BackDoor.TeamViewer.49 is the name of a backdoor trojan discovered by Russian security vendor Dr.Web, which claims to install the TeamViewer application on infected computers so that it can monitor Web traffic from the rogue to other servers on the Internet, effectively using the host as a proxy.
Dr.Web researchers, together with security experts from Yandex, first discovered the trojan in early May, distributing via a complex multi-stage mechanism.
Users are not infected with BackDoor.TeamViewer directly, but first through a malware dropper called Trojan.MulDrop6.39120, which Dr.Web says is distributed online along with an Adobe Flash Player update package.
When users install this malicious Flash Player update, they get a legitimate version of Flash, but also the Trojan.MulDrop6 trojan, which secretly installs TeamViewer on the victim's computer.
Installing TeamViewer on infected devices is nothing new, but crooks don't use it to log into a victim's computer and take control of the device. Dr.Web claims that TeamViewer is used for something else.
The crooks replace TeamViewer's avicap32.dll file with a malicious version containing the BackDoor.TeamViewer trojan. Since TeamViewer automatically runs avicap32.dll in the operating system's memory, the crooks only need to add auto-run functions to TeamViewer and make sure that the application icon is hidden from the Windows notification area.
After the criminals make all the necessary modifications and TeamViewer is running, BackDoor.TeamViewer connects via an encrypted channel to the command and control of the crooks' server, where it waits for instructions.
Dr.Web says that, in the versions analyzed, the trojan's main function was to act as a Web proxy, taking traffic received from the C&C server and their connection to the Internet, essentially masking the real IPs of the crooks.
"While we should look into this further, the real problem is the installation of a malicious software program. Once a system is infected, the perpetrators can do virtually anything with that system – depending on how sophisticated the malware, whether it can take over an entire system, steal or tamper with information, and so on," a TeamViewer spokesperson told Softpedia. "So, first and foremost, it's important for users to protect their systems as best they can by having the right anti-malware."

