Have a client that had significant funds taken from accounts last week. They pinpointed it to one computer that it had to be related to. I think part of it was access to a Google account but not 100%. They reported that after opening the locked screen and logging in that a Teamviewer Quick support box was open and the text was all Chinese. I was able to locate Teamviewer as a series of folders hidden in USER\appdata\Temp. In the connection_incoming.txt I see a connection from last week and then 4 today. They DO NOT USE Teamviewer on that machine at all. However, someone is maliciously using this to gain access. I have the logs and screenshots. What help can TV provide us regarding how to assure they don't just reinstall and use it again?
I deleted the folder entirely and after reboot confirmed that the one DLL left was removed as well.
What next?