I have a more than five-year-old Acer laptop running Windows 11. On July 7, I downloaded what turned out to be a fake paperless postcard. The next day, ScreenConnect was running on the laptop. I removed it and ran an advanced Microsoft Defender scan, which reported no threats. My bank advised me to have the computer cleaned before closing and reopening my accounts. The following day, a technician found and removed two viruses, and I opened a replacement bank account.
On August 8, another remote-access program appeared when I started the laptop. I removed it and ran another Defender scan. A few days later, I noticed a $1 ACH withdrawal, followed by several more. I also received login attempts against my Facebook and Instagram accounts. While reviewing installed programs, I found and removed one called Quick Fix.
I'm concerned that the original phishing download installed multiple remote-access tools and exposed my banking and other account information. What is the safest way to remediate this computer, and what should I do about my bank accounts and passwords?
3 Answers
A clean reinstall is generally more reliable than trying to identify every persistence mechanism left by malware. If you have multiple internal drives, be careful not to erase the wrong one; disconnect secondary drives during installation if possible. After setup, reinstall software only from official sources and change credentials again if you ever enter them on the old installation.
The safest approach is to treat the laptop as compromised and perform a completely clean Windows installation. Disconnect it from the internet first. Using a different, trusted device, change every important password, enable two-factor authentication, review recent login activity, and sign out other sessions. Contact the bank’s fraud department about the ACH withdrawals and follow its instructions for disputing them and securing the account.
Back up only irreplaceable personal data, such as photos and documents, preferably after scanning it from a trusted bootable environment. Do not restore programs, installers, scripts, or unknown files. Boot from official Windows installation media, delete all partitions on the system drive, and install Windows again. Then fully update Windows and applications before restoring files.
Check whether any unwanted service remains, but don’t rely on uninstalling the visible remote-access apps. You can open Services with Win+R and run services.msc, then look for a remaining ScreenConnect service. If it exists, stop it and disable it, but a full wipe is still the better option given the repeated infections and financial activity.

I checked the Services list and ScreenConnect is not there. I’ll proceed with securing my accounts and arranging a clean reinstall.