How to tell if a scammer is still in your computer
You watched them use one program — but these scams almost always leave more than one way back in. Here's how to know if the door is still open.
The single most important thing to understand: the remote-access tool you watched the scammer use is usually not the only one. These operators layer in several — so that removing the obvious one leaves them another way in. That's why "it seems fine now" isn't the same as "they're gone."
Signs a scammer may still have access
- A new icon or phone number on the desktop left "in case you have problems." That's a deliberate re-contact hook — a strong sign this was a scam and that they intend to return.
- Remote programs you didn't install — names like AnyDesk, TeamViewer, UltraViewer, Supremo, LogMeIn, or "Chrome Remote Desktop."
- Your antivirus is off or was uninstalled. Scammers frequently disable protection so their tools aren't flagged.
- The cursor moves on its own, windows open by themselves, or you see a "your screen is being shared" banner.
- New user accounts on the computer, or your account settings changed.
Why "I restarted it" isn't enough
Most of these tools are set to start automatically and accept connections without anyone clicking "allow." So a restart — or even shutting down overnight — doesn't help: the moment the computer is back online, the tool can reconnect. Being sure requires finding and removing every remote tool, or wiping and reinstalling the computer.
How to check (and its limits)
You can look through installed programs, running services, and startup entries for the tools above. The catch: scammers rename things, use portable versions that don't appear in the normal list, and turn on "unattended access" settings that are easy to miss. A careful person can find the obvious ones; being certain nothing was left behind is exactly what a forensic sweep is for.
A full analysis finds every remote-access tool a scammer left, confirms whether any are still active, and locks out the callback — flat pricing, no fear tactics.
See how it worksFAQ
Does disconnecting from the internet remove the scammer?
It instantly blocks active control, but doesn't remove the tools — reconnect and they can work again. Disconnect first, then remove every tool (or wipe the machine).
Can they get back in after I turn the computer off?
If a tool is set to start automatically, it can reconnect as soon as the computer is online again. Removal or a wipe is what makes it certain.