Signs That Your Computer May Be Infected with Malware
Worked for 20s
Signs Your Computer May Be Infected With Malware in 2026 — The Buff IT Guy’s Guide
Malware does not always announce itself with a flashing warning saying:
“Congratulations, your computer has been hacked.”
Modern malware can be deliberately quiet.
Credential-stealing malware may sit in the background looking for passwords. Ransomware may attempt to spread before encrypting files. Other malicious software can abuse legitimate Windows tools, modify browser settings or interfere with security software.
That makes identifying an infection more difficult than it used to be.
A slow computer, crashed application or strange browser message does not automatically mean malware. Hardware faults, Windows problems and badly behaved software can produce many of the same symptoms.
But when unusual behaviour begins suddenly — particularly when several warning signs appear together — it deserves investigation.
The Buff IT Guy has therefore put down the protein shake and prepared his malware checklist.
Here are some of the signs worth taking seriously in 2026.
1. Your Security Software Starts Warning You
We'll start with the obvious one.
If Microsoft Defender, your Endpoint Detection and Response platform or another managed security tool produces a genuine malware alert, don't simply dismiss it because the computer still appears to work normally.
Modern endpoint security can detect behaviour rather than waiting for a known virus file to appear.
Microsoft Defender for Endpoint, for example, can generate EDR alerts when supported Attack Surface Reduction rules detect suspicious activity. Microsoft's ASR technology specifically looks for risky behaviours frequently associated with attacks, including applications launching suspicious scripts, obfuscated scripts and code injection.
For businesses, alerts like these should normally be investigated centrally by IT or the security provider.
Buff IT Guy Rule #1
Don't repeatedly click “Allow” until the security warning goes away.
Security software isn't trying to ruin your afternoon.
Find out why it is complaining.
2. The Computer Suddenly Becomes Much Slower
Computers becoming slower over several years is normal.
A computer becoming dramatically slower overnight is different.
Malicious processes can consume:
CPU resources
Memory
Disk activity
Network bandwidth
That can result in applications becoming sluggish, fans working harder or the computer appearing busy when you're doing almost nothing.
However, high resource usage alone is not proof of infection.
Windows updates, cloud synchronisation, antivirus scans, browser tabs and legitimate applications can all produce similar behaviour.
Open Task Manager with:
Ctrl + Shift + Esc
Look for unusual CPU, memory, disk or network usage.
If an unfamiliar process is consuming substantial resources, don't immediately delete it or download the first “process cleaner” Google suggests.
Have it investigated properly.
3. Your Browser Starts Behaving Strangely
Browser hijacking and malicious extensions remain useful warning signs.
Watch for things such as:
Your default search engine changing unexpectedly.
Your homepage being replaced.
Searches being redirected.
New toolbars or extensions appearing.
Pop-ups appearing on websites that normally do not show them.
Security warnings telling you to telephone a support number.
Websites repeatedly redirecting somewhere unexpected.
Not every browser problem is malware.
Some are caused by unwanted extensions, adware or websites abusing notification permissions.
But if browser settings keep changing after you correct them, investigate further.
And if a webpage tells you:
“Microsoft has detected 17 viruses. Call this number immediately.”
Do not call it.
Microsoft does not diagnose your computer by making a random website shout at you.
The Buff IT Guy does not either.
4. New Applications or Browser Extensions Appear
You know which applications you installed.
Usually.
If unfamiliar software suddenly appears, find out where it came from.
Potentially unwanted applications sometimes arrive bundled with free software, browser extensions or deceptive installers.
Look for:
Unknown applications.
New startup programs.
Unexpected browser extensions.
Programs with vague names.
Software you don't remember authorising.
Again, don't assume everything unfamiliar is malicious.
Business computers often contain monitoring agents, endpoint-security software and management tools employees may not recognise.
If it is a company computer, ask IT before removing anything.
You do not want to proudly tell your IT provider you have “removed the suspicious hacker software” only to discover you uninstalled their remote-management agent.
5. Security Tools Have Been Disabled
This one deserves attention.
Malware frequently wants less resistance.
If you discover that antivirus protection, the firewall or another security product has unexpectedly stopped working, investigate why.
