, reconnect to the internet briefly to download and update a reputable malware scanner, then disconnect again before performing the scan. You can use a reputable on-demand scanner in addition to your device's existing real-time protection. Examples include Malwarebytes, Avast, Bitdefender, and Microsoft Defender. If you are struggling to download a scanner on the infected device, you may be able to use a different clean computer to download the required software onto a USB drive. Take care when connecting external media to an infected device.

  5. Run a malware scan – Follow the scanner's instructions and perform a full scan where available. If the scanner finds malware, follow its instructions for removal. If the scanner fails to run, disappears when you start the scan, or will not reopen, the device may have a deeper infection. You may need professional technical assistance or, as a last resort, to reinstall the operating system. If the first scan finds nothing but you still have strong reasons to suspect malware, seek expert assistance rather than repeatedly installing multiple scanners.

  6. Fix your web browser – Malware can change browser settings, including the homepage, search engine or extensions. Open your browser settings and check that the homepage, search engine, extensions and connection settings are ones you recognise. Clear the browser cache and browsing history if appropriate.

  7. Recover your files if Windows is corrupt – If you cannot find or remove the malware, or Windows has been damaged and does not work properly, you may need to wipe the device and reinstall Windows. Before doing this, check that you have a safe backup of your important files. Take care not to transfer infected files back onto the cleaned device.

  8. Reinstall the operating system – Reinstalling the operating system can remove malware by wiping the device and reinstalling the software. Use the Windows recovery or reset options where appropriate and follow the current instructions provided by Microsoft Support.

  9. Change your passwords – Once you are using a device you believe is clean, change passwords for the device and for online accounts that may have been accessed from the infected device. Prioritise your email account and any accounts containing financial or sensitive information. Use unique passwords and enable multi-factor authentication where available.

  10. Contact your bank if banking or card information may have been exposed – Contact your bank using the number on your card, its official app, or its official website. Explain that your device may have been infected with malware and that banking or card details may have been exposed. Ask the bank to check for suspicious activity, secure online banking access, replace cards if necessary, and advise you on any fraud-reporting steps.


Removing malware from a Mac

  1. Shut down and restore if you have a known-clean backup – If you have a recent Time Machine backup or another known-clean backup from before the infection, you may be able to restore your Mac. Follow the current instructions provided by Apple Support. Ensure that external devices are disconnected while restoring where possible. Check external devices for malware before reconnecting them.

  2. Download a malware scanner and scan the Mac – If you do not have a suitable backup, you may need to scan the Mac for malicious software. Use a reputable malware scanner and follow its instructions. Examples include Malwarebytes and Avast. You can also use security tools available through the Mac App Store. If possible, download software using a clean computer and transfer it using appropriate trusted media.

  3. Check browser settings and clear the cache – Malware can change browser settings, including the homepage, search engine and extensions. Check your browser settings and remove anything you do not recognise. Clear the browser cache and browsing history if appropriate.

  4. Empty the Downloads folder – Review your Downloads folder and remove files you do not recognise or no longer need. Do not delete files that may be required as evidence of the incident before preserving them.

  5. Recover your files – If you cannot find or remove the malware, or macOS has been damaged and does not work properly, you may need to wipe the device and reinstall the operating system. Before doing this, check that you have a safe backup of your important files. Take care not to transfer infected files back onto the cleaned device.

  6. Reinstall the operating system – Follow the current instructions provided by Apple Support for reinstalling macOS.

  7. Change your passwords – Once you are using a device you believe is clean, change passwords for the device and online accounts that may have been accessed from it. Prioritise your email account and accounts containing financial or sensitive information. Enable multi-factor authentication where available.

  8. Contact your bank if banking or card information may have been exposed – Contact your bank using the number on your card, its official app, or its official website. Explain that your device may have been infected with malware and ask whether any additional security measures are required.


Removing malware from an Android device

If you are running Android, you are likely using a mobile phone or tablet. Follow the steps below to remove malware from the device.

  1. Switch to Safe Mode – Put your phone or tablet into Safe Mode. This prevents many third-party apps from running, including some malware. The method varies between Android devices. Search for the instructions for your specific model using the manufacturer's official support information. When in Safe Mode, you will normally see "Safe Mode" displayed on the screen.

  2. Find and remove the app – Go to Settings and open the Apps section. Look for recently installed or unfamiliar apps and identify anything you do not recognise. Open the app information and select uninstall where available. If the uninstall option is unavailable, the app may have administrator privileges. Check your security settings for device administrator apps and remove the relevant administrator permission before attempting to uninstall the app again.

  3. Download an anti-malware app and run a scan – If appropriate, download a reputable anti-malware app from the official Google Play Store and run a scan. Examples include Malwarebytes and Avast Mobile Security.

  4. Change your passwords – Once you are using a device you believe is clean, change passwords for accounts that may have been accessed from the infected device. Prioritise your email account and accounts containing financial or sensitive information. Enable multi-factor authentication where available.

  5. Contact your bank if banking or card information may have been exposed – Contact your bank using the number on your card, its official app, or its official website. Explain that your device may have been infected with malware and ask whether any additional security measures are required.


Report the crime

If you are in South Africa and believe you have been the victim of a cybercrime, you can report the crime to the South African Police Service (SAPS). You can visit your nearest police station and ask to open a case. SAPS guidance states that victims can report crimes at their nearest police station, and a case should be registered in the Crime Administration System. You should retain the CAS number provided to you as a reference for future enquiries.

For emergencies requiring immediate police assistance, call 10111. For less serious complaints and general enquiries, contact your nearest police station.

When reporting the incident, preserve and take relevant evidence where possible, including:

  • screenshots

  • ransom notes

  • suspicious messages

  • payment or transaction evidence

  • device details

  • suspicious email addresses

  • usernames

  • URLs

  • relevant bank correspondence

  • any case or reference numbers already provided

You can also report relevant cyber incidents to South Africa's Cybersecurity Hub, the national Computer Security Incident Response Team (CSIRT), where appropriate.

If money, banking details or identity information were involved, contact your bank immediately. If you are concerned about identity theft or impersonation, consider contacting SAFPS for fraud-prevention support and Protective Registration.


How to avoid a malware infection in future

  • Back up your files – Having a backup can reduce the impact of malware. Use an external drive or a reputable cloud backup service. If you use an external drive for backups, disconnect it after the backup has completed so it is not continuously exposed to malware.

  • Use reputable security software – Keep your device's built-in security protections enabled and use reputable security software where appropriate.

  • Do your updates as soon as possible – Install operating system, browser, application and security updates promptly. Where practical, enable automatic updates. Security updates can fix vulnerabilities that malware may exploit.

  • Be careful with links and attachments – Do not click unexpected links or open unexpected attachments in email, SMS, WhatsApp or other messaging platforms. Legitimate accounts can be compromised and used to send malicious messages. If a message appears to come from your bank or another trusted organisation, verify it using an official contact method rather than the contact details in the message.

  • Download apps only from official app stores – The safest approach is to download apps from the official app store for your device. Avoid installing apps from unknown websites or unofficial sources.

  • Check app permissions – Review the permissions requested by apps and only grant permissions that are necessary. Be particularly cautious of apps requesting device administrator or other high-level permissions.


Donate

Your generosity makes our free support possible. Please consider giving today.

Without donations, we cannot keep our service free or provide help to the most vulnerable victims of cybercrime when they need it most. As a not-for-profit organisation, every donation goes directly towards keeping The Cyber Helpline up and running. Donate now and help us support victims of cybercrime.