VNC removal from my PC?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by piotrmaciej, Oct 10, 2007.

  1. piotrmaciej

    piotrmaciej Private First Class

    How on earth may I remove this once and for all? my friend was once in my pc installing this 'VNC' thingy! then when it was not needed for the purpose for which he intended, he thought he had removed it yet every time I boot my pc I am faced with this annoying message which I attach from screen shot, I have searched my pc and thought I have removed everything yet it is still inside my pc, please can anyone recommend a thorough method of 'expunging' it?
    Piotr Maciej:cry
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download, run and attach these logs from the Read and Run First sticky:

    GetRunKeys
    ShowNew
    HJT
     
  3. piotrmaciej

    piotrmaciej Private First Class

    Please download, run and attach these logs from the Read and Run First sticky:!!!!! Sorry but you have me 'vexed'??? sorry what logs? 'Read and Run First' what is that? my apologies for sounding 'technophobically obtuse' but can you clarify, thanks.:eek:
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  5. piotrmaciej

    piotrmaciej Private First Class

    Thanks, I am studying it now.:):cry:D
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You may run the other scans ...but as you probably are not having malware issues ...just attach the three scans that I requested. :)
     
  7. piotrmaciej

    piotrmaciej Private First Class

    Hello and thank you, well I am having all manner of issue, firstly this irksome message about 'VNC' and then my processes, I counted 59 processes as running!!! I really want to disable many but am scared to know which to disable? please if you can offer your input, much appreciated, I am only permitted to upload the one screenshot for the 'VNC' problem, but the others it is telling me error as I have alreading uploaded them in an earlier instance thread enitiled 'Starup', my how clever these forums are, prevent you from posting the same file twice.:)
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  9. piotrmaciej

    piotrmaciej Private First Class

    Well I followed your instructions and here are the logs.:) I trust they will tell you something, well of course they havbe to else the whole excercise would be pointless, thank you for your input.:);)
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now attach a new GetRunKeys log.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Next:

    Click Start> Run> type in CMD tap enter. Type the following into command prompt:

    sc stop winvnc

    Hit 'enter' and type the following:

    sc delete winvnc

    At the command prompt: type exit.

    Please run Notepad and paste the following text into a new file:
    Save the file to the desktop as fix.reg and make sure the "Save as Type" field says "All Files".


    Then please go to the desktop and double-click on fix.reg, and click Yes to merge it with the registry.

    Reboot and see if the WinVNC is gone....!
     
  12. piotrmaciej

    piotrmaciej Private First Class

    a NO GO, I did everything which you told me but got to the 'next' part and I attach a screen shot for you to observe and offer what next?:(
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Open notepad and copy and paste the following text in the quote box into the window:
    Save this as fix.bat
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.

    Did you do the regedit?
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please rename HJT.exe to analyse.exe ....it is important to do this.

    Open notepad and copy and paste the following text in the quote box into the window:
    Save this as fix.bat
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.


    Now:
    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking fix. exit HJT.

    Attach a new log.

    How is the VNC problem?
     
  15. piotrmaciej

    piotrmaciej Private First Class

    Hello Tim,

    Crikey, this irksome problem has escalated into a major problem, I mean to it's removal! so you are saying.............'Please rename HJT.exe to analyse.exe ....it is important to do this' I take it the 'HiJackThis' log which I have on my desktop, or I am first to run a new one and then rename it to 'analyse.exe'?:confused
     
  16. piotrmaciej

    piotrmaciej Private First Class

    Well Tim, I threwe caution to the wind, and renamed my HJT log file to as you had instructed, ran it, did everything as per instructed to the 'letter' rebooted my pc, and alas...............PROBLEM UNSOLVED!!!!! this blasted communique is still popping up? any further suggestions, hey now you have started you must be on a roll!:D:)
     
  17. piotrmaciej

    piotrmaciej Private First Class

    Hey Tim, attached a new log of HJT.
     

