Skip to content
Malware

Malware on a work device: the alert fired — now what

The antivirus flagged something, or the machine started behaving strangely. What you do next either hands responders a clean picture or smears it.

Malware on a work device: the alert fired — now what — Response Red advisory illustration

The essentials

  • Disconnect from the network but leave the machine powered on — the standing rule for preserving evidence.
  • Report to IT before attempting any cleanup; "I removed it myself" usually means the evidence is gone and the persistence is not.
  • An antivirus "threat removed" message is not an all-clear — loaders drop payloads that the first detection may have missed.
  • Every credential typed on that device recently should be treated as potentially captured.
  • Write down what you saw and when: the popup, the slowdown, the file you opened.

Malware detections put people in cleanup mode: delete the file, run three scanners, reboot twice, relief. The problem is that modern malware arrives in stages — the thing detected is often the delivery vehicle, and the question that matters is what it delivered before dying.

Your job is not to clean the machine. It is to freeze the situation and report it well.

Do this now

  1. Disconnect, keep it running. Wi-Fi off or cable out. Memory holds the running processes and connections responders need; power-off destroys them.
  2. Stop using it. No logins, no email checks, no "one last file". Every action overwrites something.
  3. Report with specifics. What the alert said, what you opened or installed beforehand, when the machine started acting oddly. The timeline is the investigation's spine.
  4. Rotate what the machine knew. From a different device, change passwords used on the infected machine recently — email and anything privileged first.
  5. Hand it over. Let security image or scan it properly. If the verdict is a commodity adware nuisance, you lose an hour; if it's a stealer or a foothold, you just saved the company weeks.

What not to do

  • Do not run additional cleaner tools from the internet — some are malware, and all of them trample evidence.
  • Do not keep working on the machine "carefully".
  • Do not delete the suspicious file or empty quarantine; that is the sample.
  • Do not hide that you installed something unofficial — the origin story shortens the investigation by days.
  • Do not plug in USB drives to "rescue" files first.

Preserve the evidence

Whatever else happens, these are the artifacts the investigation — and any insurance claim, dispute, or prosecution — will be built from:

  • The alert text or a photo of it.
  • What was opened, downloaded, or installed before symptoms began.
  • The symptom timeline with times.
  • The device itself, isolated and powered on.

Keep a clear head

A firing alert means the system worked — treat it as the smoke detector doing its job, not a verdict on you. Reporting fast with an honest origin story is the highest-value move available, and good security teams treat it exactly that way.

Questions victims ask

The antivirus says it removed the threat. Are we done?

Not necessarily. Detection often catches one stage of a multi-stage infection. Whether anything else landed — a stealer, a backdoor, persistence — is what a proper look at the machine answers.

How did it get in when I didn't do anything unusual?

Malvertising, a poisoned search result, a compromised legitimate site, an email attachment that looked routine — infection paths today don't require carelessness. Origin matters for defense, not for blame.

It's my personal laptop, but my work email was on it. Does IT need to know?

Yes. Work sessions and credentials on an infected personal device are a corporate exposure regardless of who owns the hardware. Expect a password rotation and possibly conditional-access checks, not a reprimand.

When the first hour is over, we take it from there.

Scoping, containment, forensics, and recovery — expert-led and evidence-safe, with AI removing the waiting. Engage a responder or talk to us about readiness.