VNC removal from my PC?

Discussion in 'Malware Help (A Specialist Will Reply)' started by piotrmaciej, Oct 10, 2007.

  1. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes....your logs are clean ....are you still getting the pop up about winvnc? What other problems are you having?
     
  2. piotrmaciej

    piotrmaciej Private First Class

    Hello Tim, my logs are clean you say, yet the vnc issue is still with me? and also can you tell me I purchased 'Registry Mechanic' and keep running scans and I keep getting the same problematic answers that I have 5 problems in 5 different locations, I'd like to send you the scan but alas in this program I do not see the option to save a log? when I print my screenshot and save to desktop, the file size exceeds the permitted attachment to Major Geeks.com:cry, so how on earth may I post the findings of the registry scan?
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you been doing registry repairs?

    Run CCleaner ....both the cleaner and the "issues' ---> save the backup when prompted!

    Tell me if it finds and deletes those items ...
     
  4. piotrmaciej

    piotrmaciej Private First Class

    Hello Tim, ran bitdefender this morning, and it would appear I am infected? so what the heck is going on, the last logs I sent you were determined as being 'free' from any infections:confused, CC Cleaner, where in there is an opton to save/export log? this just goes on and on, and this infernal 'VNC' pop up window which my current anti virus & anti spyware protection are unable to delete, and it is this anti spyware that is telling me 'unable to remove common components vnc'?:(
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    BitDefender removed one of your email messages:
    Outlook Express\WIADOMOSCI.dbx=>(message 2536)
    the rest is in your system restore files ---> which we ask you to toggle (turn off, reboot and then turn back on) when we are finished.
    There was nothing else found.

    Please tell me the "exact" path that the message you get refers to....I beleive we tried to do this much earlier, but possibly your anti-virus or anti-spyware programs blocked the fix.
     
  6. piotrmaciej

    piotrmaciej Private First Class

    Hello Tim,

    this is exactly the message I receive in the pop up window re this 'VNC' problem!

    Anti Spyware failed to delete: VNC commoncomponents, to learn more visit our spyware centre(which I do and it returns a negative feeback that they cannot comment on this problem)

    Spyware item location: hkey_local_machine_\system\currentcontrolset\enum\root\legacy_winvnc

    and also just ran a bitdefender scan on my c drive and it tells me that I have a virus? 'infected with genericpeed eml 39f05619' so is this correct or not? as your prognosis idicated that there were no further roblems found:confused:cry
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Turn off all of your anti-virus and anti-spyware programs.
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:
    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Attach a new log from:
    Avenger

    Re-enable both the anti-virus and anti-spyware programs.
    Tell me how the above ran...if you had any errors.

    It's very possible to find new viruses depending on your surfing habits or p2P programs .....which is why it is good to periodically do online scans.

    When I said you were clean ....you were ....what have you done since then? Did Bitdefender remove what it found?
     
  8. piotrmaciej

    piotrmaciej Private First Class

    No, I regret to inform you still here!!! the VNC pop window thing, did all that which you said, shut down all the spyware and anti virus software. I attach the log from Avenger, coincidentally when the PC booted a black screen window popped up will all manner of errors, I am also enclosing the said file in zip, what now pray tell?
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Start / run / type "regedit" without quotes...
    now expand hkey_local_machine_\
    Then expand system
    Then expand currentcontrolset
    then expand enum
    then expand root
    then find legacy_winvnc
    right click it and delete it.
     
  10. piotrmaciej

    piotrmaciej Private First Class

    Nope Tim!!! will not allow me to delete? crazy or what? enclosed for you to see the screenshot:cry Also whilst you are at it can you take a look at the log that Registry Mechanic found for these issues?? I do not even have this 'Bear Share' program any more???:cry
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Start / run / type "services.msc" without quotes and seek the "VNC Server ...is it there and if so is it set to disable? Stop it first.

    run the regedit.exe, seek & remove these two key if there:
    HKCU\Software\ORL
    HKLM\Software\ORL
    The while still in regedit ...search for VNC ...delete all of it.
    If none of this works ....then you should try reinstalling VNC and then use add/remove to uninstall (making sure the program is not currently running first).