    Attached Files:

  18. piotrmaciej

    piotrmaciej Private First Class

    Well Tim, I now find these strange 'ghost' like icons in all my files and folders. since I started tweeking my pc, do you think it's because of what I have been doing to try and eliminate this blasted 'VNC'?:confused
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What I need you to do at this point is to run all of the procedures in the Read and Run First sticky!!

    And then attach all of the logs!!
    Counterspy
    BitDefender
    Panda
    ShowNew
    GetRunKeys
    HJT ---> again, renamed!

    You did not rename HJT:
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    It chould be:
    C:\Program Files\Trend Micro\HijackThis\Analyse.exe

    Open notepad and copy and paste the following text in the quote box into the window:
    Save this as fix.bat
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.
     
  20. piotrmaciej

    piotrmaciej Private First Class

    Tim Tim Tim..............all this cyber blog is just too much for my brain cells to assimilate!!! I mean slowly..........Counterspy,BitDefender,Panda? what are these? other forms of anti spy software I imagine?and what does 'sticky'!! refer to?

    :confused
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  22. piotrmaciej

    piotrmaciej Private First Class

    Yes quite so, I am in the process of doing everything in accordance with the instructions:) and then maybe I shall get somewhere!!!! I shall be in touch, thanks.
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem ....attach the logs when ready ....it is becoming obvious that you have some other issues other than just the VNC one.:)
     
  24. piotrmaciej

    piotrmaciej Private First Class

    Hello again Tim, well I proceeded to follow all the instructions in the 'malware removal guide' from the begining to the end, I did not even manage to get to the end, the part where I start in 'safe mode'....what a nightmare, pc froze and all manner of irregular instances, I also note that I am unable to activate 'system restore', that is frozen?:cry I do belive I have all manner of issues in my pc, short of doing a complete uninstall and reinstall of my system can I safely function? I enclose an 'active scan' from my pc, have a lookand tell me what you think please?:confused
     

    Attached Files:

  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I suspect that this is the cause of most of your problems:

    You need to get a illegitimate copy of XP.......

    Now

    1. Download this file - Combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run this Virtumonde aka Trojan Vundo Removal

    * Double-click VundoFix.exe to run it.
    * When VundoFix opens, click the Scan for Vundo button.
    * Once it's done scanning, click the Remove Vundo button.
    * You will receive a prompt asking if you want to remove the files, click YES
    * Once you click yes, your desktop will go blank as it starts removing Vundo.
    * When completed, it will prompt that it will reboot your computer, click OK.
    * Please post the contents of C:\vundofix.txt and a new HiJackThis log in the thread you are working in.

    Note: It is possible that VundoFix encountered a file it could not remove.
    In this case, VundoFix will run on reboot, simply follow the above instructions above, starting from "Click the
    Scan for Vundo button" when VundoFix appears at reboot.

    Now attach the below logs and tell me how the above steps went.

    1. Combofix log
    2. VundoFix log
    3. new GetRunKey log
    4. new ShowNew log
    5. new HJT

    Once you are stable ...you will need to do a repair install with a legal copy of the OS.
     
  26. piotrmaciej

    piotrmaciej Private First Class

    Hello Tim,

    I enclose the scans in 2 replys to you, as for my OS, I hasten to tell you THIS IS A LEGAL COPY!!! I had my PC custom built and bought the OS myself from a shop??, I have never had any problems validating it on microsofts site when doing updates etc? so why would you say it is not legal? is that what the logs have deduced, because if they have then I would strongly beg to differ? Thanks for all your input, will I ever rif myself of these viruses?:confused
     

    Attached Files:

  27. piotrmaciej

    piotrmaciej Private First Class

    and the last of the logs, by the way 'VundoFix' returned 'no infections were found on your system' hence there is no log to attach!
     

    Attached Files:

  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The activescan log found the virus/worm in the zip file and removed it.

