Unexpected remote-control software
The scammer may have installed an application or browser extension.
A calm recovery plan after a remote-access scam involving a senior in Epping or Wollert: stop access, protect money, secure accounts and preserve evidence.

After a remote-access scam, end the call, disconnect the affected device from the internet when control may still be active, contact the bank immediately if money or banking details were exposed, and change important account passwords from a trusted device. Preserve messages, receipts and call details, then arrange a careful device and account review.
When banking, cards or transfers are involved, call the bank using a number sourced independently. Do not wait for a computer appointment before reporting the financial risk. If the scammer is still communicating, stop contact.
The same symptom can have more than one cause. These patterns help organise the next question; they do not replace hands-on diagnosis.
The scammer may have installed an application or browser extension.
Account and financial exposure may extend beyond the computer itself.
Continued contact is a strong warning sign. Do not negotiate or follow recovery offers.
Use a calm timeline and avoid blame. Anyone can be targeted.
Recovery should separate four areas: money, accounts, identity and the device. A device scan alone does not secure an exposed email account or reverse a transfer. The support plan may include removing remote-access software, checking persistence, updating the device, reviewing email forwarding and recovery settings, changing passwords from a trusted device and documenting further steps.
Some situations can be handled with account security and a device review. A reinstall may be considered when the device state cannot be trusted, but data should be backed up carefully first. Financial institutions, Scamwatch, ReportCyber or identity-support services may also be needed.
Organise what happened and the urgent actions without entering passwords, banking codes or identity documents.
These external references support the safety boundaries in this guide. Device-specific instructions can still vary by manufacturer and model.
If the scammer may still have control, disconnect it from the internet. Shut it down if that can be done safely, then use a separate trusted device for banking and password changes.
Secure the primary email account first because it can reset other accounts. Use a trusted device and enable multi-factor authentication where available.
Yes when banking, card details, transfers or online banking were exposed. The bank can advise on protective steps.
No single scan proves that every change has been removed. Review remote-access software, accounts, updates and the wider incident.
Preserve useful evidence first, including screenshots, numbers, receipts and dates. Then report and block the contact.
They can help, but account owners should understand and authorise actions where possible. Keep a simple written record of what was changed.
Prepared by: Your IT & Tech Mates content team
Technically reviewed:
Last reviewed:
Review method: Checked against current service boundaries, customer privacy rules, the Local Repair Evidence Standard and relevant official safety guidance.
How evidence and examples are handled ยท How devices and data are handled
Send the device or support goal, model where known, symptoms and clear photos. A technician can review the information before any paid work starts.