I had something very strange happen yesterday. I was checking my miner and there was someone Teamviewer'ed into it. from there they went to every machine I have. I put a stop to it, reinstalled TV with a new address and 2 factor. The only thing I have done to that machine is installed and was running Claymore 5.0.
VirusTotal gives 5.0/5.1 three hits. I have been using claymore since the beginning but this is really strange. Have have forefront and malware bytes running on all machines and they are clean.
I know miners/wallets sometimes have false positives. But this really un-nerved me...
There was a hack on Teamviewer about a month ago. I think it had something to do with those 4 PIN passwords that are given during tech support. They normally just go into your Paypal and order some gift cards. If you had saved passwords then you might of been affected.
check these
How access TeamViewer QuickSupport log files using Windows:
Click on the tool kit symbol in the upper right corner
Click on the button Open Logfiles...
Open the files named ConnectionFirst
How to access TeamViewer full version + Host module log files using Windows:
Click on Extras in the menu
Click on Open log files...
Open the files named Connections_incoming.txt and Connections.txt