Jensen IT Notes
Back to blog

IT Support & Troubleshooting

Malware Basics for IT Support Beginners

June 23, 2026

A practical beginner overview of malware types, infection signs, basic response steps, and when to escalate.

CompTIA A+SecurityMalwarePhishing

Malware is malicious software. In IT support, you do not need to be a security analyst to recognize warning signs, collect good information, and escalate quickly when needed.

Virus

A virus is malware that attaches to files or programs and spreads when those files run. The word “virus” is often used casually, but not all malware is technically a virus.

Trojan

A trojan pretends to be something useful or harmless, but does something malicious after the user opens it.

Examples include fake installers, cracked software, or attachments that appear legitimate.

Ransomware

Ransomware encrypts files or systems and demands payment. This is serious and should be escalated immediately in a workplace.

Do not keep clicking around if ransomware is suspected. Follow incident response procedures.

Spyware

Spyware collects information without proper permission. It may track activity, steal data, or capture credentials.

Phishing

Phishing tricks users into giving up credentials, opening malicious attachments, or clicking dangerous links.

Beginner-friendly explanation: phishing is usually a people-and-trust attack, not just a technical trick. Cantonese-friendly: “Phishing 就係呃你信佢,等你自己撳 link 或交資料.”

Signs of infection

Possible signs include:

  • Unexpected pop-ups.
  • Browser redirects.
  • Unknown programs installed.
  • Antivirus warnings.
  • Slow performance with strange processes.
  • Disabled security tools.
  • Files renamed or encrypted.
  • Users reporting suspicious emails or login prompts.

One sign alone does not prove malware, but it should guide careful investigation.

Basic response steps

  1. Stay calm and gather symptoms.
  2. Ask what happened before the issue started.
  3. Disconnect from the network if policy says to do so for suspected infection.
  4. Do not delete evidence unless instructed.
  5. Run approved security tools if that is part of your role.
  6. Reset passwords only through proper process.
  7. Document the timeline and user actions.
  8. Escalate when needed.

When to escalate

Escalate immediately for:

  • Ransomware.
  • Credential theft.
  • Business data exposure.
  • Multiple affected devices.
  • Suspicious admin activity.
  • Malware on servers or shared systems.
  • Anything outside your permissions or training.

Beginner Note

In security-related tickets, your job may be to recognize risk and escalate, not to solve everything alone.

Common Mistake

A common mistake is promising the user “it is cleaned” too early. Malware response needs verification and may require security team review.

Help desk example

A user opened a suspicious attachment and then saw a fake Microsoft login page. A good help desk response is to document the email, ask whether credentials were entered, preserve details, and escalate according to policy.

FAQ

Is every slow computer infected?

No. Slowness can come from old storage, low RAM, updates, startup apps, or network issues.

Should I delete suspicious emails?

Follow workplace process. Security teams may need headers, screenshots, or the original message for investigation.

Can antivirus fix everything?

No. Antivirus is important, but response may also involve isolation, password resets, patching, and investigation.

What should beginners remember most?

Recognize signs, avoid risky cleanup shortcuts, document clearly, and escalate serious cases quickly.

Keep exploring practical fixes

Browse more support notes and build a stronger troubleshooting routine.

View all posts