If anyone connected via AnyDesk, TeamViewer, Quick Assist, or similar, banking on that device is unsafe until it is cleaned.
What to do
- List every remote-access app installed in the last 14 days (AnyDesk, TeamViewer, Quick Assist, Zoho Assist, Chrome Remote Desktop)
- Check connection logs in those apps for unknown session IDs and timestamps
- Look for unfamiliar admin or user accounts on the device
- Check browser-saved passwords and crypto wallets — assume they have been read
Was this guide helpful?
Know someone who needs this? Send them the guide.
JD
Written by
Jordan DicksonFounder, CyberSecurityGuides
Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.
Reviewed by CSG Security Engineers