Backdoor.Teamviewer: what it is and how to remove it

First of all, we must note that TEAMVIEWER IS NOT MALICIOUS and it is NOT REATED TO BACKDOOR.TEAMVIEWER IN ANY WAY. It is a legitimate and trustworthy platform helping people connect remotely.

Facts checked October 6, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

An automatic scan can look at avicap32.dll and the other programs installed around the same time.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove Backdoor.Teamviewer yourself 6 steps, about 18 minutes, no software needed.

Start the steps
Backdoor.Teamviewer: fake update ads
Backdoor.Teamviewer as our 2016 report showed it.

Backdoor.Teamviewer: summary

Detection namesNo Microsoft detection name is known
DistributionNot recorded in the old report
DamageNot recorded in the old report
NameBackdoor.Teamviewer
TypeRemote access trojan
SymptomsAn unknown process in Task Manager
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 4 more facts
EvidenceOne write-up by a security site; details still limited
File namesavicap32.dll
First seen8 June 2016
Facts checked6 October 2026

What Backdoor.Teamviewer does on an infected PC

From our report of Jun 2016 · not reviewed since

What you should know about Backdoor.Teamviewer malware?

First of all, we must note that TEAMVIEWER IS NOT MALICIOUS and it is NOT REATED TO BACKDOOR.TEAMVIEWER IN ANY WAY.

It is a legitimate and trustworthy platform helping people connect remotely. It is a safe software that encrypts every conversation. However, according to the latest reports of virus researchers from Russia, hackers have started using TeamViewer to steal people's personal information and money.

They have been installing this software behind people's back with the help of Backdoor.Teamviewer and its latest version Backdoor.Teamviewer.49. Once again, these viruses, which belong to Trojan horse category, have nothing to do with TeamViewer and its developers.

Reportedly, Backdoor.Teamviewer Trojan spreads with a help of Trojan.MulDrop6.39120 Trojan horse, which is spread online concealed as an Adobe Flash Player update. This update can be downloaded from high-risk Internet sites or malicious pop-up ads. If the victim agrees to update Adobe Flash Player, the Trojan.MulDrop6.39120 gets installed along with the upgrade, and it drops TeamViewer app on the compromised computer.

Then it swaps one of TeamViewer's components, called avicap32.dll, with a fake one, which carries Backdoor.TeamViewer.49 Trojan. TeamViewer uses this .dll file within every startup, so, to activate the Trojan, cyber criminals assign this TeamViewer version to startup automatically whenever the victim turns on the PC.

When this program launches, the Trojan connects to its command and control (C&C) server and waits for instructions. To prevent this modified TeamViewer version from displaying error messages and to hide it from the victim, hackers turn off error reporting function and also hide TeamViewer's icon from the Windows notification section.

However, it seems that cyber criminals do not only use this Trojan to steal victim's personal information and money. Reportedly, frauds also seek to exploit victim's computer and use it as a proxy server. To put it simply, crooks use the compromised computer as a tool to mask their real IP address and initiate illegal activities without being caught.

It is very important to protect your computer from such malicious and complicated computer viruses as Backdoor.Teamviewer. To stop them from infiltrating your computer system is to install and keep an up-to-date anti-malware program on it. We highly recommend you to use software for that. If your computer is already infected with this Trojan, you must implement Backdoor.Teamviewer removal immediately.

Backdoor.Teamviewer: fake update ads
Backdoor.Teamviewer in our 2016 report.

How Backdoor.Teamviewer got on your PC

From our report of Jun 2016 · not reviewed since

Unfortunately, Flash Player is a gateway for criminals to infect victim's computers, so they create various bogus websites offering to install or update this software.

Please, keep in mind that the only way to get a trustworthy Flash Player on your computer is to go to its official website and see what updates are offered for you. Also, stay away from pop-up ads offering you to install software updates because the most of them are related to suspicious websites and viruses.

