Malware

RemoteAdmin.Win32.WinVNC.gc removal guide

Malware Removal

The RemoteAdmin.Win32.WinVNC.gc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RemoteAdmin.Win32.WinVNC.gc virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Starts servers listening on 0.0.0.0:5900
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine RemoteAdmin.Win32.WinVNC.gc?


File Info:

crc32: 37BBBA96
md5: 0c200772b65defa616f825e7d1403a04
name: explorerclient4.exe
sha1: cea9112043efbe91d93a9feb5d02c10ce175eeff
sha256: c567d4c8fbb468c3f7fbf9eb60269d78cd41e646fbe8d1968795841495bcd86c
sha512: 7bb81465ad8bb780b9498648390cb4219641939ce3d42fb614d85ffc6d9c07351dbba6566770aac223815f1cbde4cedc8fa4223ecca0ea56a3e1ca01eb02a8e1
ssdeep: 98304:1YRiR6OLVopnPH/R9f53Bo60nxyViSDdlDU84hYSI/IiWcKhTJbb:1YRiR6I0XRx53SbKigUP+/I/zhlb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion: 4
CompanyName: Softvision
ProductName: Explorer Client
ProductVersion: 4
FileDescription:
Translation: 0x0409 0x04e4

RemoteAdmin.Win32.WinVNC.gc also known as:

Kasperskynot-a-virus:RemoteAdmin.Win32.WinVNC.gc
AlibabaRiskWare:Win32/WinVNC.c4d327b1
NANO-AntivirusTrojan.Win32.RemoteAdmin.ddpcrw
ZoneAlarmnot-a-virus:RemoteAdmin.Win32.WinVNC.gc
eGambitnot-a-virus:Generic.Malware
Qihoo-360Win32/Virus.RemoteAdmin.ca3

How to remove RemoteAdmin.Win32.WinVNC.gc?

RemoteAdmin.Win32.WinVNC.gc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment