Dodgy use of WinVNC?

N

nath

Guest
Howdy

I was asked to look at a problem on a clients laptop, it was coming up with winvnc error messages every time he switched it on. I checked the usual places (startup/run in the registry) but nothing about vnc there. I then looked at processes in task man, and I couldn't see anything about vnc. I closed the vnc window and something disappeared. Repeated several times and found that the thing disappearing was explorer.exe .. there just happened to be two of them. "uh oh" I thought.

Did a search for explorer.exe and found one (with the normal winvnc icon) in C:\winnt\fonts "uh oh some more) I thought. Looked in the run registry settings, found it there, removed the entry. I have no doubt whatsoever that this was maliciously placed, as it was so well hidden.. but has anyone ever heard of/seen this sort of thing before? Had a quick google, but couldn't find anything.

TIA
 
J

Jonty

Guest
Hi nath

Apparently, WinVNC is a legitimate remote access tool. Unfortunately, a few trojans available utilise it to create a 'backdoor' into a person's computer. The 'Backdoor Components' section at the bottom of this virus page mentions something which soundssimilar to the problems you encountered. This McAfee page may also be of some use.

To be honest, I've never come across this before, so I'm sorry I cannot be of more assistance.

Kind Regards

Edit ~ Too late was the cry :D
 

Users who are viewing this thread

Top Bottom