First: stop, don't reboot yet
If a business computer is behaving strangely — unexpected pop-ups, ransomware notes, browser hijacking, sluggish performance, unknown programs — don't just restart or start deleting things. On a business network, the wrong first move can destroy evidence you'll need for insurance or spread the infection to a file server.
Signs you should stop and call IT immediately
- A ransom note, or files renamed with strange extensions
- The machine is a server, or holds sensitive client data
- You see accounts, files, or emails you didn't create
- Multiple machines are affected
Any of those means disconnect the network cable / turn off Wi-Fi, leave the machine powered on, and call your IT team. This is now an incident, and cyber-insurance policies often require a documented response.
Safe self-remediation for a single, low-risk PC
Step 1: Disconnect from the network
Unplug the Ethernet cable and disable Wi-Fi. This stops the malware from talking to its command server or spreading laterally.
Step 2: Boot into Safe Mode with Networking
Hold Shift while clicking Restart, then choose Troubleshoot → Advanced options → Startup Settings → Restart → 5 (Safe Mode with Networking). Most malware doesn't load in Safe Mode.
Step 3: Run a full scan with a reputable tool
Use Microsoft Defender Offline Scan (built into Windows) and a second-opinion scanner like Malwarebytes. Let both run to completion — this can take an hour or more.
Step 4: Review installed programs and browser extensions
In Settings → Apps, uninstall anything unfamiliar that appeared recently. Remove unknown browser extensions in Chrome, Edge, and Firefox.
Step 5: Clear browser data and reset browsers
Wipe cookies, cached files, and stored form data. Many browsers offer a full "reset settings" option that undoes hijacked homepages and search providers.
Step 6: Update everything
Run Windows Update to fully current, then update Chrome/Edge/Firefox, Adobe Reader, Java (if you must have it), and any line-of-business apps. Malware usually exploits out-of-date software.
Step 7: Change passwords — from a different device
Assume anything typed on the infected machine was captured. From a clean phone or computer, reset passwords for email, banking, Microsoft 365, and any business apps. Turn on MFA where it isn't already.
Step 8: Reconnect and monitor
Only after scans come back clean and updates are applied, reconnect to the network. Watch the machine for a few days — recurring symptoms mean something deeper is still there.
When to wipe and reinstall
If any of the following is true, don't trust the cleanup — reimage the machine:
- You found a rootkit or boot-sector infection
- The system handled highly sensitive data
- Symptoms return after cleanup
- You can't confidently account for how the infection got in
A clean OS install plus restored files from a known-good backup is the only way to be sure.
How to prevent the next one
- Endpoint Detection & Response (EDR) — modern replacement for basic antivirus
- Automated patching for Windows and third-party apps
- Email security that filters phishing and malicious attachments
- Security awareness training so users spot the bait
- Least-privilege accounts — day-to-day users shouldn't be local admins
- Immutable backups ransomware can't reach
That stack is what turns a malware incident from a business-stopping crisis into a 30-minute inconvenience — and it's exactly what we deploy for our managed IT clients.
Need help putting this into practice?
Network Solutionist helps Delaware businesses harden security, automate maintenance, and stop worrying about IT.
Book a Consultation