I accidentally downloaded a fake Adobe Reader from a scam email, and it installed Hexnode-related management and remote-access software on my Windows laptop. The software was present for roughly 20 minutes before I noticed it. I disconnected from Wi-Fi, started the computer in Safe Mode, and eventually factory-reset and wiped the laptop after I couldn't uninstall the application normally.
I use this personal laptop for work, including accessing a third-party payment-processing service, although my access was revoked as soon as I reported what happened. I'm worried that the attacker may have captured my passwords, accessed files or browser data, or exposed my company to risk. I've changed my passwords and enabled two-factor authentication on important accounts, but I'm unsure whether the factory reset completely removed the software or whether the computer is safe to use again. What else should I do?
3 Answers
Treat the laptop as compromised. From a different, trusted device, change every password that was used on it, starting with email, banking, work accounts, password managers, and any account with saved browser credentials. Sign out other sessions, revoke active tokens, and enable app-based two-factor authentication. Also notify your employer, IT team, and the payment provider so they can review logs and rotate any relevant credentials. A 20-minute exposure doesn’t prove that data was stolen, but remote-access software could potentially expose anything visible or accessible during that time.
For the computer itself, the safest option is a genuine clean Windows installation from Microsoft-created USB media, made on a trusted computer, rather than relying only on the built-in reset. Delete the existing partitions during setup and install fresh drivers and applications from official sources. Keep Windows and security software updated, and don’t restore unknown executables or browser extensions from backups. If you need maximum assurance, have a reputable incident-response technician examine it before putting it back into service.
The company should assume the work account and any payment-related access available from that laptop may have been exposed, even if the attacker never used it. Revoking access immediately was the right move. They should reset work credentials, invalidate sessions and API keys, check authentication and payment-service logs, and follow their incident-reporting procedures. Whether the company has a reportable incident depends on what access and data were involved, so let the company’s IT or security staff make that determination.

A normal reset is often enough for ordinary malware, but reinstalling from trusted USB media gives you more confidence that the disk was actually erased and the operating system was rebuilt. Firmware-level persistence is uncommon, though a professional can investigate if there are still unusual symptoms.