Call Phillip · 0402 596 817

Remote access scam help

What to Do After a Scammer Has Accessed Your Computer

If someone has talked you into installing remote access software such as UltraViewer, AnyDesk, TeamViewer, RustDesk or something similar, treat the computer as potentially unsafe until it has been checked.

These programs can be legitimate support tools. They become suspicious when installed after an unexpected call, pop-up, email or message.

Need help near Chatswood, Artarmon or the Sydney North Shore? IT Neighbour can check the computer, remove unwanted software, reinstall Windows if needed, and set it up to be safer in future.

Protect accounts and money

Immediate steps if the scammer may still have access

Work through these steps calmly. If you are helping a family member, stay with them and write down what has already happened.

  • Disconnect the computer from the internet if the scammer may still be connected. Turn off Wi-Fi, unplug Ethernet, or shut the computer down.
  • Stop speaking with the caller or person giving instructions. Do not call back using a number they supplied.
  • Do not use sensitive accounts on that computer. Avoid banking, email, PayPal, myGov and shopping accounts until the computer has been checked.
  • From a different trusted device, change important passwords. Start with email, Microsoft, Google, Apple and financial accounts.
  • Contact the bank immediately if banking, card details or online banking were visible. Use the number on the back of the card or the bank's official website.
  • Call the bank's fraud department urgently if money has been transferred.
  • Keep notes. Record the time, phone number, software installed, bank details shown, payments made and anything the scammer asked the person to do.

If money or banking details were involved

Contact the bank before doing further computer cleanup. The bank can protect accounts, cards and payments; computer support cannot reverse a bank transfer.

What may have been installed

Remote access programs scammers often ask people to install

UltraViewer AnyDesk TeamViewer RustDesk Supremo Zoho Assist Chrome Remote Desktop RemotePC LogMeIn or GoTo-style tools

The program itself is not always the problem

Many remote access programs are legitimate support tools. The concern is when one is installed because of an unexpected phone call, pop-up warning, email, text message, or someone pretending to be Microsoft, Telstra, the NBN, a bank, PayPal, Amazon or another trusted company.

For a trusted family member or helper

Basic checks a family member or helper can do

These Windows 11 checks can find common problems. If you are unsure about an item, do not delete it at random. Write down its name or take a photo and ask someone you trust.

Check installed apps

Also check Control Panel > Programs and Features.

Look for remote access tools, unknown VPNs, unfamiliar security tools, browser toolbars and anything installed around the time of the scam.

Check startup apps

Disable anything clearly suspicious or unnecessary. If the name is unfamiliar, check it before disabling it.

Check browser extensions

Microsoft Edge:
Three dots > Extensions > Manage extensions

Google Chrome:
Three dots > Extensions > Manage extensions

Remove unknown search tools, coupon tools, fake security tools, remote access helpers or anything the user does not recognise.

Check browser notifications

Edge: enter edge://settings/content/notifications in the address bar.

Chrome: enter chrome://settings/content/notifications.

Remove or block unknown websites. Scam sites often use notifications to show fake virus warnings later.

Check Remote Desktop

Make sure Remote Desktop is Off unless it is specifically needed and managed by someone you trust.

Run Windows Security checks

Run a full scan. Then open App & browser control > Reputation-based protection settings and review the available protection options.

A clean scan is useful, but it is not a guarantee

Security software can find many known threats. It cannot prove that nothing was changed or viewed while a scammer had full remote control of the computer.

Choosing the safer recovery path

When a fresh Windows reinstall is the safer option

If a scammer had remote control, simply uninstalling the remote access program may not be enough. They may have changed settings, installed other tools, added browser extensions, saved passwords or seen private information.