You can also end up installing malware by browsing through high-risk Internet sites, installing freeware without monitoring its installation or by simply clicking ads that tend to appear out of nowhere. If you have never heard about clickjacking, bear in mind that it is a technique used by many cyber criminals, which helps them conceal malicious links under various clickable content.

In other words, you can click on a deceptive link or ad and automatically install Trojan or another virus into your computer system. If you suspect that you have installed the aforementioned virus accidentally, it goes without saying that you must remove Backdoor.Teamviewer.49 as soon as possible.

How to check the PC for Backdoor.Teamviewer

  • File: avicap32.dll

How to remove Backdoor.Teamviewer

How to remove Backdoor.Teamviewer and lock the attacker out

Someone may have had remote control of the PC.

Cut the connection first, then remove the trojan and secure your accounts.

  1. Step 1: Remove remote access tools and lock the attacker out

    Attackers keep access through remote control tools and extra user accounts. Disconnect the PC from the internet, then remove every remote access program you did not install yourself from the installed apps list in Windows 11 or Windows 10.

    Look for a user account you do not know and delete it, and switch off Remote Desktop in Settings > System. Reconnect only for the scan.

    Full procedure with screenshots: Uninstall a program or app in Windows On uGetFix

  2. Step 2: Check where avicap32.dll runs from and stop it

    In Task Manager (Ctrl + Shift + Esc) find avicap32.dll on Processes, right-click it and choose Open file location before ending anything.

    Windows' own files live in C:\Windows\System32; the same name in %AppData%, %Temp% or C:\Users\Public is an impostor. If the folder is wrong, right-click the process again, choose End task and delete the file.

    If it starts again within seconds, a task or another process restarts it, so run the scan step in Safe Mode. Task Manager works the same in Windows 11 and Windows 10.

    Full procedure with screenshots: Close a frozen app (Task Manager, Force Quit) On uGetFix

  3. Step 3: Delete scheduled tasks that bring it back

    Programs like Backdoor.Teamviewer add a scheduled task so they return after an uninstall or reopen a page at every sign-in. Start Task Scheduler, open Task Scheduler Library and sort by Last Run Time to see what ran recently.

    On the Actions tab, a program in a user folder, a script or a web address is a warning sign; right-click such a task and choose Delete.

    Tasks with names copying Google, Edge or Windows updaters but pointing to an odd folder are typical. The tool looks the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  4. Step 4: Remove it from startup

    Press Ctrl + Shift + Esc to open Task Manager and select Startup apps (Windows 11) or the Startup tab (Windows 10). Disable entries you do not recognise, especially ones with no publisher or with a name that copies a Windows component.

    Right-click an entry and choose Open file location to see where it runs from: programs in %AppData% or %Temp% deserve a closer look. Some entries are not listed there but in the registry Run keys, which the procedure below shows how to check.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  5. Step 5: Scan the PC, then run the offline scan

    A scan finds the parts of Backdoor.Teamviewer that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.

    Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.

    It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  6. Step 6: Change passwords from another device and sign out other sessions

    Backdoor.Teamviewer can copy saved passwords, cookies and session tokens and send them out in seconds, so cleaning the PC does not undo the theft.

    Change your passwords on a device that was never infected, starting with the e-mail account, since every other reset goes through it. On each account, end all other sessions and check the recovery e-mail, phone number and forwarding rules.

    Then turn on two-step verification. Sign in on the Windows 11 or Windows 10 PC again only after the offline scan is clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

From our report of Jun 2016 · not reviewed since

How to remove Backdoor.Teamviewer.49?

If you suspect that your computer has been affected by Backdoor.Teamviewer.49 virus, you should scan it with a powerful anti-malware and let it delete all malicious files automatically.

You do NOT need to uninstall TeamViewer, especially if you have installed it consciously. As we have mentioned in the beginning of this post, it is a legitimate software that does not pose any danger. The real danger is Backdoor.Teamviewer which can be used to steal your personal data and money.

