New processes or apps you didn’t install
Sudden pop-ups, redirects, or extensions appearing
CPU/disk spikes and security tools turning off or failing to update
Fake updates and bundled “free” installers
Phishing attachments or links (archives, scripts, macros)
Malvertising and drive-by downloads from sketchy sites
Disconnect from the internet to stop more payloads.
Run a full anti-malware scan; quarantine everything found and reboot.
Check startup items, scheduled tasks, services, and browser extensions; remove unknowns.
From a clean device, change passwords and enable MFA (in case a stealer was dropped).
Review firewall/DNS logs for domains contacted and block them.
Install software only from official sources; avoid cracks and “free” codecs.
Keep OS, browsers, and plugins patched; block macros by default.
Use reputable EDR/anti-malware and email/web filtering.