What is malware?
Malware, a contraction of malicious software, is harmful software created to damage, spy on or exploit your systems without your knowledge. Malware hits everything from private PCs to company servers and typically spreads via phishing emails, infected attachments, fake downloads and vulnerabilities in software that has not been updated. The Danish Centre for Cyber Security continuously assesses the threat level against Denmark, and cybercrime consistently sits at the high end.
The 6 types of malware
- Virus: Attaches itself to files and programs and spreads when they are shared or opened.
- Worm: Spreads by itself through the network without anyone having to click anything.
- Trojan: Pretends to be a legitimate program, but opens a backdoor for the attacker when installed.
- Spyware: Covertly monitors keystrokes, screen and behaviour, stealing passwords and payment details.
- Adware: Floods the machine with adverts and collects data about your behaviour, often as a stowaway in free software.
- Ransomware: Encrypts your files and demands a ransom for the key, the most expensive and destructive type for businesses.
In practice, modern attacks combine several types: a trojan opens the door, spyware steals passwords, and finally ransomware is deployed.
How to spot malware
Classic symptoms are a machine that suddenly slows down, unknown programs and pop-up windows, a browser that changes its start page, or colleagues receiving strange emails from your address. But beware: modern malware is designed to be invisible and can lie hidden for months while stealing data. That is why behaviour-based monitoring with EDR matters more today than waiting for visible symptoms.
Malware removal: do not do this yourself
The temptation is strong to just run a scan and delete whatever it finds. That is a bad idea for three reasons:
- Reinfection: If you only remove the visible part, persistence mechanisms often remain behind and reinstall the malware after a reboot.
- Hidden backdoors: Many infections install extra remote access that an ordinary antivirus scan will not catch. The attacker simply comes back in.
- Preserving evidence: If you delete files and logs, you destroy the ability to establish what the attacker had access to, which can be decisive for GDPR notification and insurance.
The right first step is to isolate the machine from the network, leave it switched on and call in professional help, so the infection can be analysed and removed completely.
How MI Support IT can help
We prevent malware with update management, endpoint protection and continuous monitoring as part of our IT security solutions, and if malware is already on a machine, we help contain, analyse and clean up properly. Contact us if you suspect an infection or want your defences in order before things go wrong.