Body
Summary
Here’s a guide for the USNH ET&S Enterprise Help Desk and Collegis when handling a caller who has received fake support or virus pop-up - and what to do if they may have allowed remote access.
Initial Triage Questions for the Caller
These questions help assess the situation and determine the scope of potential compromise. It is critical for an investigation to capture responses to these questions:
Pop-up Details
Q1 - URL which generated pop-up or did it appear while browsing a specific website?
Q2 - What was the URL you were attempting to visit?
Q3 - What did the pop-up say? (e.g., virus alert, Microsoft support, etc.)
Q4 - Did it include a phone number or ask you to call someone?
Q5 - Did it lock your screen or prevent you from closing it?
Q6 - Were you able to get a screen grab?
Q7 - Did you run a virus/security scan? (User or Help Desk/Collegis rep)
Q7a - If yes, what tool was used?
Q7b - What were the results?
User Actions
Q8 - Did you call the number or interact with the pop-up?
Q9 - Did you download or install any software?
Q10 - Did you allow remote access (e.g., via TeamViewer, AnyDesk, GoToAssist)?
Q11 - Did you provide any personal or company information?
Q12 - Did you enter any credentials (email, Windows login, etc.)?
Q13 - Did you make any payments or provide credit card info?
System Behavior
Q14 - Is your system behaving unusually now (e.g., slow performance, pop-ups, unknown programs)? If YES, immediately disconnect from the network (Wi-Fi or Ethernet).
Q15 - Are you still connected to the remote session? If YES, immediately disconnect from the network (Wi-Fi or Ethernet).
Q16 - Have you rebooted or disconnected from the Internet?
Remedial Actions if Remote Access Was Granted
If the user allows a fake support agent to access their system, take these steps immediately:
Immediate Containment
Step 1 - If the answer to Q14 and/or Q15 is YES, or you believe there to be an imminent threat to USNH resources or data, or your personal data, then immediately disconnect from the network (Wi-Fi or Ethernet).
Step 2 - Immediately contact the USNH Cybersecurity Operations Team for quarantine. Message any of the following CyberOps Analysts:
- William Sames
- Carl Nickerson
- Matthew Reed
- Chris Garcia
- Joshua Annis
- Joe Gray
Credential Security
Step 3 - Change all passwords (USNH, personal, any accounts logged into during the time of compromise) used on the device (email, Windows, VPN, etc.) from a clean device.
Step 4 - Notify USNH Cybersecurity Operations to monitor for unauthorized access.
System Cleanup
Step 5 - Run antivirus and anti-malware scans (e.g., Windows Defender, Crowdstrike).
Forensic & Reporting
Step 6 - Document the incident: time, actions taken, screen shots if available. Include as much information as possible in the TeamDynamix ticket.
Step 7 - Report to USNH Cybersecurity Operations and possibly legal/compliance if sensitive data was exposed.
Reimage if Necessary
Step 8 - If compromise is confirmed or suspected, wipe and reimage the device.
Further Readings
Windows Computer: Running an On-Demand Scan with Crowdstrike
Need additional help?
If you have questions or need additional help with these topics, please reach out to your Help Desk Team Lead or supervisor for assistance.