Author Topic: Teamviewer Microsoft Scam  (Read 1234 times)


  • Newbie
  • *
  • Posts: 1
Teamviewer Microsoft Scam
« on: September 17, 2017, 02:23:05 PM »
Hi fellow members.

We recently had a Microsoft Scam via Teamviewer and are analysing the logs.
One of the things we try to figure out is what happened in the teamviewer session.

Was the person on our end the one who inititiated the teamviewer session of was he requested to answer the teamviewer session.

The logs state:
CommandHandlerRouting[12]::CreateActiveSession(): outgoing session to 158289069 via, protocol Port443

Is it possible that the server was already open ?

Also this line strikes me as strange.

7076  6896 D2   tvdesktop::GrabScreen::CDesktop_Win::EnumTopWindowsProcWin - window class $$$Secure UAP Background Fake Client Window Class; style 79691776
« Last Edit: September 17, 2017, 02:26:45 PM by Donkerg »