The call usually starts the same way. "I think I have been hacked. What do I do?" Sometimes it is a full-screen warning with a phone number. Sometimes a "Microsoft technician" was on the computer for forty minutes before the person got a bad feeling. Sometimes a friend texts to ask why they got a weird email.
Here is the plan I give people over the phone. It is written for the first hour, in order, because the order matters.
Minute 0 to 5: cut the connection
Disconnect the computer from the internet. Pull the network cable, or turn off Wi-Fi. If the screen is locked by a scary warning and you cannot get to the Wi-Fi icon, hold the power button until the machine turns off.
This does two things. It kicks out anyone who is connected right now, and it stops the malware from downloading more pieces or spreading to other computers in the house.
Do not call the number on the screen. Do not pay anything. Real companies do not put phone numbers in warnings. Real ransomware notes are also a scam in the sense that paying rarely gets your files back and always marks you as someone who pays.
If you have external drives plugged in, unplug those too. Ransomware goes after every drive it can see.
Minute 5 to 25: pick up your phone, not the computer
Everything in this section happens on a different device. Your phone is fine. Do not log into anything on the compromised computer, even after you have disconnected it, because a keylogger does not need the internet to record what you type.
Change your email password first. Not the bank, not Facebook. Email. Your email account is the master key to everything else, because every "forgot password" link goes there. If an attacker owns your email, they can reset the rest at their leisure.
While you are in your email:
- Check for forwarding rules you did not create. Attackers set these up so they keep getting copies of your mail after you change the password. In Gmail this is under Settings, then Forwarding and POP/IMAP, plus the Filters tab. In Outlook it is under Rules.
- Check the recovery phone and recovery email. If either one is not yours, remove it.
- Look for a "sign out of all devices" option and use it.
- Turn on two-factor authentication if it was off.
Now do the bank. Change the password, turn on two-factor, and look at recent activity. If you logged into your bank while the attacker was connected, or if you gave anyone card numbers or bought gift cards for them, call the bank's fraud line right away. The number is on the back of your card. Banks are very used to this call.
Then work down the list: any other financial accounts, Amazon, Apple or Google account, PayPal, Venmo, and anything that has a card saved.
Minute 25 to 40: figure out how it happened
You do not need to be technical for this. You need to be honest with yourself, because the answer changes what has to be cleaned.
- Did someone call you, or did you call a number? That is a remote-access scam. They almost certainly installed software that lets them reconnect later, and they may have looked through your saved passwords and documents. Treat every account on that computer as exposed.
- Did you download something? A "free" version of a paid program, a game mod, a PDF converter, a driver updater. That is a classic malware delivery method and it usually comes with a bundle of unwanted programs.
- Did you click a link in an email or text and log in somewhere? That is phishing. The computer may be fine, but the account you logged into is not. Change that password and check it for forwarding rules just like the email.
- Did a pop-up tell you to update Chrome, Flash, or a font? Fake updates are one of the most common infections we see. The "update" was the malware.
- Did it just start acting strange? Slow, hot, pop-ups, the home page changed. That is more likely adware or a browser hijacker than a live person, but it still needs a proper cleanout.
Write down what you remember. What the caller said, what you clicked, roughly when it started. It helps whoever cleans the machine.
Minute 40 to 60: warn people and check the rest of the house
If the attacker had your email or your contacts, tell your family and close friends that they may get messages from you asking for money, gift cards, or a "quick favor." The follow-on scams are often worse than the original break-in.
Then think about what else is on your network. If a person was connected to your computer, they were inside your home network. Other computers, the NAS, the printer with the admin password nobody changed. Most scammers do not bother going further, but if you have a business or work-from-home setup, assume they looked.
Finally, check your router. Log into it from your phone and confirm the DNS servers have not been changed and that remote management is off. If you do not know how, that is something we check as part of a cleanout.
What not to do
Do not run five different "PC cleaners" you found on Google. Half of them are the problem, and the other half will not catch what matters. If you want to try a scan yourself, use the tools in our free-tools virus removal guide. Those are safe.
Do not wipe the computer in a panic. A reinstall does clear the infection, but it also loses your files if they were not backed up, and it does nothing about the passwords and accounts that were already taken.
Do not trust a callback offering a refund. After a scam, victims are often called by the same crew pretending to be a refund department, the police, or the bank. If you did not start the call, hang up and call the real number yourself.
Do not reuse the old password with a number added. They already have the old one.
Why a quick scan does not count as "cleaned"
This is the part people find hardest to hear. Running an antivirus scan and seeing "0 threats found" does not mean the computer is clean. It means that one program did not recognize anything on its list.
Attackers, and the scammers who bought your information from them, do not rely on a single virus file. They leave behind ways to get back in:
- A remote-access tool that looks like legitimate software, because it is legitimate software
- A scheduled task that quietly reinstalls the malware every night at 3 a.m.
- A browser extension that reads every page you visit
- A hidden Windows user account with administrator rights
- Changed DNS settings that send you to fake versions of real sites
- A rogue certificate that makes those fake sites show a padlock
No antivirus scan looks for most of that. A person does.
That is why our virus and hacker cleanout is five stages instead of one scan. We boot the computer from Linux so Windows cannot hide anything from us, run several AI-powered scanners from different vendors inside Windows, and then go through startup items, tasks, services, extensions, accounts, and network settings by hand. After that we lock down the accounts, patch everything, and confirm it is clean with a second-opinion scan. It is $150 flat per computer, your files stay where they are, and you get a plain-English explanation of what we found.
After it is clean: make sure it does not happen again
Most people who go through this once never want to go through it again. Here is what actually helps, in order of how much difference it makes:
- Two-factor authentication on email and bank. Free, five minutes, stops most account takeovers cold.
- A password manager so every site has its own password. Then one leaked password is one leaked password.
- Updates installed promptly. Most break-ins use holes that were fixed in a patch that nobody installed.
- Real protection with someone watching it. Consumer antivirus tells you about a problem, if you happen to notice the pop-up. Our Home Protection Plan puts Bitdefender GravityZone with EDR on the machine, the same product our business clients run, with Syncro RMM sending alerts to us around the clock. Patching is handled, drive health is watched, and blocked threats show up on our screen, not just yours. It is $12.50 a month per computer with autopay, half the regular $25 price.
Quick questions
Was I actually hacked, or was it just a scary pop-up? Often it was just scareware, a web page designed to look like a system alert. If you closed it and did not call the number or install anything, you are probably fine. Clear your browser history and run a Malwarebytes scan to be sure. If you called, installed something, or let someone connect, assume the worst and follow the steps above.
Should I report it? For money lost, yes. Your bank first, then the FTC at reportfraud.ftc.gov and the FBI's IC3 at ic3.gov. Reports rarely get money back, but they build the cases that eventually shut these crews down.
Can you tell me who did it? No, and be careful of anyone who says they can. What we can do is tell you how they got in, what they touched, and make sure they are out.
How fast can you look at it? Call us. Cleanouts are usually done within a day or two, and rush service is available when you need the machine back faster. We can come to you, you can drop it off in Middletown, or for many software-only infections we can handle it remotely while you watch.
If you are reading this on your phone because the computer is doing something you do not like, call or text (860) 398-9221. That is exactly what the number is for.
