What to Do If Someone Gets Remote Access to Your Computer

 


Giving someone remote access to your computer can become a serious security problem if that person is a scammer or someone you do not trust.

Remote-access software can allow another person to view your screen, control the mouse and keyboard, open files, install programs, change settings, and potentially see sensitive information. Microsoft specifically warns that tech-support scammers may ask for remote access while pretending to fix a computer, but then steal information or install malware.

If you think an unauthorized person had remote access to your Windows PC, act quickly but methodically.

1. Disconnect the Computer From the Internet

If the remote session may still be active, disconnect the affected computer from the network.

You can:

  • Turn off Wi-Fi
  • Unplug the Ethernet cable
  • Disable the network adapter if necessary

This can interrupt an active remote connection and reduce ongoing communication while you investigate. CISA also recommends disconnecting affected systems from the internet in serious compromise scenarios.

2. End the Remote-Access Session

If the remote-control app is still open, end the session.

Common remote-access tools may include:

  • AnyDesk
  • TeamViewer
  • Chrome Remote Desktop
  • Quick Assist
  • Other remote-support software

If you do not recognize the active connection, close the remote-access program.

If necessary, use Task Manager to end the application.

3. Do Not Continue Talking to the Scammer

If the remote access began through a suspicious phone call, pop-up, email, or support message, stop communicating with the person.

Do not:

  • Call them back
  • Follow more instructions
  • Approve additional access
  • Give verification codes
  • Send screenshots
  • Share passwords
  • Pay more money

FTC guidance says unexpected tech-support contacts should not be trusted and should be reported as scams.

4. Remove the Remote-Access Software if You Did Not Intentionally Install It

If the scammer told you to install remote-control software, uninstall it after ending the session.

Open:

Settings → Apps → Installed apps

Look for software that appeared during the incident.

Remove the program if you know it was installed only for the suspicious session.

Do not remove unfamiliar Windows components randomly.

5. Check Startup Apps

Some remote-access tools may be configured to start automatically.

Open:

Task Manager → Startup apps

Look for unfamiliar remote-control software.

If you recognize an unwanted remote-access program, disable its startup behavior and uninstall the application.

6. Restart the Computer

After ending the session and removing suspicious software, restart the PC.

This can terminate processes that were still running.

However, restarting alone does not prove the computer is safe.

Continue with malware scanning.

7. Run Windows Security

Open:

Start → Windows Security → Virus & threat protection

Run a Quick scan first.

Microsoft recommends using trusted security tools to scan computers after suspected scam or malware activity.

8. Review Protection History

Open:

Windows Security → Virus & threat protection → Protection history

Look for:

  • Threat detected
  • Quarantined item
  • Action required
  • Potentially unwanted application
  • Remediation incomplete

Do not automatically restore anything unfamiliar.

9. Run a Full Scan if You Have Stronger Concerns

If the scammer installed software, opened files, or spent significant time controlling the computer, consider a Full scan.

Open:

Windows Security → Virus & threat protection → Scan options → Full scan

A Full scan is more thorough than a Quick scan and can take longer.

10. Consider Microsoft Defender Offline

If you believe malware may be persistent or interfering with normal Windows scans, Microsoft Defender Offline may provide a deeper check.

It runs outside the normal Windows environment after restart.

This is more appropriate when there is a stronger reason to suspect hidden or persistent malware.

11. Consider a Reputable Second-Opinion Scanner

If you remain concerned after Windows Security scans, a reputable on-demand malware scanner can provide another opinion.

Use established security tools from official vendor websites.

Do not download random “PC cleaner” programs from advertisements or pop-ups.

FTC guidance specifically recommends legitimate security software after tech-support scams.

12. Change Important Passwords From a Trusted Device

If the scammer could see or control the computer while you were signed in, assume important credentials may have been exposed.

Use another trusted device when possible.

Prioritize:

  1. Primary email
  2. Banking
  3. Password manager
  4. Microsoft or Google account
  5. Cloud storage
  6. Social media
  7. Shopping accounts

FTC advises changing passwords that were shared with a scammer, including other accounts that reuse those passwords.

