Fake Tech Support Scam: What to Do After Giving Remote Access to Your PC

Fake support controlled your PC? Contain the access first

End the session, preserve evidence and immediately separate the computer, accounts, email and payments.

Summary

Computer Technician in Dordogne – Fast On-Site Support

Tera24 supports homeowners, small businesses, associations, and tourist accommodations with all their IT needs across Dordogne. From Windows and Mac computer repairs to virus removal, printer installation, system optimization, data backup, Wi-Fi network troubleshooting, and on-site IT support, we provide reliable and responsive assistance tailored to your needs.

Secure each area in order without promising absolute disinfection

This guide moves from isolating the PC to choosing monitoring, deeper cleanup or a reset.

Regain control first, without letting panic set the agenda

If someone claiming to be technical support controlled your PC, the immediate goal is not to guess everything they might have done. End their access, preserve useful evidence and separate four areas: the computer, your accounts, your email and your payment methods. This order limits further access without wiping away information you may need later.

Fake support operators may ask you to install a remote-control tool and present normal system messages as evidence of a fault. Microsoft also states that genuine Microsoft error messages and warnings do not include a phone number to call, and that the company does not proactively contact individuals to request personal or financial information or to repair a PC. An urgent alert, an unsolicited call and a request for remote access should therefore be treated with caution.

An alarming screen does not prove the diagnosis offered on the phone. If the caller used a real crash to support the story, my guide to finding the real cause of a Windows blue screen brings the process back to technical evidence rather than the caller’s script.

Do not call back the number shown in the alert or supplied during the conversation. Do not approve another request, even if the caller says they need to “finish the repair” or “cancel a transaction”.

End the session and disconnect the PC without destroying useful evidence

If remote control is still active, close the control session when you can, then disconnect the PC from the network: turn off Wi-Fi and unplug Ethernet if present. If you cannot control the pointer, isolate the computer from the network first. You may leave it powered on long enough to record what is visible, provided that doing so cannot allow the remote session to resume.

Use another device to photograph the screen, the number called, the time, open windows and any messages. Keep emails, text messages, invoices, receipts, transaction references and call history. Write down what you disclosed: a password, one-time code, address, payment details or identity document. Separate what you observed from what the caller claimed.

  • Stop remote access before continuing the conversation.
  • Isolate the PC without immediately deleting files and applications.
  • Record the time, sequence of events and actions you actually performed.
  • Use another device for urgent account and payment work.

Do not use the exposed PC to sign in to online banking or change passwords while its condition is unclear. Use a trusted device and a network you control.

Remove remote-control tools and check automatic startup entries

After preserving the basic evidence, list the applications installed or opened during the call. Do not identify a tool by its icon alone. Compare the displayed name, publisher, installation date and the purpose the caller gave it. After this type of exposure, Microsoft advises removing the applications requested by the fake support operator.

Uninstall remote-control tools that you installed at the caller’s request and did not use before. Then review applications that start automatically, notification-area icons and browser extensions added during the same period. The aim is to prevent persistent access, not to delete every unfamiliar program at random.

If you are unsure about an entry, record its exact name and have it checked before removal. Disorganised deletion can break legitimate software without answering what happened. I prefer a simple timeline: present before the call, installed during the call, or first seen afterwards.

Do not reconnect the PC merely to download a random “cleaner”. Prepare updates and tools from official sources first, or have the machine examined if the exposure remains uncertain.

Scan the PC and explain why a clean result is not an absolute guarantee

A fake support operator may try to steal information or install malicious software while controlling the computer. After removing the requested applications, Microsoft recommends a full scan, applying updates and changing passwords. Run a full scan with the security protection maintained on the PC, then review the result instead of stopping at a “completed” message.

A clean result is reassuring, but it does not prove that no information was viewed, copied or transmitted during the session. It also cannot tell you what someone may do with a password entered or a code disclosed. A scan addresses risk on the computer; it does not replace account security.

  • Keep the report or a screenshot of the scan result.
  • Install operating-system and application updates through official channels.
  • Watch for alerts, access requests, new accounts and unusual behaviour.
  • Have the machine examined if removal fails or you cannot reconstruct the access obtained.

