Knowledge Base / Software / Malware Response Workflow
Problem
Practical checks for malware response workflow. Follow the safe steps below and contact your support team if the issue continues.
These are general troubleshooting checks, not a confirmed diagnosis. Follow your organization's procedures and stop if a step could risk data, safety, or managed equipment.
Symptoms to check
- A user reports pop-ups, unusual file changes, slowed performance, or suspicious redirects.
- The issue may affect one device or spread across multiple endpoints.
Possible causes
- Malware, phishing activity, or unsafe software downloads may have infected the device.
- Suspicious browser add-ons or unsafe scripts can also compromise a system.
Resolution
- Immediately isolate the device from the network if policy allows, especially if the user reports suspicious credential activity or ransomware indicators.
- Do not continue using the device for sensitive work. Capture the symptoms, recent downloads, and any suspicious messages or websites.
- Run approved antivirus and endpoint security tools, then follow the organization’s malware-removal or incident-response process. Do not delete files or disable security tools without authorization.
- Review recent email messages, browser activity, and installed software for anything unusual. If credentials may have been exposed, reset passwords and notify the security team.
- After cleanup, reconnect the device only after approval and confirm the system is stable before returning it to service.
Prevention and preparation
- Keep endpoint protection current and train users never to click unknown links or attachments.
- Document malware incidents and review whether the user or device needs additional monitoring.
Related guides
Still not fixed? Log a support request and include the exact error, who or what is affected, and the steps you already tried. Never include passwords or verification codes.
Submit a ticketLast reviewed: October 2026