Security Malware and cleanup: when a device starts misbehaving
Malware in plain English: the families and what each one does
Viruses, worms, trojans, ransomware, spyware, stalkerware and adware explained by what they actually do to your machine, how each arrives, and which ones matter in 2026.
The short answer
- Malware is any software on your device that works for someone else, and the useful way to sort it is by what it is trying to do rather than by its family name.
- Virus, worm and trojan describe how something arrives, not what it does, and nearly everything reaching home users today arrives as a trojan the user installs.
- Information stealers are the most common serious infection now, and they take saved passwords and session cookies, which is how they get past a second factor.
- Most infections start with a fake update, a lookalike download site, cracked software, or an instruction to paste a command somewhere.
- Built in security software is enough for most people, but no scanner reliably catches something new, so updates and careful installing matter more than detection.
- Pop ups and a changed search engine are usually a browser problem, not a system infection, and the fix is different.
Malware is any software running on your device that works for someone else. That is the whole definition, and it is more useful than the family names, because the names describe history rather than harm. What matters is what a given piece of software is trying to do: take your passwords, encrypt your files for a ransom, show you ads, watch what you type, use your machine as someone else's computer, or quietly install the next thing. Sort by that, and both the symptoms and the response become obvious.
Sorted by what it does to you
Six behaviors cover nearly everything that reaches ordinary people.
Stealing credentials. Information stealers are the most common serious infection today. They run once, sweep up everything useful in a few seconds, and often delete themselves. That sweep includes passwords saved in your browser, stored card details, crypto wallet files, and the session cookies that keep you logged in. Those cookies are the reason a stealer can bypass a second factor: the attacker does not need to sign in, because they can reuse your existing session.
Encrypting and extorting. Ransomware scrambles your files and sells you the key, and the current versions usually copy the data out first so they can threaten to publish it too. How it gets in and what to do in the first hour is covered in ransomware explained.
Showing ads and hijacking the browser. Adware changes your search engine, injects extra results, opens new tabs and creates a stream of alerts. It is the least dangerous family and by far the most common complaint, and the fix is usually browser level rather than system level, as set out in fixing a hijacked browser.
Watching. Keyloggers record typing. Spyware records more broadly. Stalkerware is the same technology sold to monitor a partner or family member, installed by someone with physical access to the phone, and it is the one case where the attacker is not a stranger and where safety planning matters more than a clean install.
Remote control. A remote access tool gives someone your keyboard and screen. Sometimes that is criminal software, and sometimes it is a legitimate support tool you were talked into installing, which is exactly how tech support scams work. Machines are also enrolled into botnets, where your connection is rented out for attacks, spam or as a proxy for someone else's fraud.
Using your hardware. Cryptomining software spends your electricity and your processor on someone else's coins. On a laptop it shows up as constant fan noise, heat and a battery that empties fast while nothing is running.
There is a seventh category that does none of these directly: loaders, whose only job is to establish a foothold and install whatever the operator sells next. This is why an infection is rarely just one thing.
Virus, worm and trojan: what those words mean
These three describe how something spreads, not what it does, which is why they sit awkwardly next to the list above.
A virus attaches itself to a file or program and spreads when you run the infected thing. A worm copies itself across a network with no help from you, which is what made the famous outbreaks spread so fast. A trojan does not spread at all: it pretends to be something you wanted, and you install it yourself.
Almost everything hitting home users today is a trojan by delivery, which is the single most useful fact in this article. Infection is now a social problem more than a technical one. The malware does not break in, it is invited in by a person who thinks they are installing a video player, a cracked application or a driver update.
How infections actually start
The routes that matter now, roughly in order of how often they catch people.
- Fake updates. A page says your browser, your video plugin or your graphics driver is out of date and offers the file. Real updates never arrive through a web page you happened to visit.
- Lookalike download sites. You search for a well known free program and land on a site that is not the vendor, with an installer that includes extras. Going to the official site or your operating system's own store avoids this entirely.
- Cracked software, key generators and game cheats. This is the largest single feeder of information stealers, because the user has already agreed to switch off the security warnings.
- Copy and paste instructions. A fake error page or fake human verification check tells you to press a key combination and paste a line of text to fix the problem. The line is the malware. No genuine site has ever needed this.
- Attachments. Less dominant than it was, but alive, especially archives with a password in the message body, which exists purely to stop the mail scanner from looking inside.
