Malware: how it gets onto a family device, and what to do next
Almost nothing arrives unaided. On a home device malware needs a click, an install or a permission. That is good news, because those are things a household can decide about.
The mental picture most people carry is of an attack that happens to a computer. On a family device the reality is duller and more manageable: something was downloaded, something was installed, or a permission was granted. Each of those is a moment a rule can cover.
The four routes that matter at home
Downloads that are not what they claim: a game crack, a free version of paid software, a codec a video page insists you need. This is the largest single route on a child’s computer and it is entirely voluntary.
Fake buttons and prompts: a download arrow that is an advert, an alert that your device is infected, a page insisting an update is required. These belong to the same family as scam websites and are covered on that page too.
Apps from outside the official stores, particularly on Android, where installing from a browser is possible. And browser extensions, which ask for sweeping permissions and get granted them because the permission screen is boring.
What it looks like when something is wrong
Sudden slowness with the fan running, a browser homepage or search engine that changed itself, extensions nobody installed, adverts appearing inside applications, or accounts logging out unexpectedly. On a phone: rapid battery drain, unexplained data use, or an app you do not recognise.
None of these is conclusive on its own; an old laptop is slow for ordinary reasons. Two or three together, arriving after a download, is a pattern worth acting on.
What to do after a click, in order
Disconnect from the network if a download completed, so anything that arrived cannot fetch the rest of itself. Then run a full scan with the security software already on the device, uninstall anything you do not recognise, and reset the browser.
Then change passwords, from a different device and starting with the email account, because it is the reset route for everything else. That order matters: changing passwords on a compromised device hands over the new ones.
What actually prevents it on a family device
Keep the device updated, because most of what circulates targets holes that were fixed months ago. Do not use an administrator account for daily use, so an install requires a deliberate step and a password.
Require approval for app installs (the setting is in every guide on the setup pages) and agree the house rule that free versions of paid things are the single most reliable way to lose an account. The built-in security software on a current system is adequate; a second paid scanner adds far less than either of the first two habits.
The infected-computer pop-up, and the call that follows
One family of these deserves naming separately, because it bridges into a phone call. A page announces that the device is infected, sometimes with an alarm sound and a number to ring. Nothing is infected; the page is the whole of it.
Calling the number reaches someone who will ask for remote access and then either install something real or charge for a repair that was never needed. The tell is simple and absolute: a web page cannot scan a computer, so it cannot know.
The response is to close the tab, and to force-quit the browser if the page will not let you. Then say the sentence out loud in the house, because this is the one that catches adults far more often than children.
What to do
- Disconnect from the network if a download finished.
- Run a full scan with the security software already installed.
- Uninstall what you do not recognise, then reset the browser and remove extensions.
- Change passwords from a different device, email account first.
- Turn on automatic updates and stop using an administrator account day to day.
- Set app installs to require approval on every device in the house.
Questions about malware
Do we need to buy antivirus software?
On a current, updated system the built-in protection is adequate for a household. Updates and not running as administrator both do more than a second scanner, and paid suites often add browser extensions that create their own problems.
My child downloaded a game crack. How bad is that?
It is the highest-risk category on a home computer, because the file has to be run with permission and it is impossible to verify. Assume something arrived, scan, and change the passwords for anything that was signed in on that device.
Is a phone safer than a laptop?
Generally yes, while apps come only from the official store. The risk rises sharply with sideloaded apps and with extensions or profiles installed from a browser.
Can a website infect a device without a click?
It is possible against an unpatched system, which is the argument for automatic updates. In practice, on a maintained device, almost everything needs a click or an install.
Should I factory-reset after an infection?
It is the reliable answer where something persistent is suspected, and it is often less work than chasing symptoms. Back up the documents, not the applications, and change passwords from a clean device first.
What about the router?
Worth checking once: change the default administrator password, apply firmware updates, and confirm the DNS settings have not been altered. It is rarely the cause and it is occasionally the reason a problem keeps coming back.