13. Change Reused Passwords Too

If the same password was used on several websites, change those accounts.

Use a different password for every important service.

A password manager can make this much easier.

14. Enable Multi-Factor Authentication

Turn on MFA or 2-Step Verification for important accounts.

This adds another barrier even if the password was exposed.

Prefer stronger authentication methods where available, such as:

  • Authenticator apps
  • Passkeys
  • Security keys

15. Review Your Email Account

Your email account is especially important because it can be used to reset passwords for many other services.

Review:

  • Recent sign-ins
  • Unknown devices
  • Recovery information
  • Forwarding rules
  • Security alerts
  • Messages you did not send

If anything looks unfamiliar, secure the account immediately.

16. Review Your Microsoft or Google Account Activity

If you were signed into a Microsoft or Google account during the remote session, review recent account activity.

Look for:

  • Unrecognized sign-ins
  • New devices
  • Password changes
  • Recovery changes
  • Unknown connected apps

Remove anything suspicious.

17. Check Browser Extensions

A scammer may install browser extensions.

Review the extension manager in every browser you use.

Remove extensions you do not recognize or did not intentionally install.

Be cautious of extensions that request broad access to browsing data.

18. Check Browser Notification Permissions

Scam websites sometimes gain notification permission before or during a remote-access incident.

Review notification permissions and remove unfamiliar sites.

This can stop recurring fake virus alerts and scam messages.

19. Check Your Downloads Folder

Review files downloaded during the incident.

Pay attention to unfamiliar:

  • .exe
  • .msi
  • .zip
  • Scripts
  • Installers

Do not reopen suspicious downloads.

Scan them or remove them if they were clearly part of the scam.

20. Review Installed Applications

Open:

Settings → Apps → Installed apps

Look for programs added around the time of the remote session.

Possible suspicious items may include:

  • Remote-control software
  • Fake antivirus
  • PC cleaners
  • Unknown browser tools
  • System optimizers

Research unfamiliar programs before removing them.

21. Check Financial Accounts Immediately if Sensitive Information Was Visible

If the scammer saw:

  • Online banking
  • Card details
  • Payment apps
  • Financial statements

review those accounts.

Contact the bank or card issuer using official contact details if you see suspicious activity or if payment information may have been exposed. FTC guidance recommends contacting relevant institutions when scam-related financial information is involved.

22. If You Paid the Scammer

Contact the payment provider or financial institution as soon as possible.

Explain that the payment was connected to a scam.

Ask what dispute, fraud, or protective options are available.

Do not pay another person who promises to recover the money for an upfront fee.

23. If You Gave the Scammer a Verification Code

Treat the affected account as compromised.

Immediately:

  • Change the password
  • Review sign-ins
  • Remove unfamiliar devices
  • Check recovery settings
  • Re-enable MFA if necessary

A one-time code may have been used to complete a login.

24. If You Shared Personal or Identity Information

If the scammer saw or received sensitive personal information, monitor for identity-theft attempts.

Depending on what was exposed, you may need to:

  • Monitor financial accounts
  • Watch for new accounts
  • Review official identity-protection guidance in your country

Your response should match the type of information exposed.

25. Check for New User Accounts

A scammer with sufficient access may try to create another Windows user account.

Open:

Settings → Accounts → Other users

Look for accounts you do not recognize.

Do not remove legitimate work or system accounts unless you understand what they are.

26. Check Remote Desktop Settings

If you did not intentionally use Windows Remote Desktop, review:

Settings → System → Remote Desktop

Make sure Remote Desktop is not enabled unexpectedly.

Do not change enterprise-managed settings on a work computer without contacting your IT department.

27. Check Whether Remote Software Was Set for Unattended Access

Some remote-control tools can be configured so a person can reconnect without asking for permission each time.

If you used such software, review its settings.

Disable:

  • Unattended access
  • Saved remote credentials
  • Persistent remote permissions

Then uninstall the software if you no longer need it.

28. Change Your Wi-Fi Password if Necessary

Changing the Wi-Fi password is not automatically required after every remote-access scam.

However, consider it if:

  • The scammer saw your router settings
  • You shared the Wi-Fi password
  • Router credentials may have been exposed

Also change the router administrator password if it was shown or shared.

29. Update Windows and Applications

After the incident, install available updates.

Update:

  • Windows
  • Browsers
  • Security software
  • Frequently used applications

This helps close known vulnerabilities and improves security protection.

30. Watch the Computer for Suspicious Behavior

After cleanup, monitor the PC.

Warning signs include:

  • Repeated malware alerts
  • Browser redirects
  • Unknown programs
  • New pop-ups
  • Security settings changing
  • Remote-access software reappearing
  • High network activity
  • Unknown account sign-ins

If these continue, deeper investigation may be needed.

If you still suspect an infection, follow our step-by-step guide to removing malware from a Windows PC.

31. When Should You Consider Resetting or Reinstalling Windows?

A full reset or reinstallation is not always necessary.

However, consider it when:

  • The scammer had extended remote access
  • Unknown software was installed
  • Malware keeps returning
  • Security settings were heavily modified
  • You cannot determine what was changed
  • You no longer trust the computer

CISA advises clean reinstallation in certain serious compromise scenarios when restoring trust to an affected system.


32. Back Up Personal Files Before a Reset

Before destructive recovery steps, back up important personal data where practical.

Focus on:

  • Documents
  • Photos
  • Videos
  • Work files

Do not blindly back up suspicious installers or unknown executable files.

33. Consider Professional Help for Serious Cases

Seek qualified technical help if:

  • You cannot remove remote-access software
  • Malware keeps returning
  • Financial information was exposed
  • The scammer changed important system settings
  • You are unsure whether Windows can still be trusted

For workplace computers, contact your organization's IT or security team immediately.

34. Report the Scam

Microsoft provides a way to report technical-support scams.

If you are in the United States, the FTC also accepts scam reports.

Other countries have their own consumer-protection and cybercrime reporting channels.

35. A Quick Remote-Access Incident Checklist

If an unauthorized person accessed your PC:

  • Disconnect the computer from the internet
  • End the remote session
  • Stop communicating with the scammer
  • Remove suspicious remote-access software
  • Restart the PC
  • Run Windows Security
  • Review Protection History
  • Run a Full scan if necessary
  • Consider Defender Offline
  • Change important passwords from a trusted device
  • Change reused passwords
  • Turn on MFA
  • Review email and major accounts
  • Check financial accounts
  • Review installed apps and browser extensions
  • Check for unattended remote-access settings
  • Monitor the PC for continued suspicious behavior
  • Consider Windows reset/reinstallation if you cannot restore confidence
  • Report the scam

36. The Most Important Rule

If someone you do not trust has remote control of your computer, your goal is not simply to “close the app.”

You need to consider:

  • What they saw
  • What they installed
  • What accounts were open
  • What information they may have copied
  • Whether they can reconnect

Treat the device and accounts as separate security problems.

Final Verdict

Unauthorized remote access can be serious because another person may have been able to see files, install software, change settings, or capture account information.

Start by disconnecting the computer and ending the remote session.

Remove unwanted remote-access software, scan the PC, review installed applications, and change important passwords from a trusted device.

Then check email, financial accounts, recovery information, browser extensions, and account activity.

If you cannot confidently determine what was changed, a Windows reset or clean reinstallation may be the safest option.

Most importantly, never give remote access to someone simply because a pop-up, caller, or unexpected message claims your computer has a problem.

Guide note: This article reflects Microsoft, FTC, and CISA security guidance available in August 2026. Remote-access software, Windows security menus, scam techniques, and recovery options can change. For serious compromise, use current official support and consumer-protection guidance.

Comments

Popular posts from this blog

VirusTotal Review: Can It Help You Check Suspicious Links and Files?

Complete Guide to Staying Safe Online: Websites, Apps, Offers, Payments and Privacy

How to Choose Safe and Useful Online Offers: A Beginner’s Guide