Disconnect when actively compromised
If files are being encrypted, accounts are being used, or remote control is suspected, disconnect the device from networks before continuing.
Use trusted security tools
Run Microsoft Defender or another established security product that is already installed and current. Avoid pop-up pages claiming an infection.
Use an offline scan when needed
Microsoft Defender Offline can scan before normal Windows startup, which may help with persistent threats.
Protect accounts from a clean device
For suspected credential theft, change important passwords from a known-clean device and enable multifactor authentication.
Restore carefully
Quarantine findings, update Windows and applications, and restore files only from a backup known to predate the infection. Seek professional help for business systems or sensitive data.
These steps provide general educational guidance and cannot guarantee a repair. Software cannot physically repair failed storage, damaged memory, overheating components, broken connectors, or liquid damage.