Mon–Fri, 8am–5pm · Brisbane time 9 Ferny Avenue, Surfers Paradise QLD 4217
Callback within 4 business hours
bcom ICT
HomeServicesIndustriesSupportAbout Get a quote Call 07 3041 8993
Malware removal and system hardening being carried out by bcom ICT for a Gold Coast business

Removing it is the easy part

Cleaning the machine is straightforward. Working out what was reached, resetting what was exposed and closing the way in is the part that matters.

  • Credentials reset
  • Hardened afterwards
  • Evidence preserved
  • Digital assistant after hours

bcom ICT removes viruses, malware and ransomware from Gold Coast business computers — scanning and cleaning the affected machines, resetting exposed credentials, establishing what was accessed, and hardening the environment so the same route is closed. Call 07 3041 8993.

Before you do anything

If you think it's happening right now

What you do in the first ten minutes changes what can be recovered and what can be established afterwards.

Disconnect, don't shut down

Unplug the network cable or turn off WiFi to stop it spreading. Do not power the machine off — shutting down destroys evidence held in memory that helps establish what was actually accessed.

Don't delete anything

Not the ransom note, not the suspicious email, not the unfamiliar files. That is the evidence, and you may need it for your insurer or a regulatory assessment.

Don't wipe and rebuild

It is the instinctive reaction and it removes the only record of what happened. Isolate the machine and call instead.

Change passwords from a clean device

Not from the affected machine. If something is capturing keystrokes, resetting a password on that machine simply hands over the new one.

What we actually do

  • Contain it — isolate affected machines before anything else, so it stops spreading
  • Identify what it is, because ransomware, an information stealer and adware all require different responses
  • Establish what was reached — which accounts, which files, whether anything left the building
  • Clean the machines, or rebuild them where a clean removal cannot be assured
  • Reset exposed credentials, including the saved browser passwords people forget they have
  • Close the way in — the missing patch, the account without MFA, the exposed remote access
  • Tell you plainly what happened and what your obligations may be

Removal without hardening is a temporary fix

A machine cleaned and handed back with nothing else changed will very often be reinfected, because the route in is still open. Whatever let it happen — an account without multi-factor authentication, an unpatched application, remote access published to the internet, a staff member who could not tell the email was fake — is still there.

So the job ends with hardening rather than with a clean scan. If personal information may have been accessed, your business may also have obligations under the Notifiable Data Breaches scheme, and for anything beyond a single infected machine you are into incident response rather than malware removal.

Common problems

What people describe, and what it usually is

The gap between the two is why removal alone is rarely the whole job.

“The antivirus caught something — are we fine?”

Usually a detection, not necessarily a resolution. Nobody asks how it arrived or what it did in the window before detection.

What we do Establish the entry point and check for persistence — accounts, scheduled tasks, mailbox rules, startup entries. Cleaning without closing the route is why businesses get hit twice in a month.

“The machine is slow and pops up ads”

Usually adware or a browser hijack rather than anything more serious. Annoying, low risk, and usually bundled with something a user installed.

What we do Remove it, then look at how it got there. If software is being installed without approval, that is the actual finding — and it means something worse could arrive the same way.

“Files have odd extensions and there’s a note”

Usually ransomware, mid or post encryption. This is not a malware removal job any more.

What we do Stop. Disconnect from the network, do not power off, do not delete the note. Call us — this moves to incident response, where evidence and recovery matter more than cleaning.

“It keeps coming back after we clean it”

Usually persistence that was never removed, or reinfection through the same open route — an unpatched application, an account without MFA, exposed remote access.

What we do Find the persistence and the entry route rather than running the scan again. Repeat infection is a symptom of an incomplete first response.

“Our emails are being flagged as spam by clients”

Usually your domain or IP may be sending mail you do not know about, usually from a compromised mailbox.

What we do Check for compromise before assuming it is a reputation problem. Then fix SPF, DKIM and DMARC so nobody can send as you, and request delisting once the source is closed.

