Short answer
Act in this order: end the remote session and disconnect the computer from the internet, stop all contact with the caller, secure your accounts from a different device you trust, and contact your bank if any payment or banking details were involved.
Do these first
- 1
End the session and disconnect
If someone is connected right now, close the remote software or simply turn the computer off. Unplug the network cable or switch off Wi-Fi. Ending the connection matters more than shutting down gracefully.
- 2
Stop communicating
Hang up. Do not call back to "cancel the refund", do not reply to follow-up calls or emails, and expect them to try again — often claiming to be a different company offering to recover your money.
- 3
Send no further money
No legitimate company asks for gift cards, wire transfers, cryptocurrency or bank transfers to fix a computer problem. A request to move money "to protect it" is always part of the scam.
- 4
Move to a device you trust
Use a phone or another computer that was not part of the session for everything in the next section. Do not use the affected machine to change passwords.
- 5
Call your bank if money or banking was involved
If you paid, shared card details, or they were shown your online banking, contact your bank or card issuer immediately and tell them what happened. Speed matters for reversing transactions.
What actually happened
These scams follow a familiar script: a full-screen warning claiming Windows is infected with a number to call, or a cold call claiming to be Microsoft or your internet provider. The caller asks you to install a remote-support program, shows you routine system logs presented as evidence of infection, then quotes a price for a "fix".
Microsoft does not call people about virus infections, and no legitimate warning message includes a phone number to call. Once they have remote access, what happens next varies — that is why the honest answer to "is my computer infected?" is that it depends on what they did while they were connected.
- Often: remote-access software left installed, sometimes set to start automatically and to allow unattended connections.
- Often: settings changed — a new administrator account, a modified firewall, security tools disabled, a proxy or DNS entry added.
- Sometimes: passwords viewed or captured from a browser, or account recovery emails read.
- Sometimes: nothing at all beyond the payment, if you disconnected quickly.
Securing your accounts
- 1
Start with email
Your email account controls password resets for everything else. Change that password first, from your clean device.
- 2
Then banking and anything with a card on file
Banking, payment apps, shopping accounts. Use a different password for each.
- 3
Turn on multi-factor authentication
On email and banking at minimum. This is the single change that most reduces the damage from a stolen password.
- 4
Check for changes someone else made
In your email settings, look for forwarding rules, added recovery addresses or phone numbers, and unfamiliar signed-in devices. Sign out of all sessions.
- 5
Watch your statements
Review bank and card statements for the next few months. Small test charges often precede larger ones.
Keep the details
- The phone number you called or that called you, and the date and time.
- The name of any software they had you install.
- Receipts, gift card numbers and photos of cards, transaction references and amounts.
- Screenshots of the original warning message, if you have any.
Your bank will ask for this, and it is also useful when reporting the incident to the FTC at reportfraud.ftc.gov. Keep it even if you think recovery is unlikely.
Having the computer checked
The point of an inspection is not just running a scan. What matters is finding what was left behind and what was changed:
- Remote-access tools installed during the session, including ones configured for unattended access.
- Scheduled tasks, services and startup entries added to bring those tools back.
- New user accounts, especially administrator accounts.
- Firewall, DNS, proxy and browser settings that were altered.
- Any actual malware, credential-stealing tools or browser extensions.
- Security software that was disabled and never re-enabled.
Uninstalling the obvious program from the Apps list is a reasonable start but frequently misses the persistence — the parts that quietly restore access later.
When to stop doing this yourself
Stop if you are not certain the remote software is gone, if the machine behaves oddly afterwards, if money was taken, or if banking or work systems were open during the session. Those situations need someone to go through the machine properly rather than assume a scan settled it.
Bring the computer to our counter in Bellevue and tell us exactly what you remember about the session — what was installed, what was on screen, how long they were connected. That history shapes what we look for.
Common questions
- Does Microsoft ever call about a virus?
- No. Neither does your internet provider or a bank's "security department" asking to connect to your computer. Any such call is a scam, no matter what number appears on your caller ID.
- I paid with gift cards. Can I get the money back?
- Sometimes, if you act fast. Call the card issuer on the number on the back of the card, report the fraud, and keep the cards and receipts.
- Should I just reset the whole computer?
- Not before your files are backed up and verified, and not before someone has looked at what was changed. A reset erases evidence and your data, and it does not secure accounts that were already exposed.
- They were only connected for a minute. Is that safe?
- Shorter access reduces the risk but does not eliminate it — installing remote software takes seconds. An inspection is still worthwhile.
The service that covers this
Virus, Spyware & Adware Removal
Infections cleaned out properly — registry, temp files, browsers, and hidden leftovers.
Virus, Spyware & Adware Removal in Bellevue →Optional next step
After we clean it up, keep it protected.
Ask us about Home-IT for ongoing protection, monitoring and remote support — an optional extra layer of help when something looks wrong.
Learn About Home-IT →Related guides
- What To Do If Someone Remotely Accessed Your ComputerWhether it was a scam caller, a stranger or an ex-partner, remote access needs the same response: cut the connection, secure accounts, and check what was left behind.
- Fake McAfee Popup: What It Is and What To DoA McAfee subscription warning or virus alert appearing in your browser is almost always an impersonation, not a message from McAfee. Here is how to recognise it and clear it safely.
- Fake Virus Warning Popups: What They Are and What To DoA full-screen warning says your computer is infected and gives you a phone number. Here is how to tell a scam page from a genuine alert, and what to do next.
- Computer Keeps Restarting RandomlyRandom reboots with no blue screen usually mean power, heat or a fault Windows never got to log. Here is how to tell an automatic restart from a hardware cut.
