A phone call, pop-up, or browser message claims that your computer is infected and that a “technician” can fix it remotely. The caller asks you to install remote-access software, read out a code, or allow control of the screen. Once connected, the person may show harmless Windows messages as supposed proof of an infection, request payment, or ask for account and banking information.
This is a common tech-support scam pattern. The remote-access application itself may be legitimate software, but its installation and use were unauthorized. Removing the program is only one part of the response. You also need to consider what the person could see, which settings they changed, whether another access method was added, and whether passwords or financial information were exposed.
The following is a representative repair case study based on a common Windows incident pattern. It is not a claim about a particular customer or a guaranteed cleanup result. The exact steps and final recommendation depend on the computer, the software installed, the access granted, and the information handled during the session.
First priority: stop the remote session safely
Warning: If the remote operator is still connected, do not continue chatting with them or follow additional instructions. Disconnect the computer from the internet as quickly and safely as possible. Unplug the network cable, turn off Wi-Fi using the computer’s normal controls, or disconnect the router’s internet connection if that is easier. If the computer is used by a business, contact the person responsible for IT or security before making extensive changes.
Do not enter passwords, payment details, recovery codes, or identity information while the remote session is active. If you can see the operator moving the mouse, close the remote-access program or shut down the computer. A normal shutdown is preferable when it is available, but stopping an active unauthorized session takes priority.
Do not assume that closing the window ended access. Remote tools can run in the background, start with Windows, or install a service. If the computer contains sensitive business records, medical information, tax documents, or customer data, treat the event as a possible security incident and document it promptly.
Record what happened before changing everything
Write down the phone number, website, pop-up wording, caller’s name, time of the session, remote software name, payment information requested, and anything the operator asked you to do. Keep emails, receipts, screenshots, and text messages. This information can help a bank, software vendor, law-enforcement agency, or business security contact understand the incident.
If the operator displayed a supposed virus report, note what was shown without assuming it was genuine. Windows warnings, Event Viewer entries, browser notifications, and ordinary security logs are frequently misrepresented during scams. A payment receipt or remote-session code can be more useful evidence than the alleged infection screen.
Check installed applications and remove the remote tool
After the computer is offline, sign in with an account that has administrator permission if appropriate. In Windows, open Settings > Apps > Installed apps. Review the list for remote-support or remote-desktop tools that you do not recognize or did not intentionally install. Examples may include legitimate products such as AnyDesk, TeamViewer, UltraViewer, RustDesk, or similar utilities, although the name alone does not prove misuse.
Uninstall the unauthorized application using Windows’ normal uninstall option. If the program displays a choice to remove configuration files, unattended access, or saved settings, select the removal option when you understand what it will delete. Do not download a “special removal tool” from a link supplied by the caller.
Then check Settings > Apps > Startup and Task Manager > Startup apps. Disable an unfamiliar remote-access entry, but do not randomly disable Windows components or security software. Some remote programs install a separate service, so uninstalling the visible application may not remove every component.
Look for persistence, but know when to stop
A careful technician may inspect the following areas for a matching remote-access entry:
- Installed applications and recently installed programs
- Startup applications
- Windows Services, especially services with names matching the remote tool
- Task Scheduler entries created around the time of the incident
- Browser extensions and notification permissions
- Remote Desktop settings under Settings > System > Remote Desktop
- Local user accounts under Settings > Accounts
Do not delete services, scheduled tasks, registry entries, or user accounts merely because their names look unfamiliar. Windows and installed applications create many technical entries that are not obvious to a home user. If you find an unfamiliar administrator account, an unattended-access setting, a new service, or a task you cannot identify, stop before deleting it and obtain professional help. Preserving the system state may be important for investigation, and a mistaken deletion can create boot or application problems.
Also check whether Windows Remote Desktop was enabled. Turning it off can reduce exposure, but it does not prove that all other access was removed. Remote support software and Windows Remote Desktop are separate mechanisms.
Scan from a trusted Windows security tool
Reconnect to the internet only after removing the obvious unauthorized tool, or use a separate clean computer to obtain guidance. Update Microsoft Defender or the installed security product, then run a full scan. If the situation suggests persistence, use Microsoft Defender Offline from Windows Security > Virus & threat protection > Scan options, when available.
An antivirus scan can find malicious files, but it may not identify every account change, policy change, browser setting, or legitimate remote tool misused by a scammer. A clean scan is useful evidence, not a guarantee that the computer is trustworthy.
Review browser extensions, saved passwords, downloads, and notification permissions. Remove extensions you did not install intentionally. Do not open suspicious downloads simply to inspect them. If the remote operator had access to the desktop, assume that visible files, browser tabs, email, and documents may have been viewed.
Protect accounts and financial information
Warning: Change important passwords from a different, known-clean device if possible. Start with email, Microsoft or Google accounts, banking, payroll, shopping, password managers, and business systems. If the same password was reused elsewhere, change those accounts too. Enable multifactor authentication and review recent sign-ins, recovery addresses, forwarding rules, connected apps, and active sessions.
If payment card or bank information was provided, contact the financial institution using the number on the card or an official statement—not a number supplied by the caller. Ask whether transactions, transfers, or account protections need review. If identity documents or account recovery codes were disclosed, follow the relevant provider’s identity-compromise process.
Changing a password on the affected computer is less reassuring if the machine may still be compromised. Use the clean device first, then return to the Windows PC after it has been assessed.
When cleanup is reasonable—and when reinstalling is safer
Targeted cleanup may be reasonable when the unauthorized software is clearly identified, no suspicious accounts or persistence are found, security scans are clean, Windows is supported and current, and the computer was not used for highly sensitive work during the session. Even then, explain the remaining uncertainty to the owner and monitor account activity.
A Windows reset or clean reinstall deserves consideration when the operator had extended control, installed several unknown programs, changed security settings, added an administrator account, accessed sensitive business data, or left behind components that cannot be confidently identified. A clean installation can provide stronger assurance than repeatedly deleting individual files, but it also carries data-loss and activation risks.
Before resetting or reinstalling, verify backups, copy only necessary personal files, confirm application installers and license information, and check whether the drive is protected by BitLocker. Do not erase the drive if you cannot account for the files or do not have the BitLocker recovery key. A reset may remove applications and settings, and a failed backup can make recovery more difficult.
Practical stopping points
- Stop and disconnect the network if a remote operator is still active.
- Stop before deleting unfamiliar services, tasks, registry entries, or accounts.
- Stop before changing passwords if the affected PC may still be under remote control.
- Stop before a reset or reinstall if backups, BitLocker recovery information, or business requirements are unclear.
- Escalate promptly if money, identity documents, regulated data, or an administrator account may have been exposed.
For a home computer in Bellevue, Omaha, Papillion, La Vista, Plattsmouth, Ralston, Council Bluffs, or near Offutt Air Force Base, a technician can help document the incident, inspect the system without guessing, and explain whether cleanup or a rebuild is the more responsible option. The goal is not simply to make the pop-up disappear; it is to reduce uncertainty and restore control of the computer and the accounts connected to it.
When to call a professional
If the problem continues, the data is important, or the repair requires work beyond your comfort level, AME Computers can provide professional diagnosis and repair or call 402-505-6600.
Free repair guidance
Get New Computer Repair Guides by Email
Practical PC and Mac help from AME Computers. Confirm your email once and unsubscribe anytime.

