Control by Heidi

Ghostrider - 20 Reputation points
2026-08-25T11:24:43.8533333+00:00

Yesterday I received an email invitation to a party by my cousin. It said that to open the invitation I had to click a link. The link gave me a download to a program called ScreenConnect.Clientsetup.exe. I verified that the email was from my cousin and then clicked the link. It said it loaded something but nothing came up. Shortly thereafter I saw a banner come up quickly that said my device is being controlled by Heidi something. I was concerned so had MalwareBytes run a scan on the computer. It didn't find anything. I had MalwareBytes scan the setup program and didn't find anything. I shut down the computer and went to bed. This morning I started my computer and after a couple of minutes the same banner came up - just for a second. I did some research online and the only thing I found was that there's a program called Heidi that's used for transcription by medical people and some corporations. It told me how to check for it but I didn't find what it was talking about. I tried to uninstall it, but there's nothing to be found. My research said that there's nothing inherently wrong with the program and it only controls audio. I am not in the medical or corporate world. I've been retired for 30 years and don't do transcription. I do have EMEET installed for a camera that I've used once or twice for emeets with my doctor, but I've never seen this banner until yesterday. I do have a cadence blood pressure machine, but it's totally separate. It reports my blood pressure readings to Cadence, but doesn't use the computer. Do I have a problem????? The computer seems to be running fine, but I do some banking on it.

Windows for home | Windows 11 | Security and privacy
0 comments No comments

Answer accepted by question author
_AW_ 69,121 Reputation points Volunteer Moderator
2026-08-25T11:50:03.43+00:00

I think your cousin has been hacked. The ScreenConnect client software you installed is a remote admin tool that would have been preconfigured to phone home to an attacker. Everything you do on your computer can be seen by the attacker and they will also have control of the computer.

See if you have a System Restore point prior to the installation and restore your computer.

https://support.microsoft.com/en-US/Windows/Experience/Backup-Recovery/system-restore

OR Point-In-Time restore the computer.

https://support.microsoft.com/en-US/Windows/experience/backup-recovery/point-time-restore-for-windows

Was this answer helpful?

2 people found this answer helpful.

1 additional answer

Sort by: Oldest
  1. AI answer

    2026-08-25T11:25:03.74+00:00

    The behavior described is consistent with a remote-control or scam-related program being launched, not a normal invitation flow. A file named ScreenConnect.Clientsetup.exe is especially concerning because the banner about the device being controlled appeared immediately after it was run and then appeared again after restart.

    Recommended actions:

    1. Disconnect the PC from the internet immediately.
      • Turn off Wi‑Fi or unplug Ethernet.
      • This limits any remote access while checks are performed.
    2. Run Microsoft Defender Offline.
      • Go to Start > Settings > Update & Security > Windows Security > Virus & threat protection.
      • Under Current threats, select Scan options.
      • Select Windows Defender Offline scan and then Scan now.
      • Note: the PC will restart before the scan starts.
    3. After the offline scan completes, run additional scans.
      • In Windows Security > Virus & threat protection > Scan options, run a Quick scan and then a Full scan.
      • Since Malwarebytes was already used, keeping it as a second-opinion scan is reasonable.
    4. Treat the email and download as suspicious even if it appeared to come from a known person.
      • Malicious email can appear to come from a legitimate contact.
      • Do not reopen the attachment, link, or downloaded file.
    5. If the same control banner returns after scans, assume something may still be reinstalling or relaunching on startup.
      • Microsoft documents that recurring detections can happen when a hidden component reinstalls malware after restart.
      • In that case, the offline scan is the key next step.
    6. Because banking is done on this PC, use caution.
      • Do not do banking or enter sensitive information on this device until scans are complete and the control banner no longer appears.
    7. If any remote access was actually granted or suspicious activity continues, back up personal files and consider resetting the PC.
      • Warning: a reset can remove apps and settings, so back up important files first.

    The most important fact here is that a program downloaded from an email link was followed by a “device is being controlled” message. That is not normal and should be treated as a security incident.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.