Results 1 to 13 of 13

Thread: Possible teamviewer breach

  1. #1
    Senior Member

    Join Date
    Mar 2008
    Posts
    1,265
    Thanks
    139
    Thanked 643 Times in 368 Posts
    Rep Power
    455
    Reputation
    10815

    Default Possible teamviewer breach

    If you have teamviewer on your PC you should read this article. It may well turn out to not be a problem with teamviewer itself, but it never hurts to keep an eye out.


  2. The Following User Says Thank You to SpankedHam For This Useful Post:

    tristen (02-06-16)



Look Here ->
  • #2
    Administrator
    admin's Avatar
    Join Date
    Jan 2008
    Location
    Victoria
    Age
    56
    Posts
    31,150
    Thanks
    2,238
    Thanked 13,731 Times in 5,823 Posts
    Rep Power
    4553
    Reputation
    165805

    Default

    This is a pretty big one (based on what I have read today)

  • #3
    Senior Member
    Philquad's Avatar
    Join Date
    Jan 2008
    Location
    nelson bay
    Age
    55
    Posts
    3,872
    Thanks
    192
    Thanked 1,305 Times in 783 Posts
    Rep Power
    665
    Reputation
    16938

    Default

    im always in breach of tv
    overuse lol
    https://www.facebook.com/philquad68

  • #4
    Senior Member

    Join Date
    Oct 2009
    Posts
    2,742
    Thanks
    2,501
    Thanked 2,295 Times in 850 Posts
    Rep Power
    996
    Reputation
    36415

    Default

    I don't think any of my systems have ever been breached but recently I've been getting constant pop ups from Team viewer claiming suspected commercial use.
    There isn't any but it limits any session I have to 5 mins
    I've sent them the log files but doesn't change there mind.
    I'm constantly having to load and reload Team viewer.
    It usually lasts about 2 weeks and then I start getting the pop ups again
    In hindsight I should have posted my Facebook status as: "I've blown the head gasket on my 1997 XR3i" rather than "I've just buggered a 14 year old escort".
    The police still haven't seen the funny side, my lap top's been confiscated and the wife has gone off to her mum's.

  • #5
    Senior Member
    Philquad's Avatar
    Join Date
    Jan 2008
    Location
    nelson bay
    Age
    55
    Posts
    3,872
    Thanks
    192
    Thanked 1,305 Times in 783 Posts
    Rep Power
    665
    Reputation
    16938

    Default

    uninstall it
    remove any traces of it, reg files, users/apps folder ect
    change your mac address
    reinstall it
    https://www.facebook.com/philquad68

  • The Following User Says Thank You to Philquad For This Useful Post:

    Seymour Butts (04-06-16)

  • #6
    Senior Member

    Join Date
    Oct 2009
    Posts
    2,742
    Thanks
    2,501
    Thanked 2,295 Times in 850 Posts
    Rep Power
    996
    Reputation
    36415

    Default

    Quote Originally Posted by Philquad View Post
    uninstall it
    remove any traces of it, reg files, users/apps folder ect
    change your mac address
    reinstall it
    This is proving a little more difficult that I thought
    I believe I've removed all trace
    Gone through the registry users\AppData-files etc and original location

    But spoofing the MAC
    I've always assumed;
    Device Manager/Network Adapters\Realtek PCIe GBE Family Controller\Properties\advanced\Network Address ????
    Mine's Value is ticked 'Not Present" - Can I assume you just give a value IE: any 12 characters 004fgHHH8880 without any dashes or full colons.
    In hindsight I should have posted my Facebook status as: "I've blown the head gasket on my 1997 XR3i" rather than "I've just buggered a 14 year old escort".
    The police still haven't seen the funny side, my lap top's been confiscated and the wife has gone off to her mum's.

  • #7
    Senior Member

    Join Date
    Oct 2009
    Posts
    2,742
    Thanks
    2,501
    Thanked 2,295 Times in 850 Posts
    Rep Power
    996
    Reputation
    36415

    Default

    Well, they are doing something sneaky

    Wound back the PC to an earlier (much) iteration
    Changed the MAC Addy - confirmed
    Changed the IP - Confirmed
    Deleted all reference to Teamviewer - confirmed

    Fdddd if I know what to do next except pay for it
    In hindsight I should have posted my Facebook status as: "I've blown the head gasket on my 1997 XR3i" rather than "I've just buggered a 14 year old escort".
    The police still haven't seen the funny side, my lap top's been confiscated and the wife has gone off to her mum's.

