Malware
Why downloads are the most common way malware arrives
Most malware is installed by the person using the computer, not forced onto it. Learn the four routes malware takes through downloads and the checks that catch it.
Updated 9 min readqikfox
The short answer
Malware usually arrives as a file you chose to open: a fake installer from a search result, an attachment framed as an invoice, a bundled extra inside otherwise legitimate free software, or a cracked paid application. The defence is to install software only from the vendor's own site or an official store, and to let a scanner examine files before they run.
Key points
- A file needs to run only once; blocking it before execution is the whole game.
- Search results are a common distribution route for fake installers of popular free software.
- Bundled extras inside free installers are consent-based, which is why they are easy to miss.
- Cracked commercial software is the least defensible download because tampering is expected.
- Automatic updates close the openings malware uses after it lands.
The shape of the problem
Software running on your device is trusted by the operating system to do things you asked for: read files, use the network, start when the machine starts. Malware does not need to break that model - it only needs to be launched once by someone with permission. From that moment, it inherits the trust you have.
That is why downloads dominate. A page you visit is confined by the browser's sandbox and can do relatively little. A file you download and open is a program with your privileges. The transition from browsing to installing is the moment worth guarding.
The four routes that account for most infections
Fake installers are first. Someone builds a page for a popular free application, buys placement or optimises for the download-related search, and offers an installer that includes the real program plus something extra. Everything appears to work, which is why nothing is suspected.
Attachments are second, and they lean on plausibility rather than technology. An invoice, a delivery notice, a shared document, a CV. The file itself is often a document that asks to enable content or a compressed archive containing a shortcut.
Bundling is third and the least dramatic: free software funded by offers packaged into the installer, accepted by clicking through screens designed to be clicked through. The result is browser changes, injected advertising and background processes you never chose.
Cracked commercial software is fourth. Bypassing a licence check requires modifying the program, so tampering is not just possible but expected, and there is nobody to complain to.
- Fake installers reached through search results or advertising.
- Attachments framed as invoices, deliveries, documents or applications.
- Bundled extras accepted during a legitimate free installation.
- Cracked or repacked paid software from file-sharing sites.
Checks worth making before you open a file
Start with provenance rather than the file. Did you go looking for this software, or did it arrive? Software you sought is safer to install than software that found you, and an attachment you did not expect deserves a check by another channel before it is opened.
Then confirm you are on the project's own site. For well-known open-source tools, the official page is usually the project's own domain or repository, not an aggregator with a large green button. If you cannot tell, search for the project name and read the domain before you click.
Finally, look at what you are actually being handed. An installer for a small utility that weighs far more than expected, an archive containing a shortcut, or a document that must have content enabled before it displays are all reasons to stop.
Why file scanning still matters
Careful habits reduce exposure but cannot inspect contents. A scanner can: it examines the file itself, compares it against known malicious patterns, and looks at behavioural traits that resemble software designed to hide, persist or reach out to a controller.
qikfox Antivirus reviews files, downloads and applications on the device, so the check happens at the moment a file lands rather than after something has gone wrong. It complements the browser rather than duplicating it - the browser protects the page, the scanner protects the file.
No scanner recognises everything. Detection is strongest for known families and weakest for something built last night for a small number of targets, which is why provenance remains the first line and scanning the second.
If something is already installed
Common signs are a changed browser start page or search engine, extensions you did not add, advertising appearing in places it did not before, and a machine that is suddenly busy while idle.
Disconnect from the network to stop further downloads, run a full device scan, remove what is found, then review installed programs and browser extensions by date and remove anything that appeared around the same time. Afterwards, change passwords for important accounts from a device you trust - anything typed while the machine was compromised should be considered exposed.
- Disconnect from the network.
- Run a full scan and remove what is detected.
- Review installed programs and extensions by install date.
- Change important passwords from a clean device.
- Turn automatic updates back on for the system and browser.
Questions and answers
Related qikfox pages
qikfox Antivirus
Device-wide file and download review.
Download qikfox
Official installers for every platform.
Recognising phishing pages
The delivery route that precedes most downloads.
Security at qikfox
How we think about device security.
Back to Guides · Written and reviewed by the qikfox editorial team. Published .
Put the advice into practice
qikfox Safe Browser applies most of what this article describes by default, and works alongside qikfox Search, Antivirus and VPN.