Neither an antivirus scan with no detection nor a reset is absolute proof that no compromise occurred. These actions reduce certain risks; they cannot retract information already disclosed.

Change passwords from a trusted device and enable multi-factor authentication

Start with your main email account because it may be used to reset other access. From a trusted device, choose a new, unique password and enable multi-factor authentication when available. Sign out sessions you do not recognise and review connected devices, recovery methods and backup contact details.

Continue with accounts used or displayed during the session, then any account that reused the same password. Do not turn one old password into a predictable variation. If you use a password manager, secure its main account first and review recent connections before changing the remaining credentials.

Treat a verification code you disclosed as used, even if it has since expired. Check the action it authorised: a sign-in, device addition, recovery change or transaction approval. Multi-factor authentication protects future sign-ins more effectively, but it does not replace that review.

Open account settings through an address you type yourself or an official app already installed. Do not use a “security” link received during the fake support conversation.

Check email forwarding, financial accounts and affected payment methods

In your email settings, inspect forwarding rules, filters, automatic replies, delegates and recovery addresses. Review sent, deleted and trashed messages as well. An unknown forwarding rule may continue to transmit information after a password change; record it, remove it and close unknown sessions.

For financial accounts, review beneficiaries, contact details, recognised devices and transactions you do not understand. If a payment method was used during the exchange, Microsoft recommends contacting its issuer to dispute transactions and protect the account. Use the official number on your card or statement, or a website address you enter yourself, never a number supplied by the caller.

Describe the event factually: remote control, information shown, code disclosed, payment requested and approximate time. The issuer determines the measures appropriate for the account. Continue monitoring notifications and statements without responding to follow-up calls from the fake support operator.

The PC, email and payment method require separate checks. A computer that appears normal does not prove an account is intact, and blocking a card does not clean the PC.

Preserve factual evidence and report the scam through official channels

Collect copies of phone numbers, addresses, screenshots, messages, receipts, payment references and application names. Add a short factual timeline: first contact, start and end of remote control, information supplied, files opened, any payment and the security actions already taken. Keep the originals and work from copies where possible.

Report the event through official channels for your country, such as the appropriate public reporting portal, law-enforcement body or specialist authority according to the nature and urgency of the case. Schemes and addresses differ between countries, so verify that the site is official before submitting documents. I avoid providing one generic address that may not apply to your location.

If a company or public body was impersonated, you can also use its official reporting channel found independently of the suspicious message. Do not contact the organisation through details included in the alert. Reporting does not replace contacting the payment issuer or securing the computer and accounts.

Do not post screenshots publicly without reviewing them. They may expose your address, credentials, financial references or codes that remain sensitive.

Choose monitoring, deeper cleanup or reset according to the actual exposure

The right response depends on the actual exposure. A session stopped before any installation, with no account opened and no information shared, does not justify the same response as prolonged control with elevated rights, passwords entered, email viewed or a payment made. I first classify what is confirmed, plausible and unknown.

  • Enhanced monitoring: suitable when access was very limited, checks are consistent and no persistent behaviour is found.
  • Deeper cleanup: appropriate when a tool was installed, a scan reports an item or settings were changed.
  • Reset or clean reinstallation: worth considering when actions cannot be reconstructed, trust in the system is lost or signs return after cleanup.

Before resetting, back up only the documents you need and make sure you can reinstall software cleanly and recover your accounts. Keep monitoring the accounts afterwards: reinstalling addresses the PC, not information already shared.

If you cannot determine the extent of the session, sensitive data was opened or alerts persist, stop improvised testing. An independent diagnosis should document the observations, explain what can be checked and state what will remain impossible to prove.

The goal is not to declare the computer “clean” at any cost. It is to reduce risk proportionately, protect the affected accounts and keep a clear record of the decisions made.

Picture of Damien DELPHIN

Damien DELPHIN

IT technician and founder of Tera24, I provide computer repair, troubleshooting, and optimization services throughout Dordogne, helping individuals and businesses keep their technology running smoothly.

More articles