The malware tower · the atrium

How to remove malware: the tower, floor by floor

This is the entrance to the malware tower. If something is wrong on your machine right now, do not read the atrium — go straight up to the removal floor for the device it is happening on. Everything else can wait an hour.

Almost nobody arrives here looking for protection. They arrive because a computer has started behaving strangely, or a browser opens on a page nobody chose, or an email says an account was used from a country they have never visited. The tower is built around that order of events: what to do now, what each kind of infection actually wants from you, and only then what is worth installing once the panic has passed.

Every floor is written under the same two rules. What a security program does is quoted from the company that makes it, with the date we read it, because these suites change what they include from one year to the next. And nothing is ranked until we have paid for the licences and run them on real machines for two weeks — including the part that never appears in a comparison table, which is what the program costs you in speed and interruptions every single day.

Three levels, and you are on the first. The atrium lists the floors; each floor covers one thing completely and holds the shorter guides that belong under it. Nothing here is more than three clicks from the front door, and every floor links back to this one.

Where to start

Five ways in. The first two are emergencies; the rest can be read with a coffee.

“My computer is doing something it should not.”
Go straight to removing it
“I clicked something and now I am worried.”
Start at removing it
“All my files are encrypted and there is a note.”
That is ransomware, in the kinds
“Do I need to buy an antivirus at all?”
The honest answer is in the programs
“A pop-up says I have a virus. Is it real?”
Almost certainly not — see the questions

Removing it

The emergency floors, one per device. They all follow the same order, because the order is what matters: cut the network first, log in to nothing, then clean — and change the passwords afterwards from a different machine.

On WindowsThe full sequence using what is already installed, plus one second opinion from a different vendor.Being built
On a MacWhat genuinely happens on macOS, and how much of the rest is an advert dressed as a warning.Being built
On AndroidSafe mode, the permissions worth auditing, and apps that hide their own icon from the launcher.Being built
On iPhoneWhy real infections are rare here, and what that alarming page in the browser is actually doing.Being built
When to reinstallThe point at which cleaning stops being worth the doubt, and how to do it without losing everything.Being built
What to do afterwardsWhich passwords to change, from which device, and in what order to change them.Being built

The programs

One floor per antivirus. Each answers the same questions: what it catches, what it costs in money and in speed, what it sends back to the company, and whether you needed it in the first place.

Microsoft DefenderThe protection already running on most of the computers in the world, and what Microsoft says it does.Being built
MalwarebytesWidely used as the second opinion after a first scan comes back clean. What that means in practice.Being built
BitdefenderWhat the company says the suite adds beyond the scanner itself.Being built
KasperskyThe technical record and the political question, kept clearly apart from one another.Being built
Avast and AVGTwo of the best-known free names, and what the company publishes about how the free version works.Being built
ESETA long-standing option at the lighter end of the market, read on its own documentation.Being built
Do you need one at all?Who genuinely benefits from a paid product, and who is already covered and being sold fear.Being built

The kinds

Malware is an umbrella word. Underneath it, each category is defined by what the software wants from you — and what it wants decides what you should do about it.

RansomwareWhether to pay, where the free decryption tools live, and why your backups decided this weeks ago.Being built
SpywareIncluding the hardest case, where the person who installed it lives in the same house.Being built
KeyloggersThe reason every removal guide tells you to change passwords from a different machine.Being built
TrojansNot a behaviour but a disguise, and the way almost everything on this floor arrives.Being built
AdwareTreated as the harmless one, and still a program with permission to rewrite what your browser shows.Being built
BotnetsThe case where you are not the target but the equipment, and nothing seems wrong for years.Being built
RootkitsThe kind that lies to the very tool you are using to look for it, and why reinstalling wins.Being built

The questions

What people search while deciding whether they have a problem at all. Short answers, no product attached, written to be read on a phone while the computer is switched off.

Am I infected?The signs worth acting on, and the far longer list of signs that mean nothing at all.Being built
How it got inFour doors account for nearly everything, and three of them are decisions rather than accidents.Being built
Fake virus warningsThe pop-up that is itself the attack, and why closing the tab is the whole fix.Being built
Backups that surviveWhy a backup that is always plugged in is not a backup, and the one test worth doing.Being built
Scanning safelyWhere to get a scanner when the search results themselves cannot be trusted.Being built

What this tower will not do

It will not tell you the best antivirus. That verdict needs paid licences, real machines, weeks of ordinary use, and an honest account of what each program cost in speed and false alarms. A table of features copied from a press release is not a test, and this category is full of them.

It will not carry affiliate links. Security software pays generously for recommendations, and a great many of the comparison sites at the top of these searches are paid placements wearing the clothes of a review. That is precisely why a recommendation with no money attached to it is worth something, and why this tower is slower to produce one.

And it will not frighten you into installing anything. There is a whole industry built on the gap between how dangerous the internet feels and how dangerous it is for one ordinary person with an updated machine. Several floors here exist mainly to close that gap, and the honest answer on more than one of them is that you already have what you need and can stop reading. What holds instead is simple: no rankings until we have paid for the licences ourselves and run them for two weeks, and no affiliate links ever.

Written by Alberto Gulotta

Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.

Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.

Independence and limits

No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.

This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.