What to Do If Someone Gets Remote Access to Your Computer
Giving someone remote access to your computer can become a serious security problem if that person is a scammer or someone you do not trust.
Remote-access software can allow another person to view your screen, control the mouse and keyboard, open files, install programs, change settings, and potentially see sensitive information. Microsoft specifically warns that tech-support scammers may ask for remote access while pretending to fix a computer, but then steal information or install malware.
If you think an unauthorized person had remote access to your Windows PC, act quickly but methodically.
1. Disconnect the Computer From the Internet
If the remote session may still be active, disconnect the affected computer from the network.
You can:
- Turn off Wi-Fi
- Unplug the Ethernet cable
- Disable the network adapter if necessary
This can interrupt an active remote connection and reduce ongoing communication while you investigate. CISA also recommends disconnecting affected systems from the internet in serious compromise scenarios.
2. End the Remote-Access Session
If the remote-control app is still open, end the session.
Common remote-access tools may include:
- AnyDesk
- TeamViewer
- Chrome Remote Desktop
- Quick Assist
- Other remote-support software
If you do not recognize the active connection, close the remote-access program.
If necessary, use Task Manager to end the application.
3. Do Not Continue Talking to the Scammer
If the remote access began through a suspicious phone call, pop-up, email, or support message, stop communicating with the person.
Do not:
- Call them back
- Follow more instructions
- Approve additional access
- Give verification codes
- Send screenshots
- Share passwords
- Pay more money
FTC guidance says unexpected tech-support contacts should not be trusted and should be reported as scams.
4. Remove the Remote-Access Software if You Did Not Intentionally Install It
If the scammer told you to install remote-control software, uninstall it after ending the session.
Open:
Settings → Apps → Installed apps
Look for software that appeared during the incident.
Remove the program if you know it was installed only for the suspicious session.
Do not remove unfamiliar Windows components randomly.
5. Check Startup Apps
Some remote-access tools may be configured to start automatically.
Open:
Task Manager → Startup apps
Look for unfamiliar remote-control software.
If you recognize an unwanted remote-access program, disable its startup behavior and uninstall the application.
6. Restart the Computer
After ending the session and removing suspicious software, restart the PC.
This can terminate processes that were still running.
However, restarting alone does not prove the computer is safe.
Continue with malware scanning.
7. Run Windows Security
Open:
Start → Windows Security → Virus & threat protection
Run a Quick scan first.
Microsoft recommends using trusted security tools to scan computers after suspected scam or malware activity.
8. Review Protection History
Open:
Windows Security → Virus & threat protection → Protection history
Look for:
- Threat detected
- Quarantined item
- Action required
- Potentially unwanted application
- Remediation incomplete
Do not automatically restore anything unfamiliar.
9. Run a Full Scan if You Have Stronger Concerns
If the scammer installed software, opened files, or spent significant time controlling the computer, consider a Full scan.
Open:
Windows Security → Virus & threat protection → Scan options → Full scan
A Full scan is more thorough than a Quick scan and can take longer.
10. Consider Microsoft Defender Offline
If you believe malware may be persistent or interfering with normal Windows scans, Microsoft Defender Offline may provide a deeper check.
It runs outside the normal Windows environment after restart.
This is more appropriate when there is a stronger reason to suspect hidden or persistent malware.
11. Consider a Reputable Second-Opinion Scanner
If you remain concerned after Windows Security scans, a reputable on-demand malware scanner can provide another opinion.
Use established security tools from official vendor websites.
Do not download random “PC cleaner” programs from advertisements or pop-ups.
FTC guidance specifically recommends legitimate security software after tech-support scams.
12. Change Important Passwords From a Trusted Device
If the scammer could see or control the computer while you were signed in, assume important credentials may have been exposed.
Use another trusted device when possible.
Prioritize:
- Primary email
- Banking
- Password manager
- Microsoft or Google account
- Cloud storage
- Social media
- Shopping accounts
FTC advises changing passwords that were shared with a scammer, including other accounts that reuse those passwords.
13. Change Reused Passwords Too
If the same password was used on several websites, change those accounts.
Use a different password for every important service.
A password manager can make this much easier.
14. Enable Multi-Factor Authentication
Turn on MFA or 2-Step Verification for important accounts.
This adds another barrier even if the password was exposed.
Prefer stronger authentication methods where available, such as:
- Authenticator apps
- Passkeys
- Security keys
15. Review Your Email Account
Your email account is especially important because it can be used to reset passwords for many other services.
Review:
- Recent sign-ins
- Unknown devices
- Recovery information
- Forwarding rules
- Security alerts
- Messages you did not send
If anything looks unfamiliar, secure the account immediately.
16. Review Your Microsoft or Google Account Activity
If you were signed into a Microsoft or Google account during the remote session, review recent account activity.
Look for:
- Unrecognized sign-ins
- New devices
- Password changes
- Recovery changes
- Unknown connected apps
Remove anything suspicious.
17. Check Browser Extensions
A scammer may install browser extensions.
Review the extension manager in every browser you use.
Remove extensions you do not recognize or did not intentionally install.
Be cautious of extensions that request broad access to browsing data.
18. Check Browser Notification Permissions
Scam websites sometimes gain notification permission before or during a remote-access incident.
Review notification permissions and remove unfamiliar sites.
This can stop recurring fake virus alerts and scam messages.
19. Check Your Downloads Folder
Review files downloaded during the incident.
Pay attention to unfamiliar:
-
.exe -
.msi -
.zip - Scripts
- Installers
Do not reopen suspicious downloads.
Scan them or remove them if they were clearly part of the scam.
20. Review Installed Applications
Open:
Settings → Apps → Installed apps
Look for programs added around the time of the remote session.
