If you allowed a caller, pop-up, email sender, or online contact to control your computer, act as though the computer and any accounts used on it may be exposed. The scammer may have viewed information, changed settings, installed remote-access software, or attempted to collect passwords and payment details. That does not prove that every file or account was taken, but it is enough reason to respond carefully.
Do not continue the conversation to ask what they did, and do not trust a number or link supplied by the person who contacted you. Use contact information from your bank, software provider, or device manufacturer’s official website instead.
1. Stop the remote session
Warning: If the scammer is still connected, stopping the connection takes priority over preserving evidence. Do not type passwords, open banking sites, or follow more instructions while they are watching.
- Close the remote-support program if you can identify it safely.
- Unplug the computer’s network cable, or turn off Wi-Fi using the computer’s hardware switch or operating-system controls.
- If you cannot stop the session quickly, hold the computer’s power button until it shuts down. This can cause loss of unsaved work, but it is preferable to allowing an active intruder more time.
- Disconnect other devices only if they were also involved or share the same remote-access software. Do not randomly reset equipment or delete files yet.
If you are unsure whether the session ended, leave the computer disconnected from the internet. A remote-access window disappearing does not by itself prove that all access has been removed.
2. Use a different, trusted device for account protection
Assume that passwords entered on the affected computer could have been observed. From a phone or another computer that was not involved, change passwords for the most important accounts first:
- Your primary email account.
- Banking, credit-card, payment, and investment accounts.
- Work, school, cloud-storage, and password-manager accounts.
- Shopping, social-media, tax, medical, and government-service accounts.
Use a new password for every account. If you reused the exposed password anywhere else, change those accounts too. Do not save the new passwords in a browser on the affected computer until it has been assessed.
After changing each important password, review its security settings. Sign out other sessions, remove unfamiliar recovery email addresses or phone numbers, check forwarding rules, and remove unknown devices or applications with account access. Turn on multifactor authentication where available. An authenticator app or hardware security key can be stronger than text messages, but any available multifactor option is generally better than leaving the account unprotected.
3. Contact financial institutions promptly
If you gave the scammer a card number, bank details, online-banking password, one-time code, Social Security number, or remote view of a financial account, call the institution using the number on the back of your card or an official statement. Explain that a scammer had access to your computer and ask what protective steps are appropriate.
Review recent transactions and continue checking them. Ask about replacing cards, changing account credentials, placing a fraud alert, or disputing unauthorized transactions. If money was sent by wire, gift card, payment app, cryptocurrency, or bank transfer, contact the payment provider immediately. Recovery is not guaranteed, but delay can reduce the options available.
Never pay a second person who promises to recover your money or “clean” the computer. Recovery scams often target people who have already reported a loss.
4. Record what happened before cleaning the computer
Write down the approximate time, phone number or contact method, names used by the caller, software they asked you to install, websites visited, payments made, and information you disclosed. Save emails, text messages, receipts, and screenshots if they are available on a separate device or can be copied without reconnecting the computer.
Do not take screenshots or gather logs if doing so requires reconnecting an actively compromised computer. Your notes do not need to be perfect. They can help a bank, law-enforcement agency, workplace administrator, or technician understand the scope of the incident.
Report the fraud to the appropriate financial institution and consumer-protection agency. In the United States, reports can be made to the Federal Trade Commission, and suspected identity theft can be reported through IdentityTheft.gov. Local law enforcement may also be appropriate, particularly for significant financial losses, threats, or business-related incidents.
5. Do not assume uninstalling one remote tool is enough
Scammers commonly use legitimate remote-support applications, so the presence of one program does not automatically prove malware. However, they may also create user accounts, install startup items, change browser settings, add scheduled tasks, disable security protections, or leave another way to reconnect.
From the affected computer, avoid signing into additional accounts while investigating. If the computer contains sensitive business, tax, medical, legal, or personal information, keep it offline and ask a qualified technician or your organization’s IT administrator to assess it.
A technician may check for:
- Remote-access applications and unattended-access settings.
- New local user accounts, administrator permissions, and password changes.
- Unknown startup programs, scheduled tasks, services, browser extensions, and proxy settings.
- Disabled antivirus, firewall, update, or security-notification settings.
- Suspicious files, malware indicators, and signs of unauthorized encryption or deletion.
Security software scans are useful, but a clean scan does not prove that no information was viewed or copied. Likewise, an unfamiliar program is not automatically malicious. Removing items without understanding them can make later investigation harder or interfere with legitimate software.
6. Decide whether to reset or reinstall the computer
There is no single answer for every incident. The right response depends on what the scammer did, what software was installed, the sensitivity of the data, and whether the computer can be trusted again.
| Situation | Safer next step |
|---|---|
| You only visited a suspicious page and gave no remote access or credentials | Close it, update the system and browser, review downloads and extensions, and run a security check. |
| You installed remote-control software or gave the person control | Keep the computer offline until remote tools, accounts, settings, and startup items are reviewed. |
| Passwords, financial information, or one-time codes were exposed | Protect accounts from a separate device and contact financial institutions immediately. |
| The computer contains high-value business or confidential information | Preserve it offline and involve the responsible IT or security professional before making major changes. |
| You cannot establish what was installed or changed | Consider a professional assessment and, depending on the findings, a backup-and-reinstall plan. |
A factory reset or clean operating-system installation can remove many unwanted changes, but it is not a magic eraser. It may delete files, destroy useful evidence, leave backups or other devices affected, and fail to address compromised online accounts. Before resetting, confirm that important files are backed up, identify whether backups might contain malware, and verify that you have legitimate license and sign-in information.
7. Protect other computers and people connected to the incident
If the affected computer belongs to a small business, disconnect it from business networks and notify the person responsible for IT or security. Do not conceal the incident because another employee may receive a convincing follow-up message using information the scammer learned.
Check whether the scammer accessed shared cloud storage, email contacts, remote-work tools, or a password manager. Warn contacts not to trust unexpected messages sent from your account. If the computer is used by several household members, explain that the incident is not a reason to blame anyone; the practical goal is to protect accounts and avoid a second compromise.
When to get professional help
Arrange an inspection if the scammer had control for more than a brief moment, installed software, requested administrator permission, changed passwords, accessed confidential files, or disabled security features. Professional help is especially sensible when the computer supports payroll, business operations, tax records, medical information, or regulated data.
A responsible repair process should explain what can and cannot be determined. No technician can reliably promise that a scan proves what a remote person viewed or copied. The goal is to contain access, secure accounts, preserve needed data, remove unauthorized changes where practical, and make an informed decision about continued use, reset, or replacement.
If you are in Bellevue, Omaha, Papillion, La Vista, Plattsmouth, Ralston, Council Bluffs, or near Offutt Air Force Base, AME Computers can help assess the computer and outline safe next steps. Keep the device disconnected and bring your notes about the incident so the evaluation can begin with the clearest possible picture.
When to call a professional
If the problem continues, the data is important, or the repair requires work beyond your comfort level, AME Computers can provide professional diagnosis and repair or call 402-505-6600.
Free repair guidance
Get New Computer Repair Guides by Email
Practical PC and Mac help from AME Computers. Confirm your email once and unsubscribe anytime.

