Crisp PhaseHelp with antivirus questions

I clicked a link I should not have

Six questions about suspicious messages, links and attachments, answered in the order the steps actually matter.

The first thing worth saying is that opening a link is not, by itself, the same as losing an account or a sum of money. In almost every case there is a second step between the click and the harm: typing a password, approving a code, entering card details, or running a file that was downloaded. Knowing which of those steps you took, if any, is what determines what you should do next — and it determines it far more usefully than a general scan does.

These answers are written calmly on purpose. The messages themselves are designed to produce the opposite feeling, and acting quickly out of alarm is how most of the avoidable damage happens. Read the question that matches what you did, take the steps in order, and leave the rest.

How do I tell whether a delivery or bank message is genuine?

Short answer

Do not judge by the message. Judge by going to the organisation yourself — type its address, or open its app — and seeing whether the same thing is waiting for you there. If it is not in the app, the message was not from them.

Why the message itself is unreliable

Sender names on text messages can be set by the sender, so a message can appear in the same conversation thread as genuine ones from a bank or a courier. Email addresses can be spoofed or can use a domain that differs from the real one by a character. Logos and layouts are trivially copied. None of these signals can be trusted, which is why the advice is to leave the message entirely rather than to examine it harder.

Patterns that recur across messages people ask about, and what each one is doing.
The message saysWhat it is doingWhat to do instead
A parcel could not be delivered; pay a small feeCollecting card details through a convincing payment pageCheck the courier's own tracking page using the number on your order confirmation
Unusual activity on your account; verify immediatelyCreating urgency so the login page is not examinedOpen the bank's app yourself; real alerts appear there
Your subscription will renew unless you cancelGetting you to phone a number staffed by the senderCheck the subscription in your account settings on the real service
You are owed a refund from a government agencyCollecting banking detailsSign in to the agency's own service; refunds appear there
A relative messaging from a new number asking for moneyImpersonation that relies on not being verifiedPhone the person on the number you already have

Where official information helps

Scamwatch, run by the National Anti-Scam Centre, publishes descriptions of scams currently circulating in Australia, which is a useful place to check whether a message you have received matches something already known. The Australian Cyber Security Centre publishes guidance on recognising and responding to these messages.

Where a paid product comes into it

Nothing you buy can verify a text message for you. The habit of checking with the organisation directly is free and more reliable than any filter.

I typed my details into a page that turned out not to be real

Short answer

Act on the account, not on the computer. Change the password on the real service immediately, turn on two-factor authentication while you are there, and if card details were entered, contact your bank. A scan is not the priority here and will not undo anything.

What to do, in order

  1. Change the password on the affected account by going to the service yourself, not through any link in the message.
  2. Change it anywhere else you used the same password. This is the step people skip, and it is the one that prevents the damage from spreading.
  3. Turn on two-factor authentication on that account if it is available.
  4. Check the account's security settings for a recovery email address, phone number or forwarding rule you did not add, and remove anything unfamiliar.
  5. If card or banking details were entered, contact your bank through the number on your card or in its app. Banks have processes for exactly this and would rather hear early.
  6. Sign out of all other sessions if the service offers that option, so that any existing access is ended.

What to watch out for afterwards

People who have been through one of these often receive a follow-up contact offering to recover the money, sometimes appearing to come from a bank, a law firm or a government body. Treat any such approach the same way as the first message: go to the organisation yourself rather than responding to the contact. No legitimate recovery process begins with an unsolicited message asking for a fee or for remote access to your computer.

Where to report it

Reports of cybercrime in Australia go to ReportCyber, which is run through the Australian Cyber Security Centre. Scam reports go to Scamwatch. If the incident involved your personal information being mishandled by an organisation, the Office of the Australian Information Commissioner is the relevant body.

I installed something I now regret. What should I do?

Short answer

This is the situation where a scan genuinely belongs. Disconnect from the internet if the installation is recent, uninstall the program through the normal route, then run a full scan with the protection on the machine and restart.

Why installing is different from clicking

Running an installer grants software the ability to put files on the machine and, often, to run automatically. That is a meaningfully different situation from loading a web page, and it is the case where security software is doing the job it exists to do. The urgency is real but modest: taking twenty careful minutes is better than taking two frantic ones.

What to do, in order, at no cost

  1. Disconnect from Wi-Fi or unplug the network cable if the installation happened within the last few minutes.
  2. Uninstall the program through Settings on Windows or by moving the application to the Bin on macOS, then emptying it.
  3. Check the start-up list for entries the program added, as described on the slow computer page.
  4. Run a full scan with your security software and let it finish. Act on what it reports rather than on guesswork.
  5. Restart, reconnect, and change the password on your main email account from a different device if you have one.
  6. If the program asked for remote access to your screen, treat every account used on that machine as exposed and work through the steps in the previous question.

When to ask for help

If the computer no longer behaves normally after the uninstall, if files have become unreadable, or if a message demands payment to restore access, stop and get help rather than continuing. The Australian Cyber Security Centre publishes specific guidance for ransomware incidents, and paying is not the recommended first response in that guidance.

Where a paid product comes into it

A product with a support channel is worth something in exactly this situation, because you can ask a person rather than guessing. Norton AntiVirus Plus is a paid subscription of that kind for Windows and macOS.

Visit the Norton AntiVirus Plus website to see what the vendor says the subscription includes.

Paid affiliate link. ORYNA s.r.o. receives a commission on sales through it; your price is the same either way.

Is opening an email attachment dangerous?

Short answer

It depends entirely on what the attachment is. A photograph or a plain PDF viewed in a modern reader is low risk. A document that asks you to enable editing or content, or an executable file arriving unexpectedly, is a different matter.

What makes the difference

Documents can carry macros — small programs that run inside the document — and the prompt asking you to enable content is what allows them to run. Legitimate documents from colleagues occasionally use macros, which is why the prompt exists; unexpected documents from strangers that insist on it are the pattern worth refusing. Compressed archives are used to get past filters, so an unexpected archive containing a single file is worth treating with suspicion.

Attachments that are themselves programs, scripts or installers should not arrive by email from people you do not know, and the fact that one has is itself the signal.

What to do, at no cost

  1. Check whether the message is one you were expecting from someone you know. If not, do not open the attachment at all.
  2. Never enable content, macros or editing on a document you did not ask for.
  3. If you need to see what a document says, open it in a web-based viewer rather than the desktop application, which keeps it away from your machine.
  4. When a message appears to come from a colleague but reads oddly, confirm by another channel before opening anything.

Where do I report this, and does reporting achieve anything?

Short answer

Report to ReportCyber through the Australian Cyber Security Centre for cybercrime, and to Scamwatch for scams. Reporting rarely recovers money directly, but it is how patterns are identified and warnings issued.

Which body takes which report

Where different kinds of incident are reported in Australia.
The incidentWhere it goes
Money lost, account accessed, device compromisedReportCyber, via cyber.gov.au
A scam message or call, whether or not you lost anythingScamwatch
Cyberbullying, image-based abuse or seriously harmful contenteSafety Commissioner
An organisation mishandled your personal informationOAIC
Misleading advertising or a business behaving deceptivelyACCC

Before you report

Keep the message rather than deleting it, note the date and time, and record any amount involved and the account it went to. A report with those details is more useful than one without, and gathering them takes a few minutes. Your bank will also ask for the same information.

A few more questions