What Is Malware? Types, Warning Signs and How to Remove It
A plain-language guide to malware: what it is, the main types like viruses and trojans, how infections happen, warning signs, and how to remove and prevent it.

Malware — short for "malicious software" — is any program or code written to damage a device, steal data, or gain unauthorized access to a system without the owner's consent. It is the umbrella category that includes viruses, worms, trojans, ransomware, spyware, adware and rootkits, each of which spreads and behaves differently but shares the same basic goal: doing something on your device that you did not agree to.
- Malware is the umbrella term; ransomware, spyware and adware are specific types of malware, not separate categories of threat.
- The National Institute of Standards and Technology (NIST) defines malware as software or firmware that performs an unauthorized process with an adverse impact on a system's confidentiality, integrity or availability.
- Most infections still start with something a person does — opening an attachment, clicking a link or installing an app — rather than a silent, automatic attack.
- Microsoft Defender's built-in offline scan is a free, no-install way to remove malware that hides from a normal Windows antivirus scan.
- No single tool prevents every infection; patching, backups and cautious clicking matter as much as antivirus software.
What Is Malware, Exactly?
In plain terms, malware is software built to do something harmful to a computer, phone or network, usually without the user realizing it is happening. The Cybersecurity and Infrastructure Security Agency (CISA) describes it as "unwanted files or programs that can cause harm to a computer or compromise data stored on a computer." NIST's official glossary gives a more technical version: software or firmware intentionally inserted into a system to perform an unauthorized process that harms the confidentiality, integrity or availability of that system.
Both definitions point at the same idea. Malware is not one piece of code — it is a category that covers many different techniques attackers use to infect a device, each with its own method of spreading and its own objective, from quietly logging what you type to encrypting every file on a hard drive and demanding payment to unlock it.
Malware vs. Ransomware, Phishing and Social Engineering: What's the Difference?
These terms get used interchangeably in headlines, but they describe different parts of an attack:
- Malware is the malicious software itself — the program that runs on the victim's device.
- Ransomware is one specific type of malware: it encrypts or locks a victim's files or systems and demands a ransom for the decryption key.
- Phishing is not malware at all — it is a delivery method, a fraudulent email, text or website used to trick someone into handing over credentials or running a malicious file that then installs malware.
- Social engineering is the broader psychological manipulation tactic (urgency, authority, fear) that phishing and many other scams rely on to get a victim to act.
- A zero-day vulnerability is a software flaw attackers can exploit before a patch exists — it is a way malware gets onto a device, not malware itself.
In short: phishing and social engineering are how an attacker tries to trick you; a zero-day vulnerability is a door they can walk through without tricking you at all; and malware, including ransomware, is what runs once they are inside. This explainer focuses on malware as the umbrella category — what the main types are, how they get in, and how to spot and remove them.
The Main Types of Malware
Security researchers group malware into categories based on how it behaves and spreads. The same piece of malicious code can sometimes blend more than one of these traits, but the classic categories, as described by Microsoft and documented on Wikipedia, are still the clearest starting point.
| Type | What it does | How it typically spreads |
|---|---|---|
| Virus | Attaches itself to a legitimate file or program and corrupts or deletes data once that file is opened | Hidden inside another seemingly harmless program or document; needs a user to open the infected file |
| Worm | Copies itself and spreads automatically across a network | Exploits software vulnerabilities; does not need a user to click or open anything |
| Trojan horse | Disguises itself as legitimate or useful software while secretly installing a backdoor, keylogger or other payload | Downloaded voluntarily by the user, often bundled with pirated or "free" software |
| Ransomware | Encrypts or locks files/systems and demands payment for the decryption key | Phishing emails, stolen credentials, exploited vulnerabilities |
| Spyware | Secretly monitors browsing activity, keystrokes or login credentials | Bundled with other downloads or installed through exploited security holes |
| Adware | Displays unwanted advertisements, often as pop-ups; can slow the device and change browser settings | Bundled with free software installers; some variants disable antivirus protection |
| Rootkit | Modifies the operating system to hide other malware and can grant attackers administrator-level control | Installed via an exploited vulnerability or alongside another piece of malware |
Two related terms you will also see: a botnet is a network of malware-infected devices an attacker controls remotely, often to send spam or launch distributed denial-of-service attacks, and cryptojacking malware hijacks a device's processing power to mine cryptocurrency, which is why an infected machine can run hot and loud even when it looks idle.
