Five signs your computer may have malware
Malware can enter a computer through a fake invoice, a poisoned advertisement, an unsafe download or a message that appears to come from a familiar business. It may steal information quietly, disrupt normal use or give another person access to files and accounts. The earlier you notice the warning signs, the easier it is to limit the damage.
Australian households rely heavily on connected devices for banking, shopping, work, study and government services. A laptop used for online banking in Sydney, a family computer in Brisbane or a work device in Melbourne can hold passwords, tax documents, Medicare details and private photographs. That makes unusual computer behaviour worth investigating rather than dismissing as a temporary glitch.
A single symptom does not prove that a device is infected. Older hardware, a full storage drive, a failing battery or too many browser extensions can create similar problems. Look for several changes that appear suddenly, especially after opening an attachment, installing software or visiting a suspicious website.
The signs below cover common forms of malicious software, including spyware, ransomware, keyloggers, adware and remote-access tools. They also explain what to do without making the situation worse.
What malware can do
Malware is software designed to perform unwanted or harmful actions. A virus may alter files, spyware may monitor activity, and a keylogger may record what someone types. Some threats are designed to extort money, while others focus on harvesting passwords, payment details or identity information.
Criminals often disguise malicious programs as browser updates, parcel notifications, PDF viewers or security alerts. An email mentioning Australia Post, myGov or a local bank can appear convincing because it matches services people use every week. A legitimate-looking logo does not prove that the message or download is safe.
Sudden slowness and unusual resource use
A computer that becomes slow without an obvious reason may be running malicious processes in the background. Fans can run constantly, the battery can drain quickly and the device may become hot while performing simple tasks such as reading email. A sudden increase in data use can also indicate that software is sending information elsewhere.
Check whether the problem affects one application or the whole computer. Open the system’s task manager or activity monitor and look for an unfamiliar process using large amounts of processor power, memory or network capacity. Do not delete random system files based on a name alone; search the process name through a trusted security source or ask a qualified technician to assess it.
Pop-ups and browser changes
Persistent pop-ups, new tabs and fake virus warnings are common signs of adware or a compromised browser. The warning may claim that your files are at risk and urge you to call a phone number or pay for immediate assistance. Genuine security software does not normally demand payment through a random pop-up or ask for remote access through an unsolicited call.
Other clues include a changed homepage, an unfamiliar search engine, redirects to unrelated websites and browser extensions you did not install. Remove extensions you recognise as unwanted, reset the browser if necessary and run a reputable malware scan. Avoid clicking the warning itself, since the button may download another program or send you to a fraudulent payment page.
Accounts behaving strangely
Unexpected password-reset emails, social media posts you did not publish or online purchases you do not recognise may indicate stolen credentials. Malware can capture passwords directly, while a compromised email account can provide access to other services through password-reset links. The problem may appear first on the computer, even if the visible damage occurs in an online account.
If an account looks compromised, use a different trusted device to change its password. Turn on multi-factor authentication, review active sessions and contact the bank immediately if payment details may have been exposed. Australian users should also treat unexpected messages about myGov, superannuation or tax refunds carefully, since identity information can be valuable to scammers. Guidance about scams targeting seniors is useful for recognising the social tricks that often accompany technical attacks.
Security tools stop working
Malware sometimes tries to disable antivirus protection, firewall settings or system updates so it can continue operating. A warning that protection has been turned off, an update that repeatedly fails or a security application that will not open deserves attention. The same applies if settings change without your permission.
Use this quick comparison to separate a possible infection from more ordinary computer problems:
| Warning sign | Possible explanation | Sensible first check |
|---|---|---|
| Sudden slowness | Malicious process, failing drive or too many apps | Review processor and memory use |
| Repeated pop-ups | Adware, unsafe extension or deceptive website | Close the browser and inspect extensions |
| Unknown account activity | Stolen password or keylogger | Check sessions from a trusted device |
| Disabled protection | Malware interference or expired software | Confirm security status and update source |
| Missing or renamed files | Ransomware, sync error or hardware failure | Disconnect the device and check backups |
Do not install a second “cleaner” offered by a pop-up. Download security tools only from the vendor’s official website or an established Australian technology retailer. The Australian Cyber Security Centre provides general guidance for reporting and responding to cyber incidents, while the Privacy Act 1988 and the Notifiable Data Breaches scheme may become relevant for organisations handling exposed personal information.
Files change or a ransom demand appears
Unreadable documents, strange file extensions, missing folders and a note demanding cryptocurrency are urgent warning signs of ransomware. The same pattern can sometimes result from a damaged drive or a synchronisation fault, so avoid immediately wiping the computer before preserving useful evidence.
Disconnect the device from Wi-Fi and wired networks to reduce the chance of the threat spreading to shared storage. Do not pay a ransom or open more files to investigate. Photograph the message, record what happened and contact your organisation’s IT team, a reputable technician or the appropriate Australian cyber reporting service. If the computer contains business, client or employee information, report the incident internally without delay.
How infections commonly begin
Many infections start with a small decision made under pressure: opening a delivery attachment, enabling macros in a document, installing a pirated application or allowing remote access to someone claiming to be technical support. Public Wi-Fi in a café, airport or hotel does not automatically infect a device, but it makes secure browsing and updated software especially important.
The Australian online market also includes many genuine marketplaces and digital services, which criminals imitate with copied branding and urgent discounts. Check the full sender address, type a company’s website manually and avoid using links in unexpected messages. Keep operating systems, browsers and security tools updated, and use separate strong passwords for email, banking and shopping accounts.
What to do after a warning sign
Stop entering passwords or payment details on the affected computer until it has been checked. Disconnect it from the internet if you suspect active malware, but leave it powered on when professional guidance may require evidence; an IT specialist can advise which approach is safest. Do not connect backup drives until you know the device is clean, because ransomware can encrypt connected backups.
From a trusted device, secure your most important accounts, contact your bank if financial information may be exposed and monitor statements for unfamiliar transactions. Keep records of suspicious messages, dates, phone numbers and file names. The next concrete step is to disconnect the suspect computer from the internet and run a full scan using security software obtained from its official provider.