Skip to main content

What to Do After You've Given a Scammer Remote Access to Your PC

Media What to Do After You’ve Given a Scammer Remote Access

 

You thought you were speaking to Microsoft, your bank, an internet provider or another legitimate organisation.

They persuaded you to install remote-access software.

Perhaps you gave them a code.

Then they controlled your computer.

If you've just realised it was a scam, do not panic—but act quickly.

Giving a scammer remote access is more serious than simply answering a suspicious telephone call.

While connected, they may have been able to:

  • view files
  • watch what you typed
  • access email
  • see saved passwords
  • install software
  • alter security settings
  • create new accounts
  • install remote-access tools
  • access banking websites
  • steal browser sessions
  • install malware or ransomware

Microsoft specifically warns that scammers using remote access may steal information or install malware, ransomware and other unwanted software.

What you do next matters.

1. Disconnect the Computer From the Internet

If you think the scammer still has access, end the connection immediately.

Disconnect:

Ethernet

and turn off:

Wi-Fi

If necessary, switch off your router temporarily.

Do not reconnect the affected PC simply because the scammer has hung up.

Some remote-access software can be configured for unattended access, meaning the attacker may be able to reconnect later without asking you for another code.

For a business computer, contact your IT provider from another trusted device.

The NCSC specifically advises employees who encounter suspicious activity on work devices to report it to their IT department.

2. Don't Start Changing Passwords on the Compromised PC

This is extremely important.

If the attacker installed:

  • spyware
  • credential-stealing malware
  • a keylogger
  • malicious browser extensions

then changing passwords on that same computer could simply give the attacker the new passwords.

Instead, use another device you trust.

For example:

  • another computer
  • your phone
  • a tablet
  • a company-managed device

Then begin securing your important accounts.

3. Change Your Email Password First

Your email account is particularly valuable because it can often be used to reset passwords for other services.

From a trusted device:

  1. Change the email password.
  2. Sign out existing sessions where possible.
  3. Review recent sign-ins.
  4. Check recovery email addresses and telephone numbers.
  5. Review MFA methods.
  6. Remove anything you don't recognise.

If you reused the same password elsewhere, change those accounts too.

The NCSC specifically recommends immediately changing reused passwords when credentials have been exposed.

Use a different password for every account.

A password manager can make that much easier.

4. Secure Microsoft 365 or Your Microsoft Account

If the affected computer was signed into Microsoft 365, don't limit the investigation to Windows.

Check the account itself.

For a business Microsoft 365 environment, IT should investigate:

  • recent Entra ID sign-ins
  • authentication methods
  • MFA registrations
  • active sessions
  • mailbox forwarding
  • Outlook Inbox rules
  • mailbox delegates
  • suspicious sent email
  • OAuth/application consent
  • administrator changes

This matters because cleaning the computer does not automatically remove persistence the attacker created inside the cloud account.

A scammer who obtained access to Microsoft 365 may not need access to the PC again.

5. Check Your Bank Immediately if Financial Information Was Exposed

If you:

  • logged into online banking
  • gave the scammer card details
  • transferred money
  • revealed security information
  • allowed them to watch while banking was open

contact your bank using its official telephone number or banking app.

Do not use a telephone number the scammer supplied.

Tell the bank clearly:

A scammer had remote access to my computer and may have seen my banking information.

If money has already been taken, speed matters.

The NCSC advises victims who have lost money to contact their bank and report the crime through the appropriate fraud-reporting route.

6. Don't Trust a Second Caller Offering to Recover the Money

Victims are sometimes targeted again.

Someone may contact you claiming to be:

  • the bank
  • police
  • Microsoft
  • a fraud investigator
  • a recovery company
  • the NCSC

They may claim they can recover your money or secure your computer.

Treat unsolicited contact with extreme suspicion.

The NCSC states that it will never ask for remote access to your computer or request your passwords or login details.

Verify organisations independently using contact details obtained from their official website or documentation.

7. Write Down What Happened

Before removing everything, record what you remember.

Useful information includes:

  • date and time
  • telephone number used
  • company they claimed to represent
  • website you visited
  • remote-access program installed
  • files downloaded
  • commands you saw them run
  • accounts you logged into
  • money transferred
  • passwords disclosed
  • screenshots
  • emails
  • text messages
  • payment details

For a business incident, preserve this information for IT.

