Start with the pattern, not a guess
After a scam or suspicious remote session, preserve a timeline and use a trusted device for financial and password changes. End remote access, contact affected institutions directly, and do not hide details out of embarrassment.
Practical checks and decisions
Work from observation to one controlled change at a time. Stop when the next step could risk data, accounts, electrical safety, or additional hardware damage.
Microsoft does not know your computer is infected from a random browser page
End the contact and do not use a phone number, link, download, or payment instruction supplied by the warning. Preserve the message, number, receipt, software name, and order of events.
Do not call numbers shown in full-screen security warnings
From a separate trusted device, protect email and financial access first. Contact banks and account providers through independently verified channels and change only credentials that may have been exposed.
Never share verification codes or buy gift cards for technical support
Disconnect unexpected remote access and do not continue arguing with the caller. Record whether the person saw the screen, installed software, opened accounts, received a code, or obtained payment information.
Close the browser safely and ask a trusted local person when uncertain
Review active sessions, forwarding rules, recovery methods, installed remote tools, and unfamiliar transactions. The response should match the access that actually occurred, not the scammer’s claims.
When a professional diagnosis makes sense
Get help promptly when money, passwords, email, remote access, or unfamiliar account activity may be involved. Preserve a timeline, end contact with the suspected scammer, and make urgent account changes from a separate trusted device.
For hands-on or remote help, explore the service options related to this issue, or browse the Help Center for another guide.