Microsoft's Windows Security application normally provides continuous real-time protection when Microsoft Defender Antivirus is active. Windows Security also records detected and quarantined threats in Protection History.
Warning signs could include:
Real-time protection repeatedly disabling itself.
Security settings that cannot be changed.
Protection updates failing unexpectedly.
Endpoint-security services disappearing.
Security software generating tamper-related alerts.
There can be legitimate explanations, particularly on managed business computers.
But security controls switching themselves off should never simply be ignored.
Buff IT Guy Rule #2
Malware disabling your antivirus is the digital equivalent of a burglar turning off the CCTV before climbing through the window.
Find out why it happened.
6. You See Suspicious Script or PowerShell Activity
PowerShell is not malware.
It is a legitimate and extremely useful Windows administration tool.
Unfortunately, legitimate administration tools can also be abused by attackers.
Microsoft's current Attack Surface Reduction guidance specifically calls out risky behaviours such as executing scripts that download or run files and running obfuscated or otherwise untrusted scripts.
An ordinary employee does not need to panic because a PowerShell window appeared for half a second during a legitimate software installation.
But repeated unexplained script activity, particularly alongside security alerts or other unusual behaviour, deserves investigation.
This is one area where modern EDR tools are far more useful than simply staring at the computer waiting for something suspicious to happen.
They can provide security teams with evidence about what executed, what launched it and what happened afterwards.
7. You're Getting Unexpected MFA Prompts or Account Alerts
This isn't necessarily evidence that malware is physically installed on your computer.
But it can indicate that your identity has been compromised.
Suppose credential-stealing malware captures a password.
Or perhaps an employee entered Microsoft 365 credentials into a phishing page.
You may begin seeing:
Unexpected MFA approval requests.
Password-reset notifications you didn't initiate.
Sign-ins from unfamiliar locations.
New mailbox rules.
Emails appearing as already read.
Sent messages you didn't send.
That could mean the attacker has moved beyond the device and is now attacking the user's cloud identity.
This distinction matters.
Running an antivirus scan and declaring the computer clean is not enough if the attacker already has access to Microsoft 365.
The password, active sessions, MFA configuration and wider identity environment may also need investigation.
Buff IT Guy Rule #3
Cleaning the laptop doesn't help if the attacker already has the keys to the Microsoft 365 tenant.
Malware investigations need to consider both the device and the identity.
8. Your Files Suddenly Change, Disappear or Become Unreadable
This is one of the most serious signs.
Ransomware commonly makes data unavailable by encrypting files and demanding payment for recovery. The NCSC defines ransomware as malware that prevents access to devices or data, usually through encryption, followed by a ransom demand.
Warning signs might include:
Documents suddenly refusing to open.
Large numbers of filenames changing.
Strange new file extensions.
Folders filling with ransom notes.
Files becoming corrupted.
Shared network files changing rapidly.
If you believe active ransomware encryption is occurring on a business device, treat it as an incident rather than experimenting with the computer yourself.
Contact IT immediately.
The priority may be to isolate affected systems, determine the scope of the incident and prevent further spread.
The NCSC's recovery guidance includes resetting compromised credentials where appropriate, safely rebuilding infected devices and ensuring backups are clean before restoration.
9. Your Computer Is Using the Network When It Shouldn't Be
Many legitimate applications communicate constantly with the internet.
Microsoft 365, OneDrive, Teams, browsers, Windows Update, antivirus platforms and backup services all generate network traffic.
So network activity isn't inherently suspicious.
However, unusual sustained traffic while the computer is otherwise idle can be worth investigating.
Particularly when accompanied by:
Unknown processes.
Security alerts.
Unexpected account activity.
Poor performance.
Connections to suspicious destinations.
This is another area where business-grade security monitoring can provide significantly more useful information than asking an employee to stare at Task Manager.
The important question isn't simply:
“Is the computer using the internet?”
It is:
“Which process is communicating, with what, and why?”
10. The Computer Starts Crashing or Restarting Unexpectedly
Malware can cause instability.
But so can:
A failing SSD.
Bad RAM.
Overheating.
Driver problems.
Windows updates.
Application bugs.