To remove this trojan horse from the system, you should install one of these programs: , . We do not advise you to deal with this threat manually because it is a very complicated task to do. This threat roots deeply into the computer system, and it manages to make its files look like safe ones.

After removal: passwords, accounts and prevention

Secure your accounts after the clean-up

Assume that whatever was saved in the browsers on this PC while the PC showed an unfamiliar process called avicap32.dll in Task Manager has been copied:

  • passwords
  • cookies
  • autofill data

Work from a clean device, or from this PC once the offline scan finds nothing.

Start with your main e-mail account, because it can reset everything else, then banking and payment, then social and gaming accounts. Change each password, sign out of all sessions and turn on two-step verification: Turn on two-step verification / secure a hacked account.

The full order, including crypto wallets and card replacement, is in securing your accounts after malware.

Access your website securely from any location

When you work on the domain, site, blog, or different project that requires constant management, content creation, or coding, you may need to connect to the server and content management service more often. The best solution for creating a tighter network could be a dedicated/fixed IP address.

If you make your IP address static and set to your device, you can connect to the CMS from any location and do not create any additional issues for the server or network manager that needs to monitor connections and activities. VPN software providers like can help you with such settings and offer the option to control the online reputation and manage projects easily from any part of the world.

Recover files after data-affecting malware attacks

While much of the data can be accidentally deleted due to various reasons, malware is one of the main culprits that can cause loss of pictures, documents, videos, and other important files.

More serious malware infections lead to significant data loss when your documents, system files, and images get encrypted. In particular, ransomware is is a type of malware that focuses on such functions, so your files become useless without an ability to access them.

Even though there is little to no possibility to recover after file-locking threats, some applications have features for data recovery in the system. In some cases, can also help to recover at least some portion of your data after data-locking virus infection or general cyber infection.

Questions about Backdoor.Teamviewer

Is avicap32.dll a virus?

The name avicap32.dll is not enough to say. Malware often uses technical-sounding names, and harmless updaters often use odd ones. Check three things:

  • the folder the file runs from
  • the Digital Signatures tab in its properties
  • the program that starts it (Startup apps, Task Scheduler or services)

A signed file from a company whose product you use is almost certainly fine. An unsigned file in a user folder that no installed program explains should be removed, and the PC scanned with Microsoft Defender in offline mode.

Can I end avicap32.dll in Task Manager?

Ending an unknown process is safe in the sense that Windows will warn you before you close anything critical, and a restart brings back whatever Windows needs. Ending avicap32.dll will not remove it, though: if a task or startup entry launches it, it returns at the next sign-in.

Use ending the process as a test. If something important stops working, it belonged to a program you use. If nothing changes and it comes back by itself, find and disable its starter, delete the file and scan the PC.

My antivirus was on. How did a trojan get past it?

Antivirus programs see a file only when it is written or run, and criminals test each new build against popular scanners before release. Detection catches up within hours or days, which is often after the first victims ran it.

Archives with passwords, installers that fetch the malware later, and scripts run through PowerShell make the job harder. That is why behaviour such as downloading cracks or pasting commands matters more than any setting. Keep Windows and Defender updated, and turn on Reputation-based protection in App & browser control.

Why can't I find Backdoor.Teamviewer in antivirus databases?

Because it is new or because it is listed under a different name. Antivirus companies name threats after the family they belong to, and a program that appears as Backdoor.Teamviewer on your PC may carry a generic or unrelated label in their databases.

Many new samples are first detected only by behaviour, without a family name. What you saw, an unfamiliar process called avicap32.dll in Task Manager, is enough to act on:

  • end the program
  • remove its startup entry
  • run a Microsoft Defender offline scan
  • secure your accounts

A detection name from a scan is worth noting for later.

Do I need to reinstall Windows to get rid of Backdoor.Teamviewer?