    And yes...you can safely remove the items in Registry Mechanic....(though your screen shots are difficult to read).
     
  12. piotrmaciej

    piotrmaciej Private First Class

    This most recent instruction returned no results at all! HKCU & HKLM keys are nowhere to be found. Why is it that the command 'delete' in Legacy winvnc is not being accepted? what other way, if another way exists of manually removing these persistant 'blighters'!! As for me reinstalling VNC, this is not possible, the friend of mine who installed it is out of the country, and I do not know when he'll be back? is this a program which is readily available from download?
     
  13. piotrmaciej

    piotrmaciej Private First Class

    c:\program files\bearshare applications\bearshare\bearshare.exe this is the path I keep getting as being on my PC, yet I do not have this software installed? get rid, how?
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Would not Registry mechanic allow you to remove these items?

    As to the VNC ...go back into the registry and right click the legacy_VNc and choose permissions ..add your user and give full permission ..then delete it.

    VNC is a freeware program that you can download here:
    http://www.majorgeeks.com/UltrVNC_d4143.html
     
  15. piotrmaciej

    piotrmaciej Private First Class

    Re: recurring issue 'Tray App'??

    Could someone please help? everytime I boot my PC I get these windows popping up as in the screenshot which I took, could anyone tell me what the heck they relate to? and how I may remove them from appearing? Thanks,
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I couldn't read the screen shot ...tell me what each window says.

    You may wish to use a Startup Manager

    This will tell me what all is trying to run at startup ....please tell me the contents of that also.
     
  17. piotrmaciej

    piotrmaciej Private First Class

    Registry

    Hello Tim, and anyone else for that matter, I managed to solve that last problem I had, now I am faced with a new one, maybe you or someone can help, I once had installed on my pc 'Bearshare' I removed it or so I thought, Registry Mechanic scan keeps telling me that I have 3 file extensions which it cannot repair, meaning presumeably to delete them? can you offer me a solution? I enclose the log from registry Mechanic.:cry
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Is this the file that you want removed:
    c:\program files\bearshare applications\bearshare\bearshare.exe

    If that is the file, use Avenger to remove it: (add the full path if there are others)
    Turn off all of your anti-virus and anti-spyware programs.
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:
    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Attach a new log from:
    Avenger

    Re-enable both the anti-virus and anti-spyware programs.
    Tell me how the above ran...if you had any errors.
     
  19. piotrmaciej

    piotrmaciej Private First Class

    Did all that which you said and still a problem!! Please read below, as I am unable to attach the log file in the normal manner for some reason!

    Logfile of The Avenger version 1, by Swandog46
    Running from registry key:
    \Registry\Machine\System\CurrentControlSet\Services\mulbacpk

    *******************

    Script file located at: \??\C:\Documents and Settings\ldfukymv.txt
    Script file opened successfully.

    Script file read successfully

    Backups directory opened successfully at C:\Avenger

    *******************

    Beginning to process script file:



    Could not open file c:\program files\bearshare applications\bearshare\bearshare.exe for deletion
    Deletion of file c:\program files\bearshare applications\bearshare\bearshare.exe failed!

    Could not process line:
    c:\program files\bearshare applications\bearshare\bearshare.exe
    Status: 0xc000003a


    Completed script processing.

    *******************

    Finished! Terminate.
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Right click the file / properties / look in the security tab...make sure your user account has all the boxes checked.
     
  21. piotrmaciej

    piotrmaciej Private First Class

    Right click the file / properties / look in the security tab...make sure your user account has all the boxes checked.??? sorry Tim kindly elaborate what file? Registry Mechanic is finding these errors for me re BEARSHARE!
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That would be the folder --> bearshare and all that is in that folder.
     
  23. piotrmaciej

    piotrmaciej Private First Class

    Re: Bearshare

    Tim, I physically have searched my PC for this blasted Bearshare and cannot find it anywhere??? so how in the heck is registry mechanic locating these missing files is quite beyond me??? I now see what you mean but I cannot do that which you say as there is no such file for me to go into!!!
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Attach a new GetRUnKeys log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds