Secure Your PC After a Microsoft Tech Support Scam Involving UltraViewer
Realizing you have been targeted by a tech support scam can be incredibly stressful, but taking swift, methodical action can cut off the attacker's access and secure your personal information.
Problem Description: Fake Support and Remote Access Infiltrations
Tech support scams often begin with an alarming full-screen browser pop-up disguised as an official Microsoft security alert or an FBI warning. These pop-ups claim your computer is infected or locked and urge you to call a toll-free number. Once on the phone, the fraudulent "technician" uses high-pressure tactics to convince you to install remote access software like UltraViewer. By granting them control, the scammers can steal passwords, access your online banking, install hidden malware, and lock you out of your own system.
Quick Answer for Suspected PC Compromise
Instantly stop communicating with the scammer and disconnect your computer from the internet. Uninstall UltraViewer immediately, run a full Microsoft Defender scan, and use a different, safe device to change all your critical passwords (email, banking, Microsoft).
Likely Causes Behind Fraudulent Support Warnings
- Malicious Advertising (Malvertising): Rogue ads on otherwise legitimate websites can force your browser to open fake security warnings.
- Hijacked Browser Notifications: Accidentally allowing notifications from untrustworthy sites can result in spam pop-ups that mimic system alerts.
- Typo-squatting: Mistyping a popular website URL can redirect you to a malicious landing page engineered to look like official Microsoft support.
- Social Engineering: Scammers use fear and urgency to bypass technical security measures, relying on human panic rather than complex hacking.
Recommended Solution: Step-by-Step PC Recovery Guide
- Sever the Internet Connection: Immediately unplug your Ethernet cable or turn off your computer's Wi-Fi. This instantly cuts off the scammer's remote access via UltraViewer. Do not turn the PC off until the connection is broken.
- Uninstall Remote Software: Navigate to Settings > Apps > Installed Apps (or Control Panel > Programs and Features). Find UltraViewer and any other software you were instructed to download during the call, and click "Uninstall."
- Run a Full System Scan: Open Windows Security, go to Virus & threat protection, click Scan options, and select Microsoft Defender Offline scan. This will restart your PC and scan for deeply embedded malware before Windows fully loads.
- Secure Your Accounts from a Trusted Device: Using your smartphone or a different, uncompromised computer, change the passwords for your Microsoft account, primary email, banking portals, and social media. Enable Two-Factor Authentication (2FA) wherever possible.
- Monitor and Report: Contact your bank's fraud department immediately to report potential compromise and monitor your accounts for unauthorized transactions. Finally, report the incident to authorities and file a report with Microsoft at https://www.microsoft.com/reportascam.
Alternative Solutions for Deep Malware Infections
- Perform a System Restore: If your PC exhibits strange behavior after the scan, use Windows System Restore to revert your system state to a date before the scam occurred. Type "Create a restore point" in the Windows search bar to access this utility.
- Reset Your PC: For absolute peace of mind, navigate to Settings > System > Recovery and choose Reset this PC. Select the "Keep my files" option to reinstall Windows while preserving your personal documents, effectively wiping out hidden malware.
Working with WPS Office: A Secure Offline Document Alternative
If your Microsoft account was compromised during the scam, you may be temporarily locked out of your Microsoft 365 cloud tools while recovering your account. WPS Office serves as an excellent, completely free alternative that allows you to safely keep working. WPS Office lets you create, open, edit, and save Microsoft Office-compatible files (Word, Excel, PowerPoint) locally on your hard drive. By saving documents locally offline, you maintain productivity without relying on cloud servers or an active internet connection while you focus on securing your digital identity.
Prevention Tips for Blocking Future Social Engineering Scams
- Ignore Unsolicited Calls: Microsoft, Apple, and your internet service provider will never call you unprompted to tell you your computer is infected.
- Never Call Pop-up Numbers: Real system error messages do not display phone numbers. If your browser locks up with a warning, press Ctrl + Shift + Esc to open Task Manager and force-close the web browser.
- Deny Remote Access: Never give control of your computer or download remote desktop software (like UltraViewer, TeamViewer, or AnyDesk) at the request of an unknown caller.
- Keep Your Browser Secure: Install a reputable ad-blocker and disable web push notifications for untrusted websites in your browser settings.
FAQs About Remote Access Fraud
Can the scammers access my computer after I restart it?
If you uninstalled the remote access software (UltraViewer) and ran an offline antivirus scan, they cannot regain access. Their connection relies on that specific software running on an active internet connection.
Do I need to buy a new computer after a tech support scam?
No. Your physical hardware is perfectly fine. The issue is purely software-based. By removing the remote access tools, scanning for malware, and resetting Windows if necessary, your computer is safe to use again.
How do I know if they stole my files or passwords?
It is difficult to know exactly what the scammers viewed or transferred while they had remote control. You should assume that any passwords saved in your browser, desktop files, or logged-in accounts were compromised. This is why resetting your passwords from a safe device is the most critical recovery step.