It can help determine what the attacker actually did rather than simply proving somebody connected.

8. Identify the Remote-Access Software

Common legitimate remote-support applications can be abused by scammers.

Look under:

Settings > Apps > Installed apps

and sort by installation date where useful.

Look for applications installed around the time of the incident.

But don't assume uninstalling the obvious remote-support application solves everything.

The scammer may have:

  • installed another remote tool
  • created unattended access
  • added a Windows user
  • changed Defender exclusions
  • installed a browser extension
  • created startup persistence
  • installed malware

Removing one application does not prove the computer is clean.

Microsoft recommends uninstalling applications that scammers instructed victims to install, but it also recommends malware scanning and says resetting the device may be appropriate after remote access has been granted.

9. Check Windows Accounts

Review:

Settings > Accounts > Other users

Look for:

  • accounts you didn't create
  • unfamiliar administrator accounts
  • unexpected support accounts

An unknown administrator account is a serious finding.

Don't simply delete it and carry on.

If the attacker obtained administrator-level access, they may have made other changes that are harder to identify.

10. Check Microsoft Defender

Once the immediate incident has been contained and you are ready to investigate the machine, open:

Windows Security > Virus & threat protection

Check:

  • protection status
  • Protection history
  • security intelligence updates
  • real-time protection
  • cloud-delivered protection
  • exclusions

Unexpected antivirus exclusions deserve particular attention.

Microsoft recommends updating security protection and performing a full scan when unwanted or malicious software may be present.

Run a Full Scan

Choose:

Windows Security > Virus & threat protection > Scan options > Full scan

A full scan examines every file and program rather than only the locations most commonly targeted by malware.

But don't stop there if the scammer had substantial control.

11. Consider Microsoft Defender Offline

Microsoft Defender Offline is particularly useful when you're concerned malware could be hiding while Windows is running.

Open:

Windows Security > Virus & threat protection > Scan options

Choose:

Microsoft Defender Antivirus (offline scan)

and select:

Scan now

The computer restarts and scans from the Windows Recovery Environment.

Microsoft explains that this makes it harder for persistent malware to hide or defend itself because the normal Windows environment isn't running.

After Windows starts again, check:

Protection history

for the results.

12. Check Defender Exclusions

Open:

Windows Security > Virus & threat protection > Manage settings > Exclusions

Look for anything unexpected.

An attacker might attempt to exclude:

  • a folder
  • executable
  • script directory
  • entire drive

from antivirus scanning.

Do not remove legitimate business exclusions blindly.

If it's a managed company computer, let IT determine which exclusions are authorised.

13. Check the Browser

The attacker may have interacted with your browser rather than installing conventional malware.

Review:

  • extensions
  • saved passwords
  • notification permissions
  • homepage
  • search engine
  • proxy settings

Remove extensions you know were installed by the scammer.

If passwords were stored in the browser while the attacker had access, consider those credentials potentially exposed and change important ones from a trusted device.

14. Check for Unusual Startup Software

Open:

Task Manager > Startup apps

Look for recently added or unexplained software.

Also check whether the remote-access application you identified is configured to launch automatically.

Again, don't disable unfamiliar business applications simply because you don't recognise their names.

A managed PC can legitimately contain:

  • RMM agents
  • endpoint protection
  • backup agents
  • monitoring software
  • VPN clients

Ask IT when uncertain.

15. A Clean Antivirus Scan Does Not Prove You're Safe

This is the biggest point I would strengthen in the existing article.

Suppose Defender reports:

No current threats.

That's reassuring.

But the scammer may already have:

  • copied information
  • seen passwords
  • stolen browser sessions
  • accessed email
  • changed MFA
  • created mailbox rules
  • transferred money
  • created another remote-access mechanism

Antivirus answers:

“Can I detect known malicious software?”

It does not answer:

“What did this person do during 45 minutes of legitimate interactive remote control?”

Those are different questions.

16. Should You Reset or Reinstall Windows?

If a scammer merely connected briefly and you know exactly what happened, professional investigation may establish that the system is safe.

But if the scammer had:

  • administrator access
  • significant unsupervised access
  • time to install software
  • access to sensitive business information
  • access to banking
  • access to administrator credentials

then a clean Windows rebuild may be the safer option.

