TeamViewer

TeamViewer is the complete remote control program that can control a machine over a LAN.The victim's machine can also be controlled through the Internet.0

General information:

Malware Name: TeamViewer
Malware Type: Remote Control
Company Name: TeamViewer
Company URL: http://teamviewer.com/
Threat Level: Elevated Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation

Company Description:

The German TeamViewer GmbH was founded in 2005 and is fully focused on development and distribution of high-end solutions for remote support. A fast start and high growth rates have led to more than 350.000 installations in more than 50 countries all over the world. It provides us with the remote control TeamViewer that is simple fast and secure desktop sharing, and works behind firewall also.

Spyware Description:

TeamViewer is the complete remote control program that can control a machine over a LAN.The victim's machine can also be controlled through the Internet.0

Characteristics/Symptoms:

    -> It is a network application that allows to manage and control PCs or networks from a remote location. -> It allows to access another computer without explicit authorization. -> It can also be used to monitor and steal information from the remote computer -> Slows down the performance of PC0

Additional information might be found here:

google Search at Google for TeamViewer
bing Search at Bing for TeamViewer
yahoo Search at Yahoo for TeamViewer

Processes Running:

DynGate.exe

File information Created after Installation:

File Location Size (Bytes) Type
C:\Documents and Settings\[USER]\Desktop\TeamViewer.lnk 591 Shortcut
C:\Program Files\DynGate\License.txt 2274 Text Document
C:\Program Files\DynGate\uninstall.exe 22744 Application

Folder information Created after Installation:

Folder Location
C:\Program Files\DynGate

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_LOCAL_MACHINE SOFTWAREDynGateRouter VNCConnectPort
HKEY_LOCAL_MACHINE SOFTWAREDynGateRouter Version
HKEY_LOCAL_MACHINE SOFTWAREDynGateRouter useUDP