How Malware Infects Phones and Computers
Despite decades of warnings, the overwhelming majority of infections still rely on a handful of well-worn entry points, according to CISA's guidance on protecting against malicious code:
- Email attachments and links — malicious attachments, or links to compromised or fake web pages, remain one of the most common delivery methods, which is why phishing emails and malware are so closely linked.
- Infected removable media — USB drives and other external media can carry a virus that launches automatically when plugged in, or a user opens an infected file on them.
- Malicious or compromised websites — simply visiting a booby-trapped page, or clicking a deceptive pop-up, can trigger a "drive-by download."
- Bundled or pirated software — free downloads, cracked software and some browser extensions are classic trojan horse delivery vehicles.
- Unpatched software vulnerabilities — worms and some ransomware spread by exploiting known flaws in operating systems or server software that have not been patched, which is also how a zero-day vulnerability can be weaponized before a fix even exists.
- Malicious data files — documents, PDFs, images and compressed archive files can be crafted to exploit a flaw in the program used to open them.
- Weak or reused passwords — credential-based attacks let intruders log in directly and plant malware without needing a victim to click anything at all.
Warning Signs of Malware on a Windows PC or Mac
Modern malware is built to stay quiet, so there is rarely one single "you've been hacked" moment. According to CISA and Microsoft's guidance, the signs to watch for include:
- The computer runs noticeably slower, freezes, or stops responding — CISA notes this can happen when a worm consumes system resources.
- Unexpected pop-ups, new browser toolbars, or your browser's homepage and default search engine changing without your doing it.
- Programs opening, closing or crashing on their own, or new icons and applications appearing that you did not install.
- The fan runs constantly or the device runs hot even when idle — a sign Wikipedia's documentation on cryptomining trojans associates with hidden background processes.
- Security software is disabled, won't update, or you cannot access certain security-related websites.
- Unauthorized or unusual activity in your online accounts, especially banking activity you did not initiate.
Warning Signs of Malware on an iPhone or Android Phone
The same underlying mechanics apply to phones as to PCs: infected apps and malicious links run hidden processes that consume the device's resources and try to access data or accounts without permission. In practice, that tends to show up as:
- Battery draining much faster than usual, or the phone feeling warm even when you're not actively using it.
- A noticeable spike in mobile data usage you can't account for, since some malware communicates with a remote server in the background.
- Apps you don't remember installing, or an existing app suddenly asking for permissions (contacts, messages, location) it doesn't need.
- Unexpected pop-up ads appearing outside the browser, or the phone redirecting to unfamiliar web pages.
- Unusual outgoing texts, calls or app purchases, or friends receiving messages or links from you that you didn't send.
If several of these appear together, treat it the same way you would a PC infection: stop entering passwords or payment details on the device, update and run your phone's built-in security scan or a reputable mobile security app, and review the account activity CISA recommends watching for unusual logins or purchases.
How to Remove Malware From a Windows PC
Microsoft's own troubleshooting guidance for Windows lays out a clear sequence for getting rid of a stubborn infection:
- Update your protection first. In Windows Security, turn on cloud-delivered protection and automatic sample submission, then check for the latest threat definition updates before scanning.
- Run a full scan. Open Windows Security > Virus & threat protection and run a scan so Microsoft Defender Antivirus — or your third-party antivirus — can detect and quarantine known threats.
- Run an offline scan for anything that keeps coming back. Under Virus & threat protection > Scan options, choose Microsoft Defender Offline scan. Save your work first, because the PC restarts and scans outside of Windows — which lets it catch malware designed to hide while Windows is running, according to Microsoft's support documentation.
- Free up disk space and close other programs if a scan repeatedly fails to finish or remove a detected threat, since low disk space on the system drive and competing running programs can interfere with cleanup.
- Change your passwords for important accounts once the device is clean, since CISA recommends assuming credentials entered on an infected machine may have been captured.
- Restore from a known-clean backup if the infection has damaged or encrypted files and a scan alone can't fix it. Back up regularly, in advance, to a drive or cloud service that isn't permanently connected to the infected machine.
