Accounts: Remediating Fake Support or Virus Pop-Ups (ETS Internal)

Summary

Here’s a guide for the USNH ET&S Enterprise Help Desk and Collegis when handling a caller who has received fake support or virus pop-up—and what to do if they may have allowed remote access.

Body

Summary

Here’s a guide for the USNH ET&S Enterprise Help Desk and Collegis when handling a caller who has received fake support or virus pop-up - and what to do if they may have allowed remote access.

 

Initial Triage Questions for the Caller

These questions help assess the situation and determine the scope of potential compromise. It is critical for an investigation to capture responses to these questions:

 

Pop-up Details

Q1 - URL which generated pop-up or did it appear while browsing a specific website?

Q2 - What was the URL you were attempting to visit?

Q3 - What did the pop-up say? (e.g., virus alert, Microsoft support, etc.)

Q4 - Did it include a phone number or ask you to call someone?

Q5 - Did it lock your screen or prevent you from closing it?

Q6 - Were you able to get a screen grab?

Q7 - Did you run a virus/security scan? (User or Help Desk/Collegis rep)

Q7a - If yes, what tool was used?

Q7b - What were the results?

 

User Actions

Q8 - Did you call the number or interact with the pop-up?

Q9 - Did you download or install any software?

Q10 - Did you allow remote access (e.g., via TeamViewer, AnyDesk, GoToAssist)?

Q11 - Did you provide any personal or company information?

Q12 - Did you enter any credentials (email, Windows login, etc.)?

Q13 - Did you make any payments or provide credit card info?

 

System Behavior

Q14 - Is your system behaving unusually now (e.g., slow performance, pop-ups, unknown programs)? If YES, immediately disconnect from the network (Wi-Fi or Ethernet).

Q15 - Are you still connected to the remote session? If YES, immediately disconnect from the network (Wi-Fi or Ethernet).

Q16 - Have you rebooted or disconnected from the Internet?

 

Remedial Actions if Remote Access Was Granted

If the user allows a fake support agent to access their system, take these steps immediately:

 

Immediate Containment

Step 1 - If the answer to Q14 and/or Q15 is YES, or you believe there to be an imminent threat to USNH resources or data, or your personal data, then immediately disconnect from the network (Wi-Fi or Ethernet).

Step 2 - Immediately contact the USNH Cybersecurity Operations Team for quarantine. Message any of the following CyberOps Analysts:

  • William Sames
  • Carl Nickerson
  • Matthew Reed
  • Chris Garcia
  • Joshua Annis
  • Joe Gray

 

Credential Security

Step 3 - Change all passwords (USNH, personal, any accounts logged into during the time of compromise) used on the device (email, Windows, VPN, etc.) from a clean device.

Step 4 - Notify USNH Cybersecurity Operations to monitor for unauthorized access.

 

System Cleanup

Step 5 - Run antivirus and anti-malware scans (e.g., Windows Defender, Crowdstrike).

 

Forensic & Reporting

Step 6 - Document the incident: time, actions taken, screen shots if available.  Include as much information as possible in the TeamDynamix ticket.

Step 7 - Report to USNH Cybersecurity Operations and possibly legal/compliance if sensitive data was exposed.

 

Reimage if Necessary

Step 8 - If compromise is confirmed or suspected, wipe and reimage the device.

 

Further Readings

Windows Computer: Running an On-Demand Scan with Crowdstrike

 

Need additional help?

If you have questions or need additional help with these topics, please reach out to your Help Desk Team Lead or supervisor for assistance.

Details

Details

Article ID: 5378
Created
Fri 10/24/25 11:10 AM
Modified
Wed 11/5/25 10:18 AM
Applicable Institution(s):
Keene State College (KSC)
Plymouth State University (PSU)
University of New Hampshire (UNH)
USNH System Office