Possible suspicious items may include:
- Remote-control software
- Fake antivirus
- PC cleaners
- Unknown browser tools
- System optimizers
Research unfamiliar programs before removing them.
21. Check Financial Accounts Immediately if Sensitive Information Was Visible
If the scammer saw:
- Online banking
- Card details
- Payment apps
- Financial statements
review those accounts.
Contact the bank or card issuer using official contact details if you see suspicious activity or if payment information may have been exposed. FTC guidance recommends contacting relevant institutions when scam-related financial information is involved.
22. If You Paid the Scammer
Contact the payment provider or financial institution as soon as possible.
Explain that the payment was connected to a scam.
Ask what dispute, fraud, or protective options are available.
Do not pay another person who promises to recover the money for an upfront fee.
23. If You Gave the Scammer a Verification Code
Treat the affected account as compromised.
Immediately:
- Change the password
- Review sign-ins
- Remove unfamiliar devices
- Check recovery settings
- Re-enable MFA if necessary
A one-time code may have been used to complete a login.
24. If You Shared Personal or Identity Information
If the scammer saw or received sensitive personal information, monitor for identity-theft attempts.
Depending on what was exposed, you may need to:
- Monitor financial accounts
- Watch for new accounts
- Review official identity-protection guidance in your country
Your response should match the type of information exposed.
25. Check for New User Accounts
A scammer with sufficient access may try to create another Windows user account.
Open:
Settings → Accounts → Other users
Look for accounts you do not recognize.
Do not remove legitimate work or system accounts unless you understand what they are.
26. Check Remote Desktop Settings
If you did not intentionally use Windows Remote Desktop, review:
Settings → System → Remote Desktop
Make sure Remote Desktop is not enabled unexpectedly.
Do not change enterprise-managed settings on a work computer without contacting your IT department.
27. Check Whether Remote Software Was Set for Unattended Access
Some remote-control tools can be configured so a person can reconnect without asking for permission each time.
If you used such software, review its settings.
Disable:
- Unattended access
- Saved remote credentials
- Persistent remote permissions
Then uninstall the software if you no longer need it.
28. Change Your Wi-Fi Password if Necessary
Changing the Wi-Fi password is not automatically required after every remote-access scam.
However, consider it if:
- The scammer saw your router settings
- You shared the Wi-Fi password
- Router credentials may have been exposed
Also change the router administrator password if it was shown or shared.
29. Update Windows and Applications
After the incident, install available updates.
Update:
- Windows
- Browsers
- Security software
- Frequently used applications
This helps close known vulnerabilities and improves security protection.
30. Watch the Computer for Suspicious Behavior
After cleanup, monitor the PC.
Warning signs include:
- Repeated malware alerts
- Browser redirects
- Unknown programs
- New pop-ups
- Security settings changing
- Remote-access software reappearing
- High network activity
- Unknown account sign-ins
If these continue, deeper investigation may be needed.
If you still suspect an infection, follow our step-by-step guide to removing malware from a Windows PC.
31. When Should You Consider Resetting or Reinstalling Windows?
A full reset or reinstallation is not always necessary.
However, consider it when:
- The scammer had extended remote access
- Unknown software was installed
- Malware keeps returning
- Security settings were heavily modified
- You cannot determine what was changed
- You no longer trust the computer
CISA advises clean reinstallation in certain serious compromise scenarios when restoring trust to an affected system.
32. Back Up Personal Files Before a Reset
Before destructive recovery steps, back up important personal data where practical.
Focus on:
- Documents
- Photos
- Videos
- Work files
Do not blindly back up suspicious installers or unknown executable files.
33. Consider Professional Help for Serious Cases
Seek qualified technical help if:
- You cannot remove remote-access software
- Malware keeps returning
- Financial information was exposed
- The scammer changed important system settings
- You are unsure whether Windows can still be trusted
For workplace computers, contact your organization's IT or security team immediately.
34. Report the Scam
Microsoft provides a way to report technical-support scams.
If you are in the United States, the FTC also accepts scam reports.
Other countries have their own consumer-protection and cybercrime reporting channels.
35. A Quick Remote-Access Incident Checklist
If an unauthorized person accessed your PC:
- Disconnect the computer from the internet
- End the remote session
- Stop communicating with the scammer
- Remove suspicious remote-access software
- Restart the PC
- Run Windows Security
- Review Protection History
- Run a Full scan if necessary
- Consider Defender Offline
- Change important passwords from a trusted device
- Change reused passwords
- Turn on MFA
- Review email and major accounts
- Check financial accounts
- Review installed apps and browser extensions
- Check for unattended remote-access settings
- Monitor the PC for continued suspicious behavior
- Consider Windows reset/reinstallation if you cannot restore confidence
- Report the scam
36. The Most Important Rule
If someone you do not trust has remote control of your computer, your goal is not simply to “close the app.”
You need to consider:
- What they saw
- What they installed
- What accounts were open
- What information they may have copied
- Whether they can reconnect
Treat the device and accounts as separate security problems.
Final Verdict
Unauthorized remote access can be serious because another person may have been able to see files, install software, change settings, or capture account information.
Start by disconnecting the computer and ending the remote session.
Remove unwanted remote-access software, scan the PC, review installed applications, and change important passwords from a trusted device.
Then check email, financial accounts, recovery information, browser extensions, and account activity.
If you cannot confidently determine what was changed, a Windows reset or clean reinstallation may be the safest option.
Most importantly, never give remote access to someone simply because a pop-up, caller, or unexpected message claims your computer has a problem.
Guide note: This article reflects Microsoft, FTC, and CISA security guidance available in August 2026. Remote-access software, Windows security menus, scam techniques, and recovery options can change. For serious compromise, use current official support and consumer-protection guidance.

Comments
Post a Comment