Microsoft explicitly says people who have given scammers access to their device should consider resetting it.

Microsoft also notes that where malware has caused irreversible changes, resetting, restoring or reinstalling Windows may be necessary.

For a business computer containing sensitive information, the threshold for rebuilding should generally be lower.

Why spend six hours trying to prove that every possible persistence mechanism is gone when a controlled rebuild can restore a known-good operating system?

17. Restore Carefully

If you rebuild the PC, don't blindly restore everything from the old system.

Restore:

  • documents
  • photos
  • known business files
  • other required data

from known-good sources.

Be more cautious with:

  • executables
  • scripts
  • browser extensions
  • downloaded installers
  • entire AppData folders

Microsoft recommends restoring files from backups created before an infection where possible.

18. Change Important Passwords After the Device Is Trusted

Once you're working from a known-clean device, make sure important credentials have been changed.

Prioritise:

  1. Email
  2. Microsoft 365
  3. Banking
  4. Password manager
  5. Apple/Google/Microsoft accounts
  6. Business applications
  7. Shopping/payment accounts
  8. Social media

Any password that was reused should be changed everywhere it appeared.

Also enable strong MFA or passkeys where available.

19. Watch Accounts Afterwards

Continue watching for:

  • unfamiliar login alerts
  • unexpected MFA prompts
  • password-reset emails
  • new banking beneficiaries
  • unusual card transactions
  • email forwarding rules
  • messages you didn't send

An attacker may not exploit stolen information immediately.

The absence of suspicious activity the following morning does not prove nothing was stolen.

20. Report the Scam

For a UK victim who has lost money or needs to report fraud, follow the current national fraud-reporting route applicable to your part of the UK. The NCSC specifically directs victims who have lost money to contact their bank and report the incident as a crime.

Businesses should also consider whether the incident creates:

  • personal-data exposure
  • contractual notification obligations
  • cyber-insurance requirements
  • regulatory obligations

That depends on what the attacker accessed—not simply whether antivirus later found malware.

What NOT to Do

Don't:

  • keep talking to the scammer
  • reconnect because they say they need to “finish fixing” something
  • change passwords on a potentially compromised computer
  • assume uninstalling AnyDesk/TeamViewer/etc. makes everything safe
  • trust a clean antivirus scan as absolute proof
  • install several random malware-removal utilities
  • pay a second “recovery company” that contacts you unexpectedly
  • give another caller remote access

Microsoft makes one particularly useful point: legitimate Microsoft error and warning messages do not contain telephone numbers, and Microsoft does not make unsolicited calls offering to fix your computer.

The Emergency Checklist

If you've just given a scammer remote access, concentrate on this sequence:

  1. Disconnect the affected computer from the internet.
  2. Stop using it for passwords or banking.
  3. From another trusted device, secure your email and important accounts.
  4. Revoke suspicious sessions and review MFA.
  5. Contact your bank immediately if financial information was exposed.
  6. Tell your IT provider immediately if it is a business device.
  7. Record what happened.
  8. Identify and remove the remote-access software.
  9. Check accounts, Defender, exclusions and startup persistence.
  10. Run a full Defender scan and consider Defender Offline.
  11. Investigate Microsoft 365/email separately.
  12. Consider a clean Windows rebuild where trust cannot be re-established.
  13. Monitor financial and online accounts afterwards.

The key principle is:

Treat remote access as potential account compromise as well as potential malware infection.

How Hamilton Group Can Help

If somebody has remotely accessed a business computer, the important question isn't simply:

“Can we remove the remote-control software?”

It is:

“What could they have accessed or changed while they were connected?”

Hamilton Group can help businesses investigate:

  • scammer remote access
  • compromised Windows PCs
  • malware
  • Microsoft Defender
  • Microsoft 365 account compromise
  • suspicious sign-ins
  • mailbox rules and forwarding
  • stolen credentials
  • remote-access software
  • Windows rebuilds
  • banking/payment fraud indicators
  • wider network compromise

We can also help determine whether other company devices or accounts need investigating rather than treating the affected PC in isolation.

Hamilton Group aims to make first contact on IT support requests within 15 minutes.

Visit hgmssp.com or call 0330 043 0069 if you need help after a remote-access scam.