What should I do after my father opened a suspicious ZIP file?

0
0
Asked By MellowCactus42 On

Someone my father works with sent him a ZIP file and asked him to open it. After opening it, the laptop became slow and started behaving strangely. Windows Security is no longer accessible, and Chrome opens by itself whenever the computer restarts. I disconnected the Wi-Fi, changed passwords, signed out of email accounts on that laptop, and ran the Microsoft Malicious Software Removal Tool, but I'm still concerned that malware may be present.

How much damage could have occurred within 30–45 minutes? What should I do next, and is it safe to copy his files to an external SSD before completely resetting and reinstalling Windows?

3 Answers

Answered By RiverStone_8 On

Keep the laptop completely disconnected from every network, including Ethernet and Bluetooth. Since the malware may have added persistence through scheduled tasks or startup entries, I would not rely on antivirus scans alone. The safest approach is to back up only essential personal documents, scan those files from a separate clean computer, then erase the system drive and perform a completely fresh Windows installation. Do not copy programs, scripts, executables, or unknown ZIP files.

QuietLynx17 -

A clean reinstall is much safer than trying to guess whether every persistence mechanism was removed. Malware can return later if a scheduled task or startup entry was missed.

Answered By BlueMarble_29 On

You can preserve important data, but be selective. Copy photos, documents, and other non-executable files to external storage while the infected computer remains offline. Before opening them elsewhere, scan the drive with updated security software. Avoid restoring browser profiles, installers, macros, scripts, cracked software, or unknown attachments. After reinstalling Windows, fully update it and install applications only from trusted sources.

Answered By CopperCloud6 On

Treat every account used on that computer as potentially exposed. Changing passwords was good, but do it again from a known-clean device, starting with email, banking, work accounts, and password-manager credentials. Enable multifactor authentication where possible, sign out active sessions, and contact the employer or bank if sensitive work or financial information was stored there.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.