I received a phishing email that appeared to come from someone I trusted and accidentally downloaded and ran an EXE file. It installed ScreenConnect, a remote-access application. I noticed it after roughly 10 minutes, uninstalled it, and disconnected the computer from the internet. Microsoft Defender Offline and a full Defender scan found nothing, and I also checked services, scheduled tasks, and ScreenConnect-related folders without finding anything suspicious. Is uninstalling the software and running clean scans enough, or should I completely wipe and reinstall Windows? I'm especially concerned that the installer may have included persistence or another payload such as an information stealer or keylogger.
4 Answers
A clean Defender result is reassuring, but it doesn’t prove that only ScreenConnect was installed. A customized installer can provide unattended access or drop additional malware. Run another reputable on-demand scanner, review startup items, services, scheduled tasks, and recent security logs, and check ScreenConnect events in Event Viewer for connections, file transfers, or remotely executed commands. If you find evidence of commands or transferred files, treat the machine as compromised.
Because remote-access installers can establish persistence and you can’t reliably know what happened during those ten minutes, I’d disconnect the computer, back up only personal documents after scanning them, and perform a clean Windows reinstall. Don’t restore unknown executables or scripts afterward. Also change passwords from a known-clean device, revoke active sessions, and enable multifactor authentication, especially for email, banking, and password-manager accounts.
If you decide not to reinstall, at minimum run multiple reputable scans and carefully inspect persistence locations and logs. However, security scans can miss a customized payload, so reinstalling is the more dependable answer when the computer held sensitive accounts or files.
Check Event Viewer under Windows Logs > Application and filter for ScreenConnect-related events around the time of the incident. Depending on the version, events may show the software contacting its server, an interactive connection, a disconnect, remote command execution, or file transfers. Any command execution or file transfer would make a complete wipe and reinstall the safest option.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures