At a glance
Malware can put your personal information, accounts and devices at risk. If your device has been infected with malware, follow these steps to detect and remove it.
These steps can help to reduce the risk of future attacks. Not all malware attacks are the same, so some of these steps may not apply to your situation. If you’re unsure what to do, consider seeking help from an IT professional.
Emergency help: If there is an immediate threat to life or risk of harm, call 000.
Before removing malware, check if these situations apply to you:
- If you can’t access your files or have received a ransom note, your device might be infected with ransomware. Learn more about ransomware.
- If you think malware has infected one of your accounts, learn how to recover from account compromise. Secure important accounts first, such as email, bank and online payment accounts.
- Avoid entering passwords or other sensitive information on an infected device. Some malware can record what you type and steal your information. If you need to change your passwords, use a device that is free from malware.
If you want to talk to someone, call our hotline on 1300 CYBER1 (1300 292 371). We’re available 24 hours a day, 7 days a week.
How to detect and remove malware from your device
You can reduce further harm by taking immediate action.
Step 1. Check your antivirus software
Make sure your antivirus software is turned on and is up to date.
Most devices already have antivirus software installed:
- Windows 10 and Windows 11 include Microsoft Defender.
- MacOS devices include XProtect.
- You may also have installed third-party antivirus software.
Check that your antivirus software is receiving the latest updates. If your subscription has expired, renew it or switch to a free antivirus product.
Learn more about antivirus software.
Step 2. Disconnect your device
Turn off your Bluetooth and Wi-Fi. Disconnect your device from any networks, other devices and external storage devices. This helps prevent the malware from spreading.
Step 3. Run a full device scan
Use your antivirus software to run a full scan. This will detect and remove malware from your device. This scan can take a long time to complete.
Depending on the device, your instructions may be different:
- For third-party antivirus software, follow the instructions within your software program.
- For Windows Defender, do a quick scan using the Windows Security app.
- For MacOS without third-party antivirus software and you find signs of Malware, assume XProtect has not detected or blocked the malware.
Step 4. Back up your files
Before you wipe your device, back up important information. Only back up files if you’re confident they’re not infected with malware.
It’s usually safe to back up photos, videos, contacts and messages to your device’s cloud service. For laptops and computers, you can also copy these files to a clean external hard drive.
Learn more about how to back up your devices.
When backing up your photos, don't just check your camera roll or photos app. Also check:
- photos people have sent you
- messaging apps
- other folders or albums on your device.
If you want to back up other types of files, speak to an IT professional first.
Learn more about how to back up your files.
Step 5. Safely wipe devices
Wiping your device will permanently delete your information. Make sure you’ve backed up important files and recovered any information you need before continuing.
Phones and tablets
To remove malware, you need to factory reset your device.
Depending on the device manufacturer, your steps may differ. Visit their website for guidance:
- Apple: Restore your iPhone, iPad or iPod to factory settings
- Samsung: Factory reset Samsung phone
- Google: How to factory reset your Google Pixel phone.
Laptops and computers
Remove malware by wiping infected drives and devices and reinstalling their operating systems.
Malware can spread across a network. We recommend wiping all drives and devices that were connected to the same network during or after the infection.
Depending on the device manufacturer, your steps may differ. Visit their website for guidance:
- Apple: Erase your Mac and reset it to factory settings
- Microsoft: Reset your PC.
Step 6. Restore information
After wiping your device, restore the information you backed up in step 4.
Only restore information from a backup if you’re confident it’s free from malware.
Visit your device manufacturer’s website for specific instructions:
- Apple: Restore your iPhone, iPad or iPod touch (includes Mac laptops and computers)
- Google: Back up or restore data on your Android device
- Microsoft: Back up and restore with Windows Backup.
Step 7. Change passwords
Some types of malware can steal your passwords. Change the passwords of any accounts you accessed from your infected device as soon as possible.
Start with your most important accounts, including:
- cloud storage
- social media
- online banking
- business accounts.
Use strong, unique passwords for each account. For extra protection, turn on multi-factor authentication (MFA) where available. This makes it harder for cybercriminals to access your accounts. Passkeys are one of the most secure forms of MFA and also provide amore secure way to log in to your online accounts than using a password.
Step 8. Notify and report
Report a cybercrime or security incident to us.
It can be difficult to know how your device was infected with malware. If you suspect your device was infected as part of a scam, report the incident to Scamwatch.
Additional reporting responsibilities for businesses
Depending on the impact of the attack, you may have to notify your customers.
You may need to report the incident to regulators, if your business:
- holds sensitive information such as financial or personal information
- is part of a government supply chain.
If you think you need to make a report, consult with the Office of the Australian Information Commissioner. You can also seek legal or government support.
You may also need to contact:
- The compromised website or product owner: If the malware came from a compromised website or product, report it to the owner. Only use an official email or phone number. This helps protect others from harm.
- Services Australia: If you’ve sent personal details or money to someone pretending to be from a government service, contact the Services Australia Scams and Identity Theft Helpdesk.
- IDCARE: If your personal information is at risk from a data breach, contact IDCARE. They’re a national identity and cyber support service for individuals and organisations.
- Australian Taxation Office (ATO): If someone has stolen your personal or business identity, contact the ATO. You must report all tax-related security issues to them.
Step 9. Check for suspicious or unusual activity
After removing malware from your device, monitor your accounts for signs they have been compromised.
If you find any suspicious activity, learn how to recover from account compromise.
Malware incidents can also result in identity theft. Learn more about identity theft.
Step 10. Protect yourself from future attacks
Consider how malware got onto your device. This can help you prevent it from happening again.
Malware can get onto a device in many ways, such as:
- clicking on a suspicious link in an email or text message
- downloading a file from an untrusted source
- installing a fake or unsafe applications
- visiting a malicious website
- using outdated software with security weaknesses.
Once you know how the malware got onto your device, take steps to protect yourself. This can include being more careful with links and downloads, and keeping software updated.
Learn how to stay secure online.
Keep up to date with our latest advice and guidance by joining our partnership program.