    You should uninstall all of your old Java:
    J2SE Runtime Environment 5.0 Update 10"
    J2SE Runtime Environment 5.0 Update 6"
    J2SE Runtime Environment 5.0 Update 9

    You still have this service:
    O23 - Service: Systart (Winsys32) - Unknown owner - C:\WINDOWS\winstc.exe (file missing)

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    * On the page that opens, scroll down to Systart
    * then right click the entry, select Properties and press Stop Service.
    * When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    * Click OK until you get back to Windows.

    * Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    * At the lower right, click on the Config button
    * Then click the Misc tools button
    * Select Delete an NT Service
    * Copy/paste Winsys32 into the box that opens, and press OK
    * If you receive any error messages just ignore them and continue.

    Reboot.

    I'm not seeing any other problems.

    What issues are you still having and do they occur on each user account?
     
  29. piotrmaciej

    piotrmaciej Private First Class

    Hello Tim,

    just did all that you recommended, what now? should I run any more scans to determine whether I am now 'FREE' from infection? I have to tell you the pop up warning window re VNC is still with me:confused, any further instructions?
     
  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Start / run / services.msc ....look for the VNC service ...tell me if you find it ...also do a search for it.

    No other scans are needed as I don't think malware is an issue ....though you may want to consider doing a repair install.
     
  31. piotrmaciej

    piotrmaciej Private First Class

    searched and no 'VNC' looked in services.msc and nothing:confused so how the heck is this window popping up everytime? you mentioned 'though you may want to consider doing a repair install' can you elaborate further, what do I do install my OS Disc?:confused
     
  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  33. piotrmaciej

    piotrmaciej Private First Class

    Hello Tim,

    well, nothing in the regit register for 'vnc':confused, I still have issues, ie viruses, what do you personally think to this 'Langa Letter: XP's No-Reformat, Nondestructive Total-Rebuild Option':confused, flicking through the comments left by persons who have tried this procedure makes scary reading, I mean what if it fails etc and I am left with all my files being lost?
     
  34. piotrmaciej

    piotrmaciej Private First Class

    The counterspy scan log I mentioned earlier Tim:)
     

    Attached Files:

  35. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to run counterspy and have it remove/quarantine all that it finds!! You should read it!! You have problems that should have been corrected before we began this.

    Please do so and then attach a new counterspy log.

    Also run the Bitdefender scan and the Panda scan!!
    Attach those logs also!
     
  36. piotrmaciej

    piotrmaciej Private First Class

    Hey Tim, I am running the scans as we speak and will attch as soon as finished, yes quite, I had, and still have by all accounts problems before any of this 'vnc' business arose, and i still do!(The VNC):(
     
  37. piotrmaciej

    piotrmaciej Private First Class

    Where in Counterspys settings am I able to set the software so that it quarantines all found risks, and then gives me the option to delete/remove them perm from my PC? I have looked and studied and must be 'obtuse' because I cedrtainly cannot find anything:confused do you think that because this is a trial version and does not extend to me having these options? and what about saving the log? in panda and bitdefender the options are entirely different!
     
  38. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    How long have you had Counterspy installed? It is only a 15 day trial and may no longer be effective.

    Download and run AVGAnti-spyware.

    For Panda:
    To start the online scan go here: Panda ActiveScan

    1. When the page appears, click the Scan your PC button.
    2. In the next window, click the Check Now button
    3. You now need to enter some information before you can run a scan
    * Enter your Country
    * Enter your State/Province
    * Enter your e-mail address and click send
    * Select either Home User or Company
    4. Click the Scan Now button
    5. If you get a prompt about an Active-X component, allow the component to be installed.
    6. Now a download to your PC will begin. This is a required component for the scan. It contains detection information. (Note: It may take a while to download based on your connection speed.)
    7. When the download has completed, click on Local Disks to start the scan
    8. When the scan is finished close the popup window and then click See Report
    9. Click Yes to the prompt, then click Save Report
    10. The default report name is Activescan.txt. Just save it where you can find it so you can attach to your message when you begin a thread with a request for help.

