Skip to content
FIN-CSIRT
RS
Report an incident

FIN-CSIRT / Practical lesson

Suspect an infected device?

Contain a possible compromise and choose a recovery process suitable for the device.

Users of online and financial servicesAbout 5 minutes of reading + 3 questions
Go to response steps Need help now?

What you will learn

  • For an active compromise, first isolate the device from the network.
  • Let your IT or security team manage recovery of a work device.
  • Distinguish checking, cleaning and restoring from a trusted backup.

Contain an active problem

If you see active remote control, a ransom demand or other serious signs of compromise, disconnect Wi-Fi and any wired network connection. Do not connect backup drives. For a work device, immediately tell your IT or security team and let them decide about investigation, shutdown and recovery.

From another trusted device, contact your bank if banking information was exposed during the incident or you suspect a payment. If an account may be affected, follow account recovery guidance.

Record the time and message or photograph the screen. Before erasing or resetting, check what needs preserving as evidence. Reporting to FIN-CSIRT does not replace urgent contact with your bank or internal team.

Investigate signs without jumping to conclusions

Slow performance, restarts and unusual windows can have several causes. Take a finding from a known security tool seriously; a warning on a random website is not the same as that finding.

Do not call a number in a message offering urgent cleaning or give a stranger access. Unsolicited “technical support” calls can be scams. Open the manufacturer’s official support independently or contact your own IT specialist.

Choose the process for your device

For routine checks and recovery preparation, use the Windows, Mac, Android or iPhone guide. These do not replace isolation of an actively affected device or an IT assessment.

Personal computer

Follow instructions from the operating system provider and your existing security tool. An updated antivirus scan can help detect and remove malware. If the device was isolated because of an active incident, do not reconnect it yourself just to download updates; seek instructions for continuing safely.

If the problem persists or the tool cannot remove it, expert help or a fresh system installation may be needed. A clean result from one scan is not a guarantee that no compromise exists.

Phone or tablet

Check the manufacturer’s official guidance for the particular problem. A factory reset may be an option, but it erases data. Before starting, check backups, account access and necessary evidence. Do not assume a reset addresses every possible cause.

Restoring data

After cleaning or reinstalling, use a trusted backup from before the infection. Do not indiscriminately copy everything from an infected device: this may carry malicious files across too.

After recovery

Enable system and app updates, maintain protection and make backups that are not continuously accessible to the device. Check device encryption to protect data if the device is lost; encryption does not replace malware protection. If symptoms return, seek another expert assessment.

Practice example

A pop-up offers urgent cleaning

A pop-up offers urgent cleaning
A pop-up offers urgent cleaning

A browser warning claims to have found many viruses. It asks you to call the displayed number and install a remote support program.

Fictional training scenario.
Show the example explanation
The message is not a security-tool finding
A website can display a fabricated warning. Use a known tool or support service to investigate.
Remote access gives additional control
Do not grant it to a stranger on the basis of a pop-up or unsolicited call.

Check your knowledge · 3

Your turn to choose the next step.

Choose one answer for each question shown. More complex lessons select three questions from a wider question bank when the lesson loads.

Questions and explanations are also available without JavaScript.

A work laptop displays a ransom demand and files are changing. What comes first?

Why does this matter? While files are changing, a connected device may also threaten reachable network data or backups. Isolation limits connections while the security team assesses recovery and evidence.

  1. Disconnect it from the network and immediately tell IT or the security team.Correct answer

    Isolation limits possible spread; the team directs next steps and evidence preservation. Disconnecting reduces the opportunity to reach other systems; it is an initial measure, not proof that the device is clean.

  2. Connect the backup drive to save every file.

    Connecting the backup could expose it too. Malware may gain access to the attached drive too, potentially making the backup unusable for recovery.

  3. Immediately perform a factory reset yourself.

    A reset may destroy evidence and data before the team assesses the incident. An irreversible change before assessment can make it harder to establish the attack’s scope and restore business data.

After a problem, an antivirus scan finds no threat. What does that mean?

Why does this matter? A scan result describes what that scan found, not everything that has ever happened on the device. Relate it to symptoms and known events without assuming either complete safety or that everything was stolen.

  1. The device is guaranteed safe.

    No single check provides that guarantee. A threat can go undetected, so persistent suspicious behaviour should not be dismissed because of one result.

  2. Every password on the device has certainly been stolen.

    A negative result does not establish password theft. That conclusion would need additional evidence of access to the information; the scan alone does not establish it.

  3. The scan found no threat, but persistent signs still need investigation.Correct answer

    If suspicious behaviour continues, follow official instructions or get expert help. This respects the limits of the result and continues checking what remains unexplained.

You plan to erase and reinstall a personal computer. What should you check beforehand?

Why does this matter? Erasing a system can remove both personal data and traces needed to investigate the incident. Restoring every file without assessment can also restore content that contributed to the problem.

  1. Only that the internet connection is fast.

    Connection speed does not address loss of data or evidence. A connection may help download a system, but cannot recover the only copy of a file you erased.

  2. The consequences of erasure, necessary evidence and availability of a trusted backup.Correct answer

    Erasure may be irreversible; plan recovery before starting. Planning identifies what you will lose, what must be retained and what you can use to resume work.

  3. Whether you can copy everything from the infected device without checking.

    Indiscriminate copying may carry malicious files into the restored system. A backup is useful when there is reason to trust it; file origins and contents still matter during restoration.

No registration. Your answers are not sent; the result is just for you.

Remember

For an active compromise, first isolate the device from the network.

Check accounts used on the device

References

Sources and further reading

Mobile-device steps follow the Serbian National CERT guidance on safe app use. Ransomware isolation and data recovery are supplemented by the CISA ransomware guide (United States) and the UK NCSC guidance for a hacked device. Cleaning and reset procedures depend on the device and manufacturer.

Content last reviewed