
Forgotten remote-support software can leave a computer reachable long after the support call, contractor, or IT provider is gone. The program may be completely legitimate—and still become an unnecessary path into business files, email, accounting data, cameras, or saved browser sessions if nobody owns, updates, or monitors it.
The problem in one sentence
If you cannot name who is allowed to connect remotely, which tool they use, why it is installed, and when that access should end, you do not have controlled remote support—you have an unknown access path.
Why this can become expensive
Remote monitoring and management (RMM) and remote-desktop tools are normal parts of professional IT support. They let an authorized technician maintain systems without driving to the office. The same capability is useful to criminals when a tool is installed through a scam, an old technician account remains active, or a provider’s credentials are compromised.
In its advisory on malicious use of RMM software, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), with the NSA and MS-ISAC, warned that criminals have used legitimate tools in refund scams and as backdoors. CISA notes that portable versions may run without a full installation or administrator rights, and legitimate RMM activity may not trigger antivirus alerts. CISA specifically recommends auditing remote-access tools, reviewing execution logs, and controlling which RMM programs are allowed.
- Home cost: stolen banking or shopping sessions, identity theft, fraudulent transfers, or paid “support” that creates a second problem.
- Business cost: exposed customer data, ransomware, invoice fraud, downtime, emergency incident response, and uncertainty about what an intruder accessed.
- Operational cost: removing the wrong tool can also lock out your current IT provider or break monitoring and backups. That is why this should be an ownership audit—not a blind uninstall spree.
Who should run this audit?
You are likely affected if…
- A technician, software vendor, camera installer, bookkeeper, or family helper has ever controlled the computer remotely.
- Your business changed IT providers, merged offices, inherited computers, or bought a used PC.
- You see unfamiliar “support,” “assist,” “control,” “viewer,” “agent,” or “remote” programs.
- A caller or pop-up once instructed you to download a tool so they could “fix” an account, refund, virus, or subscription problem.
You may be lower risk if…
- You can identify the one approved support product, its owner, the authorized technician accounts, and the devices enrolled.
- Unattended access is disabled unless there is a documented need.
- The account uses multifactor authentication, access logs are reviewed, and old technicians and devices are removed promptly.
- Your inventory was checked recently. “I do not see an icon” is not proof; some agents run in the background.
First: decide whether this is an audit or an incident
Stop and treat it as a possible incident if…
- The mouse moves by itself, a chat box appears unexpectedly, a remote-session banner is active, or an unknown person is connected now.
- You were told to log in to a bank, buy gift cards, move money, read back a security code, or hide the call from someone else.
- Files are being renamed or encrypted, security tools are disabled, or accounts are changing.
Disconnect the computer from Wi-Fi or unplug its Ethernet cable, stop using it, and call a trusted IT professional through a number you already know. Do not continue banking from that device. Do not let the caller “clean up.” Avoid deleting files or uninstalling tools before evidence and logs are preserved. If files appear encrypted, follow our first-15-minutes ransomware checklist.
The 30-minute remote-support software audit
Step 1: Write down what is authorized before touching anything
Make a short table with one row per computer: device name, approved support company, product name, account owner, whether unattended access is allowed, business reason, and review/end date. Ask your current provider for its exact product and publisher name. A vague answer such as “we use remote access” is not enough.
For a business, also list software vendors that support point-of-sale systems, accounting programs, practice-management software, security cameras, phones, and line-of-business equipment. Those vendors may use a different support tool from your main IT company.
Step 2: Check installed apps on Windows
- Open Start → Settings → Apps → Installed apps.
- Sort by install date when available, then scan for support, remote-control, viewer, host, agent, assist, or management software you cannot explain.
- Also open Task Manager → Startup apps and note unfamiliar support-related items. Do not disable business software solely because its name is unfamiliar.
- Take screenshots or photos of questionable entries, including publisher and version, before changing them.
Microsoft’s official removal path is Settings → Apps → Installed apps → More → Uninstall; Control Panel → Programs and Features is another path for traditional desktop programs. Do not uninstall yet if you have not confirmed ownership.
Step 3: Check Applications and background access on a Mac
- Open Finder → Applications and look for remote-support or management software you cannot identify.
- Open System Settings → General → Login Items & Extensions. Review items that open at login and items allowed to run in the background.
- In System Settings → Privacy & Security, review Screen & System Audio Recording and Accessibility permissions. Remote-control tools often need these permissions to see or control the Mac.
- Record the app name and publisher before removal. Apple notes that some apps include their own uninstaller, and that deleting an app does not cancel a related subscription.
Step 4: Remember that “not installed” does not mean “never ran”
CISA warns that portable RMM executables can run from a download without a normal installation. Review Downloads, Desktop, and other locations where support files were saved. Look for remote-support files that arrived around a suspicious call or email. On a managed business network, your IT provider should review endpoint and security logs for portable RMM execution rather than relying only on the installed-app list.
Do not open an unknown file to see what it does. Record its name and location, then let a trusted technician or your security software examine it.
Step 5: Check the provider’s web console and technician accounts
Uninstalling a local agent is only half the job. In the approved product’s administrative console, confirm:
- Every enrolled device still belongs to you.