“Should we just wipe and rebuild it?”

Usually the instinct after any infection. Sometimes right, and often premature.

What we do Rebuild where a clean removal cannot be assured — but not before evidence is preserved and data is off. Wiping first destroys the record of what was accessed, which may determine your obligations.

In practice

When a clean-up turns out to be something else

Representative engagements, drawn from real work with identifying detail removed — we don’t name clients without written permission.

Representative engagement

Cleaned three times by someone else

The situation

A Gold Coast business had the same machine cleaned by their previous provider three times in two months. Each time it came back clean; each time the infection returned within a fortnight.

What we found

The malware was being removed correctly, but the route in was never closed — an unpatched application with a known vulnerability, plus a local administrator account with a password shared across every machine in the office.

What we did

Removed the infection, patched the application, ended the shared local administrator practice, and checked every other machine for the same exposure — two others were already infected without symptoms.

The outcome

It stopped recurring. The billable cycle of clean-and-return had been treating the symptom for two months, which is exactly the incentive problem managed IT removes.

Representative engagement

An infection that turned out to be a breach

The situation

A Gold Coast practice reported a machine behaving oddly and asked for a virus clean.

What we found

Not commodity malware. An information stealer had harvested saved browser credentials weeks earlier, and one of those credentials had been used to sign into the practice’s Microsoft 365 from overseas. A mailbox rule was quietly forwarding correspondence out.

What we did

Contained immediately, removed the forwarding rule, reset every credential from clean devices, revoked all sessions, and established from the logs what had been accessed and over what period — which is the question that decides a notification.

The outcome

What was booked as a virus clean was a notifiable-breach assessment. The practice could answer what was accessed because logging happened to be adequate, which is not always the case.

Representative engagement

Adware that was the least of it

The situation

A Gold Coast business called about pop-ups on a reception machine — irritating rather than alarming, and assumed to be a simple clean.

What we found

The adware was trivial. What sat alongside it was a remote access tool installed the same day through the same bundled download, giving someone outside the business an unattended path onto the machine. It had been there five weeks.

What we did

Removed both, checked every other machine for the same tool, reset credentials that had been entered on the affected machine, and reviewed logs for activity during the five-week window.

The outcome

The pop-ups were the visible symptom of something considerably worse. This is why we establish how something arrived rather than just removing what was reported.

Common questions

Questions Gold Coast businesses ask us

How do you remove a virus from a business computer?

bcom ICT isolates the affected machines first, identifies what the infection is, establishes what accounts and files were reached, then cleans or rebuilds the machines and resets exposed credentials. The job ends with hardening the route that allowed it, because removal alone usually leads to reinfection. Call 07 3041 8993.

What should we do the moment we notice?

Disconnect the machine from the network but do not power it off — shutting down destroys evidence in memory. Do not delete the ransom note or the suspicious email, and do not wipe and rebuild. Change passwords from a device you know is clean, not from the affected one, and call 07 3041 8993.

Will we lose data?

Usually not from a standard malware infection. Ransomware is different — recovery then depends entirely on whether your backups were separated from the network and have actually been tested. That is decided long before the incident.

How do we know it's really gone?

Because we establish what it was and what it did, rather than running a scan until it reports clean. Where a clean removal cannot be assured, the honest answer is to rebuild the machine, and we will say so rather than hand back something we are not confident in.

Is this the same as incident response?

No. Malware removal deals with infected machines. If accounts were compromised, data may have left the business, or multiple systems are affected, that is cyber incident response — containment, forensic investigation, recovery and reporting for your insurer and regulators.

How do we stop it happening again?

Multi-factor authentication everywhere, patching that actually happens, and backups held where an infection cannot reach them. Those three are Essential Eight controls and they account for most of the difference. An assessment tells you which you are missing.

Call 07 3041 8993

Open 8am–5pm Mon–Fri. Disconnect the machine from the network but leave it running — and don't delete anything.

Last updated: August 2026 · Reviewed by the bcom ICT team