GuideHQ

What do I do if I let someone control my computer?

The order to work in after a remote access scam: money first, then access, then the machine — and why changing passwords on the affected computer makes things worse.

Difficulty
intermediate
Time
1 hr 30 min
Read
4 min
Safety
warning

Short answer

Disconnect the computer from the internet immediately. Then, from a different device, call your bank and change the passwords for email and banking. Only after that should you deal with the machine itself: remove the remote access software, run a full scan, and consider a clean reinstall.

Remote access scams usually arrive as a call about a refund, a virus warning, or a broadband problem. Whoever was on the other end could see everything on screen and could install anything. The recovery order matters because the wrong order hands them the new passwords too.

Safety

Assume anything typed or stored on that computer during and before the session is known, including saved passwords and banking details. Change passwords from a different device, never from the affected one, until it has been cleaned. Contact your bank straight away if any banking site was open during the session.

Step by step

  1. Disconnect the computer from the internet now.Unplug the ethernet cable or turn wifi off at the machine. Do not simply close the software — the session can be resumed. Leave the computer switched off if you are not working on it.
  2. Call the bank from a different phone or device.If any banking site or app was open, or if you were talked into a refund process, ring the number on your card, or 159 where supported. Refund scams usually end with money leaving, not arriving.
  3. Change critical passwords from a different device.Email first, because it is the reset route for everything else, then banking, then anything with a card stored. Use a phone or another computer that was never part of the session.
  4. Sign out of all sessions everywhere.Major accounts have a security page listing signed-in devices with a 'sign out everywhere' option. This ejects anyone still holding a session token even after a password change.
  5. Check email rules and forwarding.A common step is to add a forwarding address or a rule that hides bank emails. Check the mail settings for forwarding, rules and filters you did not create.
  6. Remove the remote access software.It is ordinary, legitimate software used dishonestly — names like AnyDesk, TeamViewer and similar. Uninstall it through the normal remove-programs process, and check what else was installed the same day.
  7. Run a full scan with the built-in security tool.Windows Security or the equivalent, updated first, with a full rather than quick scan. A clean result is reassuring but not conclusive.
  8. Consider wiping and reinstalling.If banking was used on that machine, or the session was long, a clean reinstall is the only way to be certain. Back up documents and photos only, not applications or settings.
  9. Report it.Action Fraud, or Police Scotland on 101 in Scotland. Tell your bank even if no money moved, so the account is flagged.
  10. Watch the accounts for a few weeks.Check statements, and consider a credit report check. Some fraud appears weeks later using details gathered during the session.

Tips

  • Genuine organisations do not ask for remote access. Microsoft, your bank and your broadband provider will never call you and ask to control your computer.
  • A refund scam often involves showing you an inflated refund and asking you to send back the difference. The screen was edited; nothing was ever paid in.
  • If a password manager was unlocked during the session, change its master password and consider every stored password compromised.

Common mistakes

  • Changing passwords on the affected computer — If anything is still installed, the new passwords are captured as you type them. Always use a different device until the machine is clean.
  • Only closing the remote access window — The software remains installed and can reconnect. It has to be uninstalled, and the machine disconnected until it is.

If it doesn't work

Money has left the account

Cause: A transfer was made during or after the session — Fix: Tell the bank immediately and use the phrase 'authorised push payment fraud'. Speed is the main factor in recovery.

Cannot sign in to email any more

Cause: The password and recovery details were changed — Fix: Use the provider's account recovery process from a clean device. Expect it to take time and to require identity evidence.

New software or a browser extension appeared

Cause: Installed during the session — Fix: Remove anything dated that day, reset the browser to defaults, and run a full scan. Reinstalling the system is the safest option.

The caller keeps ringing back

Cause: Successful targets are called repeatedly and sold on to other groups — Fix: Do not answer or engage. Block the numbers, register with the Telephone Preference Service, and consider changing the number if it continues.

Questions people ask

They only looked, they did not install anything. Is that fine?

Treat it as if they did. You cannot verify what happened in a session you did not control, and looking is enough to capture saved passwords and card details from a browser.

Do I need to replace the computer?

No. A clean reinstall of the operating system removes anything installed. Replacing hardware is not necessary.

Written and maintained by the GuideHQ editorial team. More in Technology.