What is actually still on it
Look at C:\Users first: every profile folder is somebody's workspace, and a used machine often keeps one or two, complete with browser profiles and their saved logins. Check Credential Manager (Control Panel → User Accounts → Credential Manager) for saved network and website credentials, and Settings → Accounts → Family & other users for accounts you did not create. Wi-Fi passwords, license keys stored in the registry, personal documents in the old profile — all of it survives the handover unless someone removed it.
Then look for the tools of remote generosity: TeamViewer, AnyDesk, RustDesk, LogMeIn in the installed-apps list, and whether Remote Desktop is enabled (Settings → System → Remote Desktop). A leftover remote tool with saved unattended access is the single worst thing to find on a bought machine, because the previous owner — or anyone who bought their credentials — can still log in.
- User profiles under C:\Users that are not yours
- Browser profiles with saved passwords and sync accounts still signed in
- Credential Manager entries: network shares, websites, saved certificates
- Remote-access tools and an enabled Remote Desktop
- Unknown accounts in Settings → Accounts, including hidden administrators (run net user in a Command Prompt)
- Scheduled tasks and startup entries whose names do not match any installed app
Check for the ugly possibilities
Malware on a sold machine is rarer than the forums imply, but a keylogger on a PC that will hold your bank login is not a risk to accept on vibes. Run a full Microsoft Defender scan first, then an offline scan (Windows Security → Virus & threat protection → Scan options → Microsoft Defender Offline scan), which restarts the machine and scans before Windows loads — that is where persistent malware gets caught. Open the hosts file (C:\Windows\System32\drivers\etc\hosts) and check it has no entries redirecting your bank somewhere else; look at Defender's protection history for what it has already fought; and check the firmware for a supervisor password and remote-management features like Computrace/Absolute, which survive every reinstall.
The move that beats all checkups
If the machine came with Windows installed and you did not pay for that install to survive, the clean answer is a clean start: Settings → System → Recovery → Reset this PC → Remove everything, with the clean-the-drive option if you are the paranoid type. That erases profiles, credentials, remote tools and every poisoned custom thing in one stroke; you get a fresh account and a stock Windows. If you keep the existing install anyway — some OEM machines carry licensed software worth preserving — do every check above, and then still delete the old profiles and their browser data. Activation survives the reset on OEM machines because the license lives in the firmware; retail licenses may ask you to sign in with the Microsoft account that owns them.
Questions and Answers
Is it safe to use a secondhand PC without reinstalling Windows?
It is a calculated risk. If you skip the reinstall, at minimum run an offline Defender scan, remove old profiles, uninstall remote tools and change every password you plan to type on that machine. A reset or clean install removes the question entirely.
Will I lose my Windows license if I reset a used PC?
No. OEM licenses live in the firmware and re-activate automatically after a reset. Retail licenses are tied to a Microsoft account and re-activate once you sign in with the account that owns them.
Know what is included before you buy.
The one-time 30-minute trial covers core tools. PRO-labelled features stay locked until a paid license is activated.
Read next
Write to us: [email protected]