    For BitDefender:
    Once Bitdefender completes the scan:

    Click-on Click here to view the report

    When the window comes up with the report. Click File, Save As.... and then change the Save as type to Text File (*.txt)

    Change the file name to something short like bdscan1.txt

    Then save it to your Desktop or anywhere else you can find it to upload here as an attachment.

    Post the bdscan1.txt file as an ATTACHMENT.
     
  39. piotrmaciej

    piotrmaciej Private First Class

    Well here they are, all three of the scans performed, I have mega issues by all accounts, is there anyway that they may be removed from my pc without my having to follow this earlier suggestion by you of doing this 'Fred Langa' fix thing?:cry:cry:cry:cry
     

    Attached Files:

  40. piotrmaciej

    piotrmaciej Private First Class

    Have you managed Tim to take a look at the logs which I sent you? and what of your recommendations in my being able to remove them?:)
     
  41. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to uninstall EMule! Then do a search for Emule and delete all associated files.
    You also need to remove all of your IE toolbars!
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Attach a new log from:
    Avenger
    HJT ---> RENAME THE .EXE to ANALYSE!
     
  42. piotrmaciej

    piotrmaciej Private First Class

    Okay removed all IE tootlbars, removed emule plus from my system, did all that you asked, and attach the logs.
     

    Attached Files:

  43. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you running all of this from an Administrator account?

    And you're still not getting it.

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe ...should be:
    C:\Program Files\Trend Micro\HijackThis\Analyse.exe
    you need to right click the HijackThis.exe and choose rename.

    Attach new logs for:
    ShowNew
    GetRunkeys
    HJT
     
  44. piotrmaciej

    piotrmaciej Private First Class

    You will have to forgive me I am not a 'technophobe' or at least not when it comes to mastering computer jargon! I am an Interior designer, I paint, I draw, I design, so when you give me instructions that are vague I attempt to decipher them to the best of my 'limited' techno ability, I do apologise that I am not renaming the logs correctly, so now I AM TO RIGHT CLICK ON THE HIJACKTHIS LOG FILE AND RENAME IT ANALYSE.EXE? which is what I have now done, and I double clicked it and it was a blank black screen, what now, attach it and once again new logs for
    ShowNew
    GetRunkeys
    HJT

    all perfectly perplexing to me, but you ARE THE EXPERT, and I respect you for that, but what started as a question to remove this blasted VNC pop up thing, has escalated into an almighty excercise, and most noteably for you, tell me do you get paid for this?
     
  45. piotrmaciej

    piotrmaciej Private First Class

    sorry and what do you mean am I running all of this from an admistrator account? well yes I am the administrator of this my PC, why is there something which you have seen that is in anyway ominous?:confused
     
  46. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I want to be sure that the fixes and logs are coming from an account that has full privileges, nothing ominous.:)

    No, this is all volunteer.

    Open the C:\ Program Files \ Trend Micro \ HijackThis folder and you will see the hijackthis.exe that is what you need to right click and choose rename. Not the log file.

    Did you remove :
    C:\Program Files\AskTBar?
     
  47. piotrmaciej

    piotrmaciej Private First Class

    Yes that's an affirmative, I am the account administrator with full privelleges, okay I renamed the HijackThis folder as instructed, so what now, run all that which you asked me in the previous message and attach the logs to you once again?
     
  48. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes...run the scans and attach the logs ..I hope you didn't rename the folder ...it was the .exe file inside the folder that needed to be renamed.
     
  49. piotrmaciej

    piotrmaciej Private First Class

    Okay Tim....the logs! tell me the worse:cry
     

    Attached Files:

  50. piotrmaciej

    piotrmaciej Private First Class

    Hello Tims, did you manage to look at my last logs which I sent you?:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds