Short answer
Disconnect the machine from the network first — that ends any live session immediately. Then secure your accounts from a different device, and have the computer checked for remote-access tools, added accounts and configuration changes rather than assuming a scan is enough.
Signs of remote access
- The cursor moves, windows open or text is typed while you are not touching anything.
- A remote-support program you did not install — the common names appear in your Apps list and in the system tray.
- The screen dims, a black window covers it, or a session notification appears briefly at startup.
- Sign-in alerts from accounts you did not sign into, or password reset emails you did not request.
- A new user account on the computer, or your account suddenly needing a different password.
- The machine wakes on its own, or the fans run at odd hours.
Immediate steps
- 1
Cut the network connection
Unplug the ethernet cable or switch off Wi-Fi. This ends any live session instantly and is faster than trying to close the program.
- 2
Do not keep working on the machine
Anything you type on a compromised computer — passwords included — may be visible to whoever set it up.
- 3
Secure email first, from another device
Change your email password on a phone or a different computer, then check for forwarding rules and unfamiliar recovery addresses.
- 4
Then banking, work and cloud storage
Change those passwords too, and sign out of all active sessions where the option exists.
- 5
Enable multi-factor authentication
It stops a stolen password from being enough on its own.
- 6
Contact financial institutions if warranted
If banking was open during the session, or payment information is stored on the machine, tell your bank and watch statements.
- 7
Note what you saw
Times, program names, on-screen messages, anything the person said. It shapes the inspection and matters if you report it.
What a proper check looks for
Remote access is a configuration problem as much as a malware problem. An antivirus scan will not flag a legitimate remote-support tool that someone installed deliberately, because the program itself is not malicious.
- Installed remote-support and remote-desktop software, including tools configured for unattended access.
- Windows Remote Desktop and remote assistance settings that were turned on.
- Scheduled tasks, services and startup entries created to reinstate access.
- Extra user accounts, particularly administrators, and password changes on existing accounts.
- Firewall rules, port forwarding on the router, DNS or proxy changes.
- Keyloggers, information stealers and browser extensions with broad permissions.
- Saved browser passwords that were accessible during the session.
- Security software that was disabled or excluded from scanning certain folders.
About your data
When to stop DIY
Stop if you cannot confirm what was installed, if the access happened more than once, if work or business systems were reachable from the machine, or if you are not confident the machine is clean. Continuing to use a computer you do not trust for banking is the real risk here.
When to have it checked
We go through the machine for remote-access tools, persistence, added accounts and changed settings, then confirm what is actually running before you use it for anything sensitive again. Bring it to the shop in Bellevue with whatever details you noted down — knowing which program was used shortens the job considerably.
Common questions
- Will antivirus software detect remote access?
- Not reliably. Most remote-support tools are legitimate programs, so a scanner has no reason to flag them. Detection depends on inspecting what is installed and configured, not just scanning.
- Is unplugging the internet enough?
- It ends the current session, which is the urgent part. It does nothing about what was already taken or left installed.
- Should I change passwords on the affected computer?
- No. Use a different device until the machine has been checked, or the new passwords may be captured too.
The service that covers this
Virus, Spyware & Adware Removal
Infections cleaned out properly — registry, temp files, browsers, and hidden leftovers.
Virus, Spyware & Adware Removal in Bellevue →Optional next step
After we clean it up, keep it protected.
Ask us about Home-IT for ongoing protection, monitoring and remote support — an optional extra layer of help when something looks wrong.
Learn About Home-IT →Related guides
- What To Do After a Fake Microsoft Support ScamYou called the number or let someone connect. Here is the order to do things in: cut access, secure accounts from a clean device, contact your bank, then have the computer checked.
- Browser Keeps Redirecting to Strange WebsitesUnexpected redirects, a search engine you didn't choose, new tabs opening on their own and constant popups usually come from an extension, adware or changed browser settings.
- Fake Virus Warning Popups: What They Are and What To DoA full-screen warning says your computer is infected and gives you a phone number. Here is how to tell a scam page from a genuine alert, and what to do next.
- Windows Blue Screen Keeps Happening: Reading the Stop CodeRepeated blue screens point at drivers, memory, storage, firmware or overheating. Learn what stop codes do and don't tell you, and which fixes to avoid early.