  • #8
    Senior Member

    Join Date
    Oct 2009
    Posts
    2,742
    Thanks
    2,501
    Thanked 2,295 Times in 850 Posts
    Rep Power
    996
    Reputation
    36415

    Default

    Finally got it all fixed.
    Jeeze Teamviewer hides crap all over the show - heaps of Cached and Temp directories and folders
    In hindsight I should have posted my Facebook status as: "I've blown the head gasket on my 1997 XR3i" rather than "I've just buggered a 14 year old escort".
    The police still haven't seen the funny side, my lap top's been confiscated and the wife has gone off to her mum's.

  • #9
    Senior Member
    Philquad's Avatar
    Join Date
    Jan 2008
    Location
    nelson bay
    Age
    55
    Posts
    3,872
    Thanks
    192
    Thanked 1,305 Times in 783 Posts
    Rep Power
    665
    Reputation
    16938

    Default

    yes finding that myself
    have done it before
    this helps

    im more concerned atm with the pos at the other end
    2 pc's have had cryptolocker thru them
    its impossible
    https://www.facebook.com/philquad68

  • The Following 2 Users Say Thank You to Philquad For This Useful Post:

    cmangle (06-06-16),Seymour Butts (05-06-16)

  • #10
    Senior Member

    Join Date
    Oct 2009
    Posts
    2,742
    Thanks
    2,501
    Thanked 2,295 Times in 850 Posts
    Rep Power
    996
    Reputation
    36415

    Default

    Thanks Phil,
    Yes, thats the same file I found and now use - quite handy.
    Thanks for your help
    In hindsight I should have posted my Facebook status as: "I've blown the head gasket on my 1997 XR3i" rather than "I've just buggered a 14 year old escort".
    The police still haven't seen the funny side, my lap top's been confiscated and the wife has gone off to her mum's.

  • #11
    Senior Member

    Join Date
    Mar 2008
    Posts
    1,265
    Thanks
    139
    Thanked 643 Times in 368 Posts
    Rep Power
    455
    Reputation
    10815

    Default

    Quote Originally Posted by Seymour Butts View Post
    Mine's Value is ticked 'Not Present" - Can I assume you just give a value IE: any 12 characters 004fgHHH8880 without any dashes or full colons.
    Any value using 0-9 A-F, but it must be unique on the network and, if by some bizarre chance given how everything is switched these days, you have a hub or *gasp* coax based network, at least 200 count different to any other MAC on your network to allow collision back-off to work properly.

  • The Following User Says Thank You to SpankedHam For This Useful Post:

    Seymour Butts (06-06-16)

  • #12
    Senior Member

    Join Date
    Oct 2009
    Posts
    2,742
    Thanks
    2,501
    Thanked 2,295 Times in 850 Posts
    Rep Power
    996
    Reputation
    36415

    Default

    Quote Originally Posted by Philquad View Post
    yes finding that myself
    have done it before
    this helps

    im more concerned atm with the pos at the other end
    2 pc's have had cryptolocker thru them
    its impossible

    Hi Phil,
    speaking of Cryptolocker - have you had any luck cleaning systems that are Crypto infected??
    I must admit I usually just wind back or rebuild but what about yourself??
    In hindsight I should have posted my Facebook status as: "I've blown the head gasket on my 1997 XR3i" rather than "I've just buggered a 14 year old escort".
    The police still haven't seen the funny side, my lap top's been confiscated and the wife has gone off to her mum's.

  • #13
    Senior Member
    Philquad's Avatar
    Join Date
    Jan 2008
    Location
    nelson bay
    Age
    55
    Posts
    3,872
    Thanks
    192
    Thanked 1,305 Times in 783 Posts
    Rep Power
    665
    Reputation
    16938

    Default

    not really
    i started a thread
    basicly if theres a previous version or shadowcopy its ok
    but in this case, there gone & system restore is shot
    even data recovery is not working as theres no previous install
    so im only recovering corrupted files anyway
    https://www.facebook.com/philquad68

  • Bookmarks

    Posting Permissions

    • You may not post new threads
    • You may not post replies
    • You may not post attachments
    • You may not edit your posts
    •