Short answer
Disconnect the machine from the network first — that ends any live session immediately. Then secure your accounts from a different device, and have the computer checked for remote-access tools, added accounts and configuration changes rather than assuming a scan is enough.
Signs of remote access
- The cursor moves, windows open or text is typed while you are not touching anything.
- A remote-support program you did not install — the common names appear in your Apps list and in the system tray.
- The screen dims, a black window covers it, or a session notification appears briefly at startup.
- Sign-in alerts from accounts you did not sign into, or password reset emails you did not request.
- A new user account on the computer, or your account suddenly needing a different password.
- The machine wakes on its own, or the fans run at odd hours.
Immediate steps
- 1
Cut the network connection
Unplug the ethernet cable or switch off Wi-Fi. This ends any live session instantly and is faster than trying to close the program.
- 2
Do not keep working on the machine
Anything you type on a compromised computer — passwords included — may be visible to whoever set it up.
- 3
Secure email first, from another device
Change your email password on a phone or a different computer, then check for forwarding rules and unfamiliar recovery addresses.
- 4
Then banking, work and cloud storage
Change those passwords too, and sign out of all active sessions where the option exists.
- 5
Enable multi-factor authentication
It stops a stolen password from being enough on its own.
- 6
Contact your bank directly if money could be involved
If banking was open during the session, if payment details are stored on the machine, or if you were asked to move money or buy gift cards, call your bank using the number on the back of your card or on a statement — never a number the caller gave you, and never one from a popup. Ask them to review recent activity and flag the account.
- 7
Note what you saw
Times, program names, on-screen messages, anything the person said. It shapes the inspection and matters if you report it.
What a proper check looks for
Remote access is a configuration problem as much as a malware problem. An antivirus scan will not flag a legitimate remote-support tool that someone installed deliberately, because the program itself is not malicious.
- Installed remote-support and remote-desktop software, including tools configured for unattended access.
- Windows Remote Desktop and remote assistance settings that were turned on.
- Scheduled tasks, services and startup entries created to reinstate access.
- Extra user accounts, particularly administrators, and password changes on existing accounts.
- Firewall rules, port forwarding on the router, DNS or proxy changes.
- Keyloggers, information stealers and browser extensions with broad permissions.
- Saved browser passwords that were accessible during the session.
- Security software that was disabled or excluded from scanning certain folders.
About your data
When to stop DIY
Stop if you cannot confirm what was installed, if the access happened more than once, if work or business systems were reachable from the machine, or if you are not confident the machine is clean. Continuing to use a computer you do not trust for banking is the real risk here.
When to have it checked
We go through the machine for remote-access tools, persistence, added accounts and changed settings, then confirm what is actually running before you use it for anything sensitive again. Bring it to the shop in Bellevue with whatever details you noted down — knowing which program was used shortens the job considerably.
Common questions
- Will antivirus software detect remote access?
- Not reliably. Most remote-support tools are legitimate programs, so a scanner has no reason to flag them. Detection depends on inspecting what is installed and configured, not just scanning.
- Is unplugging the internet enough?
- It ends the current session, which is the urgent part. It does nothing about what was already taken or left installed.
- Should I change passwords on the affected computer?
- No. Use a different device until the machine has been checked, or the new passwords may be captured too.
The service that covers this
Virus, Spyware & Adware Removal
Browser popups, fake warnings, malware and hacked computers cleaned out properly — registry, temp files, browsers and hidden leftovers.
Virus, Spyware & Adware Removal in Bellevue →Optional next step
After we clean it up, keep it protected.
Ask us about Home-IT for ongoing protection, monitoring and remote support — an optional extra layer of help when something looks wrong.
Learn About Home-IT →Related guides
- What To Do After a Fake Microsoft Support ScamYou called the number or let someone connect. Here is the order to do things in: cut access, secure accounts from a clean device, contact your bank, then have the computer checked.
- My Email Was Hacked: What To Do FirstFriends getting messages you didn't send, password reset emails you didn't ask for, or mail disappearing. Here's the order to fix it in and how to stop it happening again.
- I Think My Computer Was Hacked: What To Do FirstStrange behaviour, popups, a cursor moving on its own or a support call you now regret. Here's how to tell what you're dealing with, what to do first, and what not to do.
- Browser Keeps Redirecting to Strange WebsitesUnexpected redirects, a search engine you didn't choose, new tabs opening on their own and constant popups usually come from an extension, adware or changed browser settings.
- Locked Out Of Windows: Password Or PIN Not WorkingWindows says your password or PIN is wrong, or the sign-in screen loops back on itself. Here's what usually causes it, what's safe to try, and what to do when nothing works.