- Browser extensions. An extension that can read every page can also take everything on it, and popular extensions are sometimes sold and repurposed after the fact, a risk explained in the permission that reads every page.
- Phones. Sideloaded apps on Android, and configuration profiles or physical access on iPhones. Store apps are not perfect but the difference in risk is large.
Symptoms and the first response
| Family | What you would notice | First response |
|---|---|---|
| Information stealer | Often nothing, until logins start failing or contacts get messages from you | Change passwords from a clean device, end all sessions, turn on a second factor |
| Ransomware | Files renamed and unopenable, a note on the desktop | Disconnect the device immediately, do not pay yet, check backups |
| Adware | New homepage, extra tabs, desktop alerts, injected results | Remove unknown extensions, reset the browser, clear notification permissions |
| Spyware or stalkerware | Battery and data use that does not match your usage; someone knows too much | Do not tip off the installer if it is a domestic situation; seek support first |
| Remote access tool | Cursor moving on its own, unfamiliar support software installed | Disconnect from the network, uninstall it, change passwords elsewhere |
| Cryptominer | Fans running constantly, heat, slow machine when idle | Check what is using the processor, remove it, scan |
Two symptoms people over read: a slow computer is usually just a full disk, too many startup programs or old hardware, and a suddenly noisy laptop is often an update running in the background. Neither is evidence of infection on its own.
What actually protects you, in order
Ranked by how much each one returns for the effort, which is not the order most advice gives.
- Install updates. Operating system, browser and anything exposed to the internet. Most successful attacks use flaws that were fixed months earlier. Which updates to rush and which can wait is covered in software updates explained.
- Only install software you went looking for. From the vendor or an official store. This single habit removes most of the list above.
- Turn on a second factor everywhere important. It does not stop a stealer taking cookies, but it does stop a stolen password on its own from being enough.
- Keep backups that a ransomware infection cannot reach. That means a copy which is offline or versioned, not just a folder that syncs, since a sync will happily copy the encrypted files over the good ones. The practical shape of this is in backups that actually work.
- Run fewer browser extensions and review the ones you have twice a year.
- Use the built in security software. For most people it is genuinely enough, and a second paid suite adds alerts rather than protection.
Be honest about what scanning can and cannot do. Antivirus recognizes things that are already known and behavior that looks familiar. Fresh malware, and anything an operator tailors before sending, will often pass a scan on the first day. A clean scan is reassuring, not proof, which is why the order above puts prevention above detection.
If you think something is on your machine now
Start by writing down what happened just before the symptoms began: a download, an extension, an installer, a phone call. That one detail decides most of the response, because a browser problem and a system compromise need very different work.
If you ran something you should not have, disconnect the device from the network, run a full scan with the tool already on the machine, and then change the passwords for anything you used on it from a different device, starting with email. If the trouble is limited to pop ups, new tabs and a changed search engine, it is almost certainly a browser problem and not a system one. For anything more, the ordered cleanup, including the hidden scheduled tasks and browser profiles that survive a simple uninstall, is in how to clean an infected computer.
Common questions
Do I need to pay for antivirus?
For most people, no. The security software built into current versions of Windows and macOS detects the same widely circulated threats as paid products and is better behaved about resources and alerts. Paid suites mainly add extras like a VPN or identity monitoring, which are worth judging separately rather than as protection against malware.
Can a Mac or an iPhone get malware?
Yes, though the mix differs. Macs mostly encounter adware and information stealers delivered through fake installers rather than viruses in the old sense. iPhones are rarely infected by ordinary malware, and the realistic risks there are configuration profiles installed under pressure, and stalkerware set up by someone who has your passcode.
How do I know if I have malware or just a slow computer?
Slowness alone is weak evidence. A machine that is short of disk space, running many startup programs or simply old will feel identical. Look instead for things that should not happen: unfamiliar programs installed, a search engine you did not choose, the cursor moving on its own, contacts receiving messages you did not send, or sign in alerts from new locations.
Does a factory reset remove everything?
A full reinstall removes nearly all consumer malware, but it does not undo what was already taken. If passwords or session cookies were stolen, those are gone regardless of what you do to the device, so a reset must be paired with changing passwords and ending active sessions. Be careful restoring from a backup made after the infection started.
Is opening an email enough to get infected?
Almost never on its own. Mail apps block scripts and remote content by default, and the danger begins when you open an attachment, follow a link and type something, or run a file the message told you to unzip with a supplied password. Reading and deleting a message is safe.