Palm Desert Geeks

Virus and scams

Virus and scam removal in the Coachella Valley

Palm Desert Geeks removes viruses, malware and scam software from PCs and Macs across the Coachella Valley, and helps you recover after a fake pop-up or a phone scammer got into your computer. Bring it to 77564 Country Club Dr. Bldg. A, Suite 220, Palm Desert, or call 760-278-9676 before you do anything else.

Call 760-278-9676 Book on pdgeeks.com

Is it a virus, a scam, or both

These are two different problems, and they get fixed differently. A virus or other malware is software running on your computer that you didn't ask for. A scam is a person trying to talk you into paying, or into letting them in. Plenty of the calls we get turn out to be the second kind, and no scan fixes that.

Signs of a scam

  • A full-screen warning says your computer is infected or locked and gives a phone number to call.
  • A voice or alarm plays from the speakers and the page won't close.
  • Someone phones you claiming to be from Microsoft, Apple, your internet provider or your bank's fraud department.
  • An email says you were charged for an antivirus renewal you never ordered, with a number to call for a refund.

Signs of real malware

  • Your browser's home page or search engine changed and won't change back.
  • Ads and notifications appear in the corner of the screen even with the browser closed.
  • Programs you don't remember installing, often called cleaners, optimizers or driver updaters.
  • Your antivirus is switched off and won't switch back on.
  • Friends say they're getting odd emails or messages from you.
  • The fan runs hard while the computer sits idle.

The pop-up with a phone number

That warning is a web page. It's an ad or a hijacked link dressed up to look like Windows or macOS, and it isn't coming from your computer. Microsoft and Apple don't put phone numbers in security warnings. On its own, the page hasn't infected anything. The damage starts when someone calls the number.

Here's what you can safely do yourself.

  1. Don't call the number, and don't click anything inside the warning, including the X it shows you.
  2. Close the browser from outside the page. On Windows, press Ctrl, Shift and Esc together, select your browser in Task Manager and choose End task. On a Mac, press Command, Option and Escape, select the browser and click Force Quit.
  3. If the keyboard won't respond, hold the power button down until the computer shuts off. That does no harm in this situation.
  4. When you reopen the browser, say no if it offers to restore your previous pages.
  5. If the same warnings come back as small notifications, a website has permission to send them. Open your browser's settings, find Notifications under site settings and remove any site you don't recognize.

If you closed it and never called, you're almost certainly fine. If it returns every day, something is feeding it, and that's worth a look.

Tech-support phone scams

The phone version works the same way, minus the pop-up. A caller says your computer is sending errors, or a refund is owed, or your account was used fraudulently. Then they ask you to install a remote access program so they can "fix" it. Once they're connected, they show you ordinary system logs and call them proof of hackers, or they open your bank's website and pretend to send a refund that's too large.

A few rules cover nearly every version of this. Nobody legitimate phones you about a problem on your computer. Nobody legitimate takes payment in gift cards, wire transfers, cryptocurrency or cash in a box. And caller ID proves nothing, because the number on your screen can be faked. Hang up, then call the company yourself using the number printed on your card or statement.

The first hour after you let someone in

This happens to careful people. The scripts are practiced and the callers are patient. What matters is what you do next, in this order.

  1. Cut the connection. Unplug the network cable or turn off Wi-Fi, then shut the computer down. If they're still on the phone, hang up. Don't answer when they call back.
  2. Call your bank and card companies. Use the number on the back of the card. Tell them a stranger had remote access to your computer and whether you were signed in to banking at the time. Ask them to watch for or stop any transfers, and ask what they recommend for the cards.
  3. Change passwords from a clean device. Use a phone, tablet or another computer the caller never touched. Start with your email, because whoever controls your email can reset everything else. Then banking, then your Apple, Google or Microsoft account. Turn on two-step sign-in where it's offered.
  4. Write down what happened. The phone number, the name they gave, what they had you install, what they looked at and anything you paid. Your bank will ask, and so will we.
  5. Leave the computer off. Don't use it for banking, email or shopping until it's been checked. Scammers often leave a remote tool set to start with the computer.
  6. Report it. If you paid with gift cards, call the card issuer right away. You can also report the scam to the Federal Trade Commission, and to your local police if money was taken.

Be ready for a second wave. People who've been scammed often get a follow-up call from a "recovery service" offering to get the money back for a fee. That's the same crowd.

Real cleanup versus running a scan

A scan answers one question: does this program recognize anything on the list it carries. That's useful, and it isn't the whole job. Remote access tools are legitimate software, so a scanner will often leave one alone. Browser hijackers hide in extensions, notification permissions and sync settings. Some malware reinstalls itself from a scheduled task minutes after it's removed.

Here's what we do when a computer comes in for cleanup.