A fresh reinstall may be recommended if:

  • Remote access software was installed and used
  • Banking or email was opened during the session
  • The person is not sure what the scammer did
  • Multiple suspicious programs are present
  • The computer is behaving strangely
  • The user is vulnerable and likely to be targeted again

Before reinstalling, confirm:

  • Important files are backed up
  • OneDrive, Documents, Desktop, Pictures and Downloads have been checked
  • Microsoft account and Microsoft 365 or Office logins are known
  • Special programs, licence keys, printer and email setup have been noted
  • Important passwords have been changed from a different trusted device

After cleanup

How to make the computer harder for scammers to misuse again

The right setup depends on the person using the computer. For someone who is regularly targeted, simple restrictions and a familiar browser are often more helpful than complicated security software.

  • Reinstall Windows 11 fresh if the remote access incident was serious.
  • Reinstall Microsoft Office or Microsoft 365.
  • Reconnect OneDrive and confirm important folders are syncing.
  • Change the Microsoft account password.
  • Enable MFA or two-step verification where practical.
  • Use Microsoft Edge as the main browser for vulnerable users.
  • Turn on Microsoft Defender SmartScreen.
  • Turn on potentially unwanted app blocking.
  • Turn on Edge scam or scareware protection if it is available.
  • Install Malwarebytes Browser Guard in Edge.
  • Use Secure DNS such as Quad9: https://dns.quad9.net/dns-query
  • Block or regularly review browser notification permissions.
  • Remove remote access programs that are not genuinely needed.
  • Avoid saving banking passwords in the browser.
  • Keep Windows Update, the browser and Office updates enabled.

A strong practical safeguard

Use a Standard User account for daily use

For people who are likely to follow scammer instructions, one of the strongest protections is to make their normal Windows account a Standard User and keep a separate Administrator account.

If a scammer tells them to install UltraViewer, AnyDesk, TeamViewer or another remote control program, Windows should ask for the administrator password. If neither the scammer nor the everyday user knows that password, installing the program becomes much harder.

Friendly local support

How IT Neighbour can help

I provide local computer support in Chatswood, Artarmon and nearby Sydney North Shore suburbs. If someone has accessed your computer remotely, I can help check it and set it up to be safer.

  • Check for remote access software
  • Remove unwanted or suspicious apps
  • Check browser extensions and notifications
  • Run security scans
  • Reinstall Windows 11 if needed, then restore familiar settings, programs and everyday functions wherever possible
  • Reinstall Microsoft Office or Microsoft 365
  • Reconnect OneDrive
  • Set up Microsoft Edge with stronger scam protection
  • Install Malwarebytes Browser Guard
  • Set up Secure DNS filtering
  • Create a separate administrator account
  • Change the normal account to a Standard User
  • Help change passwords and secure accounts
  • Set up printers, email and basic apps again after a reinstall

Not sure whether the computer needs a check or a full reinstall?

Call Phillip for calm, practical advice and local help around Chatswood, Artarmon and the North Shore.

Common questions

Scam computer help FAQ

Is uninstalling UltraViewer or AnyDesk enough?

Sometimes, but not always. If a scammer had remote control, they may have made other changes or seen private information. A proper check or fresh Windows reinstall may be safer.

Should I change my passwords?

Yes, especially email, Microsoft, Google, Apple, banking and shopping accounts. Change them from a different trusted device if possible.

Should I contact my bank?

Yes, if banking pages, card details or online banking were open while the scammer had access. Use the number on the back of your card or the bank's official website.

Can a Standard User account still use the computer normally?

Yes. It can browse the web, use email, Office, OneDrive and printers. It just cannot install software or make major system changes without the administrator password.

Are remote access programs always bad?

No. They are legitimate tools when used with someone you trust. They are risky when installed because of an unexpected call, pop-up, email or message.

Important information

This page provides general computer safety information, not legal, banking or cyber-forensic advice. If money has been transferred or banking details were exposed, contact your bank immediately. If identity documents or personal information were exposed, consider contacting IDCARE or the relevant government service.

You can also report cybercrime through ReportCyber or report the scam to Scamwatch. A Scamwatch report is not an official police report.

Need local help after a remote access scam?

Call Phillip for practical computer help in Chatswood, Artarmon and nearby North Shore suburbs.

or email support@itneighbour.com.au