How to Remove Malware From a Phone
- Boot into safe mode (Android) to stop third-party apps from running, then uninstall anything unfamiliar or recently added before the problems started.
- Delete the suspicious app directly from Settings > Apps if you can identify it, or run a scan with your phone's built-in protection or a mainstream security app from the official app store.
- Update the operating system and all apps immediately afterward, since outdated software is one of the most common ways a device gets reinfected.
- Review account activity and change passwords for anything you logged into on the device, prioritizing email, banking and any account tied to two-factor recovery.
- As a last resort, back up your data and factory reset the device if the infection persists, then restore only your photos, contacts and files — not reinstalled apps — from backup to avoid reintroducing the malware.
How to Prevent Malware: A Quick-Reference Checklist
CISA's guidance on protecting against malicious code and Microsoft's security guidance both converge on the same fundamentals. None of these is a silver bullet alone, but together they close most of the entry points described above:
- Keep antivirus or anti-malware software installed and updated, and make sure real-time protection is turned on, not just scheduled scans.
- Install software and operating system updates promptly, ideally with automatic updates enabled, since unpatched vulnerabilities are a direct path for worms and exploit-based malware.
- Think before you click on email attachments or links, even from senders you recognize, and verify unexpected requests through a separate channel.
- Download software only from official sources — app stores and vendor sites — and avoid cracked or pirated software, which is a common trojan horse vector.
- Use a firewall and turn on pop-up blocking in your browser, and browse day-to-day from an account without administrator rights.
- Use strong, unique passwords and multi-factor authentication for every account; a password manager makes this practical across dozens of accounts without reusing credentials.
- Disable AutoRun/AutoPlay for USB drives and other removable media so an infected device can't launch malware automatically.
- Back up important files regularly to a drive or cloud service that isn't constantly connected, so ransomware or a corrupted system doesn't cost you your data.
- Monitor your accounts for unusual activity and contact your bank or provider immediately if something looks wrong.
Malware isn't going away, and new variants emerge constantly, but the defenses that work are unglamorous and consistent: patch promptly, back up often, question unexpected links and attachments, and keep a real-time scanner running. Those habits stop the overwhelming majority of infections described in CISA's and Microsoft's own guidance, long before a device ever shows a warning sign.
Frequently asked questions
What is malware?
Malware (short for malicious software) is any program or code designed to damage a device, steal data, or gain unauthorized access to a system without the owner's consent. It is an umbrella term that covers viruses, worms, trojans, ransomware, spyware, adware and rootkits.
What is malware in cyber security?
In cyber security, malware refers to software or firmware intentionally inserted into a system to perform an unauthorized action that harms the confidentiality, integrity or availability of that system, as defined by NIST. It includes everything from viruses and worms to ransomware and spyware.
What is malware on my phone?
Malware on a phone is a malicious app, file or link that runs hidden processes on the device, often to steal data, spy on activity, or rack up charges. Common signs include fast battery drain, unexplained data usage spikes, unfamiliar apps, and unexpected pop-up ads.
What is a malware infection?
A malware infection happens when malicious code successfully installs and runs on a device, typically after a user opens an infected attachment or file, clicks a malicious link, installs a bundled program, or a vulnerability is exploited without any user action at all.
Is a computer virus the same thing as malware?
No. A virus is one specific type of malware that attaches itself to a legitimate file and spreads when that file is opened. Malware is the broader umbrella category that also includes worms, trojans, ransomware, spyware, adware and rootkits.
Can malware be removed without a full factory reset?
Often, yes. Running an updated antivirus scan, or on Windows a Microsoft Defender offline scan, removes most infections. A factory reset is generally only necessary as a last resort when an infection persists after scanning and cleanup.
Sources
- CISA: Protecting Against Malicious Codecisa.gov
- CISA: Malware, Phishing, and Ransomwarecisa.gov
- NIST Computer Security Resource Center: Malware (Glossary)csrc.nist.gov
- Microsoft Security 101: What Is Malware?microsoft.com
- Microsoft Support: Troubleshoot Problems With Detecting and Removing Malwaresupport.microsoft.com
- Wikipedia: Malwareen.wikipedia.org
Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.


