The obvious infections are the easy ones. A screen full of pop-ups is annoying, but at least you know something is wrong. The malware that costs people the most is the quiet kind: it sits in the background for weeks, skimming passwords and browsing habits, while the machine looks mostly normal. This is a guide to spotting that kind, the nine signs that are easy to explain away and shouldn't be.
- Modern malware often hides instead of announcing itself, so "my computer still works fine" isn't proof it's clean.
- Slowness, overheating, and browser weirdness all have innocent causes too. It's the pattern of several signs together that points to an infection.
- The most dangerous kinds steal passwords and banking logins quietly, or hand remote access to someone else.
- Basic antivirus scans miss the parts that dig in. If problems come back after a scan, the cleanup wasn't deep enough.
Where infections actually come from now
It helps to know how malware gets on a machine, because it's rarely the shady thing people picture. The common routes:
- A browser extension that looked useful, or that quietly changed hands and turned malicious in an update.
- A "free" version of paid software, or a cracked app from a torrent. These are one of the most reliable ways to get infected.
- An email attachment or link that looked like it came from someone real.
- A fake "update your Flash / your browser / your driver" prompt on a sketchy site.
Notice none of these require you to be careless. Good extensions go bad, and fake prompts are getting harder to tell from real ones. Microsoft keeps a plain-English rundown of how Windows Security and Defender handle this if you want the official version.
1. Slow, but only sometimes
Malware eats CPU, memory, and bandwidth, so an infected machine feels sluggish. But so does an old one. The tell is inconsistency: it's fine, then it grinds to a halt for no reason you can see, then it's fine again. That pattern often lines up with the malware waking up to do its thing.
Open Task Manager (Ctrl+Shift+Esc) and look at what's using the CPU when the machine is idle. A process you don't recognize sitting at 40% while you're doing nothing is worth a hard look. Plain slowness with no mystery process is more likely a full drive or aging hardware, which is a different fix.
2. It overheats when it should be resting
You're not doing anything heavy, but the fan is loud and the machine is hot. Something is running the processor hard behind the scenes. Crypto-mining malware is the classic cause. It uses your hardware to mine currency for someone else, and you get the heat, the fan wear, and the electricity bill.
Left long enough, constant heat isn't great for the machine either. It won't melt anything, but it wears out fans and stresses components sooner than they should.
3. Your browser has a mind of its own
Search results send you somewhere other than where you clicked. The homepage reset itself. A search engine you never chose is now the default. Random tabs open on their own. That's a browser hijacker, and the reason it exists is money: it reroutes your traffic and, in the worse cases, watches what you type into forms. Including logins.
4. Signs someone else has been in your accounts
This is the one that keeps people up at night, and rightly. Watch for:
- Login alerts or "new device" emails you didn't trigger.
- Passwords that suddenly stop working, or that you know you didn't change.
- Sent emails or messages you never wrote.
- Your webcam light flicking on when nothing's using it.
Some malware exists purely to give an attacker remote control of your machine. If you think that's happened, treat every password as compromised and change them from a different, clean device.

5. Your security software got switched off
A lot of malware's first move is to disable the thing that would catch it. So if your antivirus won't open, Windows Defender is mysteriously off, scans quit halfway, or Windows updates have stopped installing, don't assume it's a glitch. Something turning off your defenses is a strong sign it's already inside.
6. Scary pop-ups asking for money
Full-screen warnings that your PC is infected, that you've been hacked, that you need to pay right now or call a number. This is scareware, and none of it is real. The whole point is panic. It wants you to either pay a scammer, install their "fix" (more malware), or call the number and let them remote in.
Microsoft and Apple do not put phone numbers on error screens, ever. A warning page with a number to call is always a scam. Don't call it, and don't let anyone who "called about your computer" connect to it.
7. Programs and extensions you never installed
Malware likes to bring friends. A new toolbar, a browser extension you don't remember adding, an unfamiliar program in your startup list, an app in your tray you can't place. Each one is worth questioning. Many of these quietly load every time Windows boots, which is part of why the machine feels slower over time.
8. Files moving or vanishing on their own
Documents disappearing, showing up in the wrong place, or renamed with an extension you don't recognize. That last one can be an early sign of ransomware starting to encrypt your files. If you catch files being renamed en masse, that's a stop-everything moment: shut the machine down and disconnect it before it finishes.
9. Windows won't start right after all this
The severe end. Boot loops, black screens, "startup repair" that never repairs, crashes before you even reach the desktop. Some infections damage the files Windows needs to load, or the storage they sit on. At that point you can't clean it from inside Windows because Windows won't run, and it needs a proper offline repair.
The myth that costs people the most
Here's the belief that does the real damage:
"If I can still use my computer, the virus can't be that bad."
The quiet infections are the expensive ones precisely because the machine keeps working. Nothing looks broken while a keylogger reads your banking password or spyware copies your files. "It still works" tells you nothing about whether it's clean.
What to try yourself, and where it stops
If you've caught it early, a careful DIY pass is reasonable:
- Disconnect from the internet.
- Run a full scan with a trusted, up-to-date antivirus.
- Go through your browser extensions and remove anything you don't recognize.
- Check your startup programs and disable the ones you can't account for.
- Uninstall recently added software you didn't intend to install.
- Update Windows once you're back online.
The reason this doesn't always hold is that antivirus removes the file it recognizes but leaves the machinery around it: registry changes, scheduled tasks, a hijacked browser, a persistence hook that quietly reinstalls the whole thing on the next reboot. That's why the pop-ups or redirects come back a few days later. When that happens, the cleanup needs to go deeper than a scan.
When to stop scanning and get help
Hand it over if any of these are true:
- The infection keeps coming back after you've scanned and removed it.
- Banking, email, or saved passwords might be exposed.
- The machine constantly crashes or won't start.
- Files are encrypted or you're locked out.
At that point you're not looking for a stubborn file, you're looking for what it left behind and what it may have taken. That's worth a proper diagnosis rather than another scan.
We clean Windows PCs and Macs across Calgary, in your home or remotely, and check whether anything was left behind or leaked. The diagnosis is free, you get a flat quote before any work, and if a cleanup isn't worth it on that machine, we'll say so.
Want the longer version of what a thorough cleanup actually involves? Read what a proper cleanup involves.




