Teamviewer deletevalue safeboot
stanley783
Posts: 1
Hi,
we detected that Teamviewer executed command "/deletevalue safeboot" via bcedit.exe. I know teamviewer has features related to safe booting, but this specific event was kinda suspicious.
Also noticed two more operations at same time:
RegSetValue HKLM\software\wow6432node\teamviewer\version
RegDeleteKey HKLM\software\wow6432node\teamviewer\temp
TeamViewer 15.52.3
Any idea why would service delete safeboot and is this considered standard behavior? We noticed this on only one device, despite it being deployed on multiple. Thanks.
1