Power-supply problems.
That makes unexpected crashing one of the least useful malware indicators when considered by itself.
If the computer produces repeated blue screens or unexpected restarts, investigate properly rather than immediately declaring it infected.
This is a good example of why symptoms need context.
A machine that crashes once after installing a graphics driver probably has a software problem.
A machine that suddenly begins crashing while security tools are disabled, unknown processes appear and unusual network activity occurs is a very different situation.
11. Your Storage Space Suddenly Disappears
A rapidly shrinking system drive can have innocent explanations.
Windows updates, temporary files, OneDrive synchronisation and application caches can consume large amounts of space.
But unexplained storage growth can also indicate malicious or unwanted activity.
Rather than buying a “PC cleanup” utility, check:
Settings > System > Storage
and use Task Manager or your management platform to determine what is actually happening.
Again:
Diagnose first.
Delete second.
What Should You Do If You Think Your PC Has Malware?
For a personal Windows PC, Windows Security provides Quick, Full, Custom and Microsoft Defender Offline scans. Microsoft's Offline scan restarts the computer into the Windows Recovery Environment so persistent malware has a more difficult time hiding or defending itself.
For a business computer, the approach should be different.
Don't automatically start downloading random malware-removal utilities.
And don't spend three hours attempting to clean the machine before telling IT.
Report it immediately.
Your IT provider may need to investigate:
Endpoint alerts
User identity
Microsoft 365 activity
Network connections
Other affected devices
Administrator accounts
Backups
Evidence from the original machine
If ransomware or another serious infection is confirmed, rebuilding the device from a known-clean state may be safer than attempting to remove every malicious component manually. NCSC ransomware guidance specifically includes safely wiping infected devices and reinstalling the operating system during recovery.
Don't Forget Your Backups
If malware destroys important information, backups become critical.
But ransomware operators may also target backups.
The NCSC recommends maintaining backups that are appropriately separated from production systems and specifically warns that ransomware may target backups to increase pressure on the victim.
Modern businesses therefore need more than:
“Yes, we have a backup somewhere.”
You should know:
Is it protected?
Who can delete it?
How long is data retained?
Can it actually be restored?
When was restoration last tested?
A successful backup job is useful.
A successful recovery is what matters.
Prevention Is Better Than Malware Removal
Businesses should not depend entirely on employees spotting malware symptoms.
Modern endpoint security can reduce the chance of the attack reaching that stage.
Microsoft's Defender technology includes Attack Surface Reduction controls designed to prevent behaviours attackers commonly abuse, while centrally managed EDR can provide security teams with detection and investigation capability.
Combine that with:
Rapid security updates.
MFA and strong identity security.
Email protection.
Least privilege.
DNS and web filtering.
Managed endpoint protection.
Secure backups.
Employee security awareness.
The objective is to create several chances to stop an attack.
Not one.
The Buff IT Guy Verdict
The biggest mistake is assuming malware always makes a computer obviously broken.
Some malware wants to be noticed.
A lot of it doesn't.
A pop-up every three seconds is suspicious.
But so is an unexplained Microsoft 365 login, disabled endpoint protection or a strange process quietly communicating in the background.
At the same time, don't diagnose malware every time Windows takes ten seconds longer to start.
One strange symptom doesn't prove infection.
Look for unexpected changes, multiple warning signs and security alerts — and investigate them properly.
And on a business computer, report suspicious behaviour quickly.
The sooner an attack is detected, the sooner your IT team can work out what happened, what else may be affected and what needs protecting next.
Worried Your Business Computer May Have Malware?
Hamilton Group can help businesses investigate suspicious devices and provide ongoing protection through managed IT support, endpoint protection and EDR, Microsoft 365 security, managed patching, network security, backup and disaster recovery, vulnerability management and cyber-security monitoring.
Rather than relying on somebody noticing that their computer “feels a bit strange”, modern monitoring can help identify potentially malicious behaviour and give IT teams the information needed to investigate it.
And when your team needs IT support, our aim is to make first contact within 15 minutes.
Call Hamilton Group on 0330 043 0069 or visit hgmssp.com to speak with one of our IT and cyber-security experts.