- Every technician or vendor account is current and individually assigned—not a shared login.
- Multifactor authentication is required, especially for administrators and remote access.
- Old sessions, trusted devices, API tokens, and unattended-access passwords are revoked.
- Connection logs are retained and can answer who connected, to which computer, and when.
If a technician or employee has left, pair this audit with our same-day offboarding checklist. That article focuses on people and accounts; this one focuses on the remote-control software, devices, consoles, and lingering access paths they may leave behind.
Step 6: Remove access in the safest order
- Confirm the current owner. Make sure the tool is not protecting backups, monitoring, patching, or an active support agreement.
- Preserve evidence if anything is suspicious. Save screenshots, file names, timestamps, and relevant connection logs.
- Revoke console access first. Disable the old technician, device, unattended-access credential, token, or session through the authorized admin console.
- Change exposed credentials. If an unknown party had access, use a known-clean device to change important passwords and enable MFA. Begin with email and financial accounts.
- Use the publisher’s documented uninstaller. On Windows, use Installed apps or Programs and Features. On Mac, use the vendor uninstaller when provided; otherwise follow Apple’s app-removal process.
- Restart and verify. Confirm the program no longer starts, the old device no longer checks in to the console, and your approved support method still works.
Good practice versus risky practice
Phone readers: swipe the table left if all columns are not visible.
| Good practice | Risky practice |
|---|---|
| One approved remote-support platform with a named owner | Several tools installed “just in case” with no inventory |
| Individual technician accounts with MFA | A shared vendor password or permanent unattended code |
| Access expires when the job or contract ends | Old providers remain enrolled indefinitely |
| Connection logs are reviewed and retained | Nobody can say who connected or when |
| Users verify support requests through a known number | Users install a tool because a pop-up or caller says to |
| Portable tools are controlled and logged | Only the installed-app list is checked |
Three realistic examples
Home computer after a fake refund call
A caller convinced the owner to run a portable remote-control file, then asked them to open online banking. The file does not appear under Installed apps. This is an incident: disconnect, stop using the device, preserve the download and timeline, and secure financial and email accounts from a clean device.
Small business changes IT providers
The new provider installs its agent, but the old provider’s agent and technician accounts remain. The business should reconcile every computer in both consoles, revoke the old provider’s access, export the relevant logs, remove the old agent, and verify monitoring and backups under the new provider.
One-time software-vendor support
An accounting vendor needed a supervised session six months ago. If the product was only needed for that session, leaving unattended access enabled creates needless exposure. Confirm with the vendor, remove or disable the tool, and require a fresh verified support session next time.
How to keep the problem from returning
- Allow one approved remote-support method whenever practical; document exceptions.
- Review the inventory quarterly and whenever an employee, contractor, or IT provider leaves.
- Require a ticket or scheduled appointment before remote access, then verify surprise requests using a phone number or portal you already trust. See our known-number callback guide.
- Use individual accounts, least privilege, MFA, short session timeouts, and access logs.
- Teach users that a familiar logo does not prove a remote session is safe; legitimate software can be misused.
- For managed businesses, use application controls or allowlisting so unapproved portable RMM tools cannot simply run.
Frequently asked questions
Is all remote-support software dangerous?
No. It is valuable when the software is approved, patched, monitored, and tied to authorized individual accounts. The danger is unknown, unmanaged, excessive, or scam-installed access.
Should I uninstall every remote tool I find?
No. First identify the owner and business purpose. Removing a legitimate management agent can interrupt support, patching, monitoring, or backups. If you cannot identify it, document it and ask a trusted technician before opening or deleting anything.
Does antivirus catch unauthorized remote access?
Not always. CISA notes that legitimate RMM software generally may not trigger antivirus or antimalware defenses, and portable tools may run without a normal installation. Inventory, logging, application controls, and user verification are still necessary.
What if I used remote support once but do not see an installed program?
The session may have used a portable or temporary client. Check Downloads and the original support records. If the session was suspicious, do not reopen the file—preserve it and seek trusted help.
What should I ask an IT provider?
Ask for the exact product and publisher, device inventory, technician roster, MFA requirement, unattended-access policy, log retention period, offboarding process, and how emergency access is approved.
Official guidance and sources
- CISA/NSA/MS-ISAC: Protecting Against Malicious Use of Remote Monitoring and Management Software—threat details and recommendations to audit tools, review logs, and control RMM execution.
- CISA: Guide to Securing Remote Access Software—defensive guidance for organizations using remote-support technology.
- CISA Cyber Essentials—inventory connections and accounts, and prioritize MFA for administrative and remote access.
- Microsoft Support: Uninstall or remove apps and programs in Windows.
- Apple Support: Delete or uninstall apps on Mac and manage login and background items.
- NIST SP 800-46 Rev. 2: Guide to Enterprise Telework, Remote Access, and BYOD Security—security planning for remote access used by employees, contractors, partners, and vendors.
Your next action
Set a 30-minute timer today. Inventory every remote-support tool on one important computer, name the person or company that owns it, and assign an end date. If you find unknown access—or want a second set of eyes—contact The IT Guys through our verified Contact Us page or review our small-business IT services for Port Saint Lucie, Jensen Beach, Fort Pierce, and Vero Beach.
