How to Disable Remote Desktop After a Scam on Windows
Question details
The user needs to completely sever remote access and secure their device and accounts after falling victim to a tech support scam.

- Product
- Windows Remote Desktop
- Device & OS
- not provided
- Scenario
- Recovering from a remote-access scam where an attacker gained control of the computer, potentially installing secondary backdoors or accessing financial information.
- Observed behavior
- Even after built-in Remote Desktop is disabled, attackers might still control the mouse, access browsers, or make fraudulent purchases using stealthy third-party remote tools.
Immediately disconnect your computer from the internet (unplug the Ethernet cable or turn off Wi-Fi) to instantly cut off the scammer's active connection while you perform these security checks.
Disable Remote Desktop and Remove Unauthorized Tools
The most critical step is to turn off built-in remote features and uninstall any third-party remote software the scammer may have installed.
Scammers rarely rely solely on Windows Remote Desktop. They often trick victims into installing legitimate but easily abused third-party remote support applications. You must check for and remove these tools to ensure your system is isolated.
Click the Start button, go to Settings > System > Remote Desktop, and toggle the 'Enable Remote Desktop' switch to the 'Off' position.
Press the Windows Key + R to open the Run dialog, type 'appwiz.cpl', and press Enter to open your installed programs list.
Sort the list by the 'Installed On' date. Look for software installed on the day of the scam (such as AnyDesk, TeamViewer, LogMeIn, or ScreenConnect), right-click them, and select 'Uninstall'.
Open Windows Security (or your preferred antivirus software), navigate to Virus & threat protection, select 'Scan options', and run a 'Full scan' to detect and remove any hidden malware or keyloggers.

Secure Your Accounts from a Safe Device
Because scammers may have compromised your passwords or active browser sessions, you must secure your accounts using a different, uncompromised phone or computer.
Stay Productive and Secure with WPS Office
While securing your computer from remote access scams, you may need a reliable and safe office suite to manage your personal and financial documents. WPS Office is a highly secure, free alternative to Microsoft Office that focuses on local productivity without relying on easily exploited remote-access integrations.
- 1. Visit the Official Website: Go to the official WPS Office website using a secure browser.
- 2. Download the Installer: Click the 'Free Download' button to get the latest, most secure version.
- 3. Install WPS Office: Run the installer and follow the on-screen instructions to safely set up your new office suite.

Frequently Asked Questions
Why is someone still controlling my mouse after I disabled Remote Desktop?
The scammer likely installed a third-party remote access tool (such as AnyDesk, ScreenConnect, or TeamViewer) which operates completely independently of Windows Remote Desktop. You must find and uninstall these specific programs from your Control Panel to stop the unauthorized access.
Can I completely uninstall Windows Remote Desktop Connection?
Windows Remote Desktop Connection (mstsc.exe) is a core component of the Windows operating system and cannot be cleanly uninstalled through standard menus. However, ensuring the 'Enable Remote Desktop' toggle is switched off in System Settings completely blocks incoming connections.
Is it safe to use my computer for banking immediately after a scam?
No. It is not safe to log into banking or financial accounts until you have completely disconnected from the internet, removed all unauthorized remote software, and run a full system anti-malware scan to ensure no hidden keystroke loggers remain on your device.