Usually not. A thorough clean-up is enough when the offline scan finds nothing afterwards and you do not see an unfamiliar process called avicap32.dll in Task Manager again. A reset is the safer choice if an attacker had remote control, if security tools were switched off, or if detections come back after every clean-up.

Windows 11 can reset itself without a USB stick under Settings > System > Recovery > Reset this PC. Copy documents and photos out first and scan the copies. A reset does not change passwords or undo stolen data, so the account steps still apply.

Should I check my other computers too?

Yes, it takes little time and removes doubt. Backdoor.Teamviewer itself usually stays on one PC, but the download that carried it may have been copied to other computers, shared drives may hold the same installer, and an attacker who had access could have tried saved passwords on other devices.

Run a full scan on every Windows PC in the home or office, check shared folders for the original download, and change Wi-Fi and router passwords if they were stored on the infected machine.

Should I report Backdoor.Teamviewer?

Report it if you lost money, if accounts were taken over, if you are a business, or if the trojan came through a scam call. A police or national cybercrime report gives you a reference number for your bank and insurer and helps link cases.

You do not need to report a trojan that antivirus blocked before it ran. Before reporting, write down the dates, the detection name, file names and any messages or transactions linked to the attack; screenshots of antivirus alerts are useful evidence. The country list is in the report section above.

How dangerous is Backdoor.Teamviewer?

Treat it as serious until proven otherwise. The visible sign is an unfamiliar process called avicap32.dll in Task Manager, and programs that behave this way often have more abilities than they show:

  • copying passwords
  • downloading other malware
  • giving remote access

Its family is not known yet, so nobody can say which of these it uses. The good news is that the response is the same in every case and takes about an hour:

  • cut the network
  • remove the startup entry
  • run an offline scan
  • change passwords from a clean device

If someone had remote control, a full reset is safer.

How do I know if my PC has Backdoor.Teamviewer?

Often you do not, which is the point of a trojan. Possible signs are an antivirus alert naming Backdoor.Teamviewer or a generic trojan detection, unknown programs or scheduled tasks, processes with random names in Task Manager, browser extensions you did not add, security settings turned off, slower performance, or account alerts about logins from unknown places.

The reliable check is a full scan followed by Microsoft Defender's offline scan. If you recently ran a crack, a fake installer or a command a website told you to paste, scan even without symptoms.

Will Fortect remove Backdoor.Teamviewer?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For Backdoor.Teamviewer, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove porterneuman.mx: PowerShell and JavaScript files tied to the AveMaria remote access trojan, and what to do

porterneuman.mx is a web address where URLhaus found five script files in a WordPress plugin folder on 30 September 2026: four PowerShell stubs and one JavaScript file. One stub is tagged AveMariaRAT, a remote access...TrojansHigh riskUgnius Kiguolis ·

Remove Memz virus

Memz virus is the custom-made trojan that overwrites Windows boot sequence with Nyan Cat meme animation Memz virus is the trojan originally created by Leurak as viewer-made malware forTrojansHigh riskLucia Danes ·

Remove qpwot.cfd: a server handing out scripts that lead to the MassLogger and VIP Keylogger stealers, and what to do if one ran

qpwot.cfd is a web address that URLhaus listed seven times on 6 October 2026 for JavaScript files and PowerShell files named secured_stub.ps1, tagged MassLogger and VIPKeylogger, two keyloggers that steal passwords...TrojansHigh riskUgnius Kiguolis ·

Remove www.beinke-aufzuege.de: a hacked website hosting FormBook PowerShell stubs, and what to do if a script fetched them

www.beinke-aufzuege.de is the address of a German website that URLhaus lists for four PowerShell files tagged Formbook, a password stealer for Windows, hidden in random folders inside the site's own Joomla media...TrojansHigh riskUgnius Kiguolis ·

Questions and experiences: Backdoor.Teamviewer

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,442 members already hereReading, writing, commenting and voting. 0 verified · 167 joined this year