  1. We ask what happened and when, then check the computer off the network so nothing can phone home while we work.
  2. We look for remote access tools and remove every one you didn't knowingly install.
  3. We review what starts with the computer: startup items, scheduled tasks and services on Windows, login items and background agents on a Mac.
  4. We check for user accounts that shouldn't exist and for settings the intruder changed, such as a new password or a lock screen you didn't set.
  5. We scan with more than one tool, because no single scanner catches everything.
  6. We reset the browsers: extensions, search engine, home page, notification permissions and saved sync data.
  7. We check network settings a hijacker likes to change, such as the proxy and DNS entries.
  8. We bring Windows or macOS and your browsers up to date, confirm your security software is running, and tell you what we found.

You get a quote before the work starts. Bring the computer into the shop and the diagnostic is free. If your email was part of it, we can also check for forwarding rules a scammer added, which is covered on our Microsoft 365 and email page. Macs aren't immune to any of this, and the same process applies. See Mac support for the rest of what we do on Apple machines.

Clean it or wipe it

Most adware and browser hijacks clean up fine, and the computer goes home with everything in place. Other cases call for erasing the drive and reinstalling the system from scratch. We'll recommend that when the infection reaches deep into the system, when a stranger had long unsupervised access, when ransomware is involved, or when the computer is used for banking and you'd rather be certain than probably fine.

A wipe isn't the disaster it sounds like. We copy your documents and photos off first, check them, reinstall, and put them back. If files went missing or got encrypted along the way, our data recovery page explains the options.

An infection is almost never a reason to buy a new computer. Malware lives in software, and the hardware underneath is fine. The exception is a machine too old to run a supported version of Windows or macOS. It can't get security updates, so it will get infected again, and we'll tell you that honestly. For an office, one infected computer is a warning about the rest of them, and our cybersecurity and backup page covers what to put in place.

Three ways to get help

  • Bring it to the shop

    We're at 77564 Country Club Dr. Bldg. A, Suite 220 in Palm Desert. Walk-ins are welcome, but call ahead so a technician is ready for you. Diagnostics are free when you bring the device in, and you get a quote before any work starts.

  • We come to you

    For networks, Wi-Fi, printers, offices and anything that doesn't travel well, we work on-site at your home or business. The free diagnostic applies to devices brought into the shop, not to on-site visits.

  • Remote support

    Software, email and account problems can often be handled over a secure remote connection. Call first and we'll tell you whether remote help fits the problem.

Where we do this

We handle virus and scam removal for homes and businesses in Rancho Mirage, Palm Desert, Indian Wells, La Quinta and Indio. Each city guide covers what's particular to that city.

Questions people ask

A pop-up says my computer is infected and gives a number to call. Is it real?

No. It's a web page built to look like a Windows or Apple warning. Real security alerts don't include a phone number. Don't call and don't click inside it. Close the browser with Task Manager on Windows or Force Quit on a Mac, or hold the power button until the computer turns off. If you never called, you're very likely fine.

I let someone remote into my computer. What do I do right now?

Disconnect the computer from the internet and shut it down. Call your bank using the number on your card and tell them a stranger had access. Change your email and banking passwords from a different device, such as your phone. Then leave the computer off and call us at 760-278-9676 so we can check it before you use it again.

I already ran an antivirus scan and it found nothing. Am I safe?

Not necessarily. Scanners look for known malware. The remote access programs scammers use are legitimate software, so many scanners ignore them. Browser hijacks also hide in extensions and notification settings that a scan doesn't touch. If a stranger was connected to your computer, have it checked by hand, even if the scan came back clean.

Can you remove a virus by remote support?

Sometimes. Remote support over a secure connection works for browser hijacks, notification spam and unwanted programs. If someone else may still have access to your computer, or the infection looks serious, we'd rather have the machine in the shop and off your network. Call us and we'll tell you which makes sense for your situation.

Do Macs get viruses and scams too?

Yes. Macs get adware, browser hijackers and unwanted "cleaner" apps, and the fake warning pop-ups and phone scams work exactly the same on a Mac as on a PC. The scam targets the person, and the computer is just the way in. We clean up both Macs and Windows PCs.

Do I need to buy a new computer after a virus?

Almost never. Malware is a software problem. In serious cases we erase the drive and reinstall the system after saving your files, and the same computer comes back clean. The one exception is a computer too old to get security updates, where replacing it is the safer choice. We'll tell you which case you're in.

Talk to a person about it

Call, and tell us what's going on. You'll get a straight answer and a quote before any work starts.

Call 760-278-9676 Book on pdgeeks.com Directions to the shop

Palm Desert Geeks · 77564 Country Club Dr. Bldg. A, Suite 220, Palm Desert, CA 92211

Call 760-278-9676Directions