What should you actually do first if you think you have malware?
Disconnect from the network, then work through a sequence — because the instinct to start deleting things immediately can destroy evidence, spread the problem, or do nothing at all while the real cause persists.
The order that matters:
Disconnect from the internet. Unplug the cable or turn off Wi-Fi. This stops data being exfiltrated, stops the machine receiving instructions, and stops it reaching other devices on your network. Do this before anything else.
Do not turn it off immediately if ransomware is suspected and files are being encrypted — disconnecting stops the spread, and shutting down can lose recovery options. Otherwise powering off is fine.
Do not log into anything from the affected device, including to "check" whether accounts are safe. Use a different device.
Change passwords from a clean device, starting with email — because email is the recovery route for everything else — then banking, then anything reusing the same password.
Check for unauthorised access: mail forwarding rules, added recovery addresses, new devices on accounts, and filter rules that hide alert emails. Attackers set up forwarding rules routinely, and they survive a password change.
Scan with a reputable tool, ideally more than one, and from a boot medium if the system is compromised enough that it cannot be trusted to scan itself.
Recognising what is not malware. A great deal of suspected infection is something else:
Browser notification spam, granted permission by an accidental click, which looks like system alerts and is fixed in browser settings.
Scareware pop-ups claiming infection and demanding a call — never phone the number, which is the actual attack.
Unwanted browser extensions and search hijacking, which are ordinary software.
Genuine performance problems mistaken for infection.
When to rebuild rather than clean. If credentials were stolen, if the infection had administrator access, or if anything persists after cleaning, a clean reinstall is the only reliable answer — modern malware can survive removal tools.
Restore data from backup, not from the compromised system, and scan before restoring.
Report it if money or identity documents are involved.