Contain an active problem
If you see active remote control, a ransom demand or other serious signs of compromise, disconnect Wi-Fi and any wired network connection. Do not connect backup drives. For a work device, immediately tell your IT or security team and let them decide about investigation, shutdown and recovery.
From another trusted device, contact your bank if banking information was exposed during the incident or you suspect a payment. If an account may be affected, follow account recovery guidance.
Record the time and message or photograph the screen. Before erasing or resetting, check what needs preserving as evidence. Reporting to FIN-CSIRT does not replace urgent contact with your bank or internal team.
Investigate signs without jumping to conclusions
Slow performance, restarts and unusual windows can have several causes. Take a finding from a known security tool seriously; a warning on a random website is not the same as that finding.
Do not call a number in a message offering urgent cleaning or give a stranger access. Unsolicited “technical support” calls can be scams. Open the manufacturer’s official support independently or contact your own IT specialist.
Choose the process for your device
For routine checks and recovery preparation, use the Windows, Mac, Android or iPhone guide. These do not replace isolation of an actively affected device or an IT assessment.
Personal computer
Follow instructions from the operating system provider and your existing security tool. An updated antivirus scan can help detect and remove malware. If the device was isolated because of an active incident, do not reconnect it yourself just to download updates; seek instructions for continuing safely.
If the problem persists or the tool cannot remove it, expert help or a fresh system installation may be needed. A clean result from one scan is not a guarantee that no compromise exists.
Phone or tablet
Check the manufacturer’s official guidance for the particular problem. A factory reset may be an option, but it erases data. Before starting, check backups, account access and necessary evidence. Do not assume a reset addresses every possible cause.
Restoring data
After cleaning or reinstalling, use a trusted backup from before the infection. Do not indiscriminately copy everything from an infected device: this may carry malicious files across too.
After recovery
Enable system and app updates, maintain protection and make backups that are not continuously accessible to the device. Check device encryption to protect data if the device is lost; encryption does not replace malware protection. If symptoms return, seek another expert assessment.