Malware

What is “RemoteAdmin.Win32.WinVNC.1370”?

Malware Removal

The RemoteAdmin.Win32.WinVNC.1370 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RemoteAdmin.Win32.WinVNC.1370 virus can do?

  • Unconventionial language used in binary resources: Lithuanian
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine RemoteAdmin.Win32.WinVNC.1370?


File Info:

crc32: D15D27A3
md5: 268dbb5b80266c4b07b527f5479aa6c9
name: nv_audena.exe
sha1: fed9f948b2f95450a6ad360d0a2e55baf7d1aded
sha256: b2d2e5bf7bf9581f394076c049a635e9987ab3aeb2fdfeb5ae0bb532727a57e8
sha512: 9d9af97e2b8897c7443da2cbf2d3e93af49bdbf2813daed470ba87cf21c299df0dfd8c2b896df3c65981ebc74dad1d2253b764f68aa05b2e021c8879d40e702b
ssdeep: 6144:g3fBs+arG2NIrpZC2apuEOleaoo0JgURItZb:0TpUtdY50JgURq
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

RemoteAdmin.Win32.WinVNC.1370 also known as:

FireEyeGeneric.mg.268dbb5b80266c4b
Qihoo-360Win32/Backdoor.fe1
McAfeeArtemis!268DBB5B8026
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
Cybereasonmalicious.8b2f95
F-ProtW32/HackTool.BPT
TrendMicro-HouseCallTROJ_GEN.R057H0CCT20
Kasperskynot-a-virus:RemoteAdmin.Win32.WinVNC.1370
AegisLabRiskware.Win32.WinVNC.1!c
RisingMalware.Heuristic!ET#84% (C64:YzY0OjrHjSXmFejN)
McAfee-GW-EditionArtemis!PUP
SentinelOneDFI – Suspicious PE
Trapminemalicious.moderate.ml.score
APEXMalicious
CyrenW32/Tool.OUNP-7901
WebrootW32.Gen.Bt
Antiy-AVLTrojan[RemoteAdmin]/Win32.WinVNC
Endgamemalicious (high confidence)
ZoneAlarmnot-a-virus:RemoteAdmin.Win32.WinVNC.1370
MicrosoftTrojan:Win32/Wacatac.C!ml
YandexRiskware.RemoteAdmin!
eGambitUnsafe.AI_Score_99%
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove RemoteAdmin.Win32.WinVNC.1370?

RemoteAdmin.Win32.WinVNC.1370 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment