Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > General Computer Security
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


General Computer Security Get Help With System Security - This forum is not for malware removal assistance. For malware removal assistance, read the sticky topic at the top of the Virus/Trojan/Spyware Help forum, or the "First Steps" link at the top right of each page.

Reply
 
LinkBack Thread Tools
Old 02-03-2007, 11:35 AM   #1 (permalink)
Moderator Hardware Team
 
Done_Fishin's Avatar
 
Join Date: Oct 2006
Location: Brit living in Greece
Posts: 7,526
OS: WinME, WinXP Pro SP3, Win7 Beta, Ubuntu 9.04 & Netbook Remix & CD2USB, Mepis 6.5, Fedora 10

My System

Info Please - Infected UBCD?

I ran Zonealarms "spyware" check and it brought up some points that I would like to clear up.
Inside the folders that I have been using to create UBCD in English & Greek I have been givena warning about a program called TIGHTVNC 1.2.9 saying that I should quarantine it because it says it's a RAT!

Since I have been doing various stuff on a couple of different drives & partitions It hads suggested that I quarantine the following:
What do you guys think .. is it genuine or one of those situations where a diagnosis program is highlighted because of certain context or performance!
I have a program which has been highlighted by another program because it has picked out my passwords for sites (ones that I had long forgotten but are stored on the PC)

The files below seem to be the same ones over and over but in different guises that I was setting up for my diagnostics CD.

File: N:\WinXP_SP2 & BART_UBCD4\BartPE\PROGRAMS\ultravnc\winvnc.exe
File: N:\WinXP_SP2 & BART_UBCD4\BartPE_GK\PROGRAMS\ultravnc\winvnc.exe
File: P:\WinXP_SP2 & BART_UBCD4\BartPE\PROGRAMS\ultravnc\winvnc.exe
File: P:\WinXP_SP2 & BART_UBCD4\BartPE_GK\PROGRAMS\ultravnc\winvnc.exe
File: P:\WinXP_SP2 & BART_UBCD4\UBCD_CD\BartPE\PROGRAMS\ultravnc\winvnc.exe
File: P:\WinXP_SP2 & BART_UBCD4\UBCD_CD\BartPE_GK\PROGRAMS\ultravnc\winvnc.exe
File: P:\WinXP_SP2 & BART_UBCD4\UBCD_CD\plugin\Network\ultravnc\files\winvnc.exe
File: S:\Computer stuff\FM1_D\PC Diagnostics\UBCD_CD\plugin\Network\ultravnc\files\winvnc.exe
File: N:\WinXP_SP2 & BART_UBCD4\BartPE\PROGRAMS\ultravnc\vncviewer.exe
File: N:\WinXP_SP2 & BART_UBCD4\BartPE_GK\PROGRAMS\ultravnc\vncviewer.exe
File: P:\WinXP_SP2 & BART_UBCD4\BartPE\PROGRAMS\ultravnc\vncviewer.exe
File: P:\WinXP_SP2 & BART_UBCD4\BartPE_GK\PROGRAMS\ultravnc\vncviewer.exe
File: P:\WinXP_SP2 & BART_UBCD4\UBCD_CD\BartPE\PROGRAMS\ultravnc\vncviewer.exe
File: P:\WinXP_SP2 & BART_UBCD4\UBCD_CD\BartPE_GK\PROGRAMS\ultravnc\vncviewer.exe
File: P:\WinXP_SP2 & BART_UBCD4\UBCD_CD\plugin\Network\ultravnc\files\vncviewer.exe
File: S:\Computer stuff\FM1_D\PC Diagnostics\UBCD_CD\plugin\Network\ultravnc\files\vncviewer.exe
File: N:\WinXP_SP2 & BART_UBCD4\BartPE\PROGRAMS\ultravnc\vnchooks.dll
File: N:\WinXP_SP2 & BART_UBCD4\BartPE_GK\PROGRAMS\ultravnc\vnchooks.dll
File: P:\WinXP_SP2 & BART_UBCD4\BartPE\PROGRAMS\ultravnc\vnchooks.dll
File: P:\WinXP_SP2 & BART_UBCD4\BartPE_GK\PROGRAMS\ultravnc\vnchooks.dll
File: P:\WinXP_SP2 & BART_UBCD4\UBCD_CD\BartPE\PROGRAMS\ultravnc\vnchooks.dll
File: P:\WinXP_SP2 & BART_UBCD4\UBCD_CD\BartPE_GK\PROGRAMS\ultravnc\vnchooks.dll
File: P:\WinXP_SP2 & BART_UBCD4\UBCD_CD\plugin\Network\ultravnc\files\vnchooks.dll
File: S:\Computer stuff\FM1_D\PC Diagnostics\UBCD_CD\plugin\Network\ultravnc\files\vnchooks.dll
File: N:\WinXP_SP2 & BART_UBCD4\BartPE\PROGRAMS\ultravnc\ldapauth.dll
File: N:\WinXP_SP2 & BART_UBCD4\BartPE_GK\PROGRAMS\ultravnc\ldapauth.dll
File: P:\WinXP_SP2 & BART_UBCD4\BartPE\PROGRAMS\ultravnc\ldapauth.dll
File: P:\WinXP_SP2 & BART_UBCD4\BartPE_GK\PROGRAMS\ultravnc\ldapauth.dll
File: P:\WinXP_SP2 & BART_UBCD4\UBCD_CD\BartPE\PROGRAMS\ultravnc\ldapauth.dll
File: P:\WinXP_SP2 & BART_UBCD4\UBCD_CD\BartPE_GK\PROGRAMS\ultravnc\ldapauth.dll
File: P:\WinXP_SP2 & BART_UBCD4\UBCD_CD\plugin\Network\ultravnc\files\ldapauth.dll
File: S:\Computer stuff\FM1_D\PC Diagnostics\UBCD_CD\plugin\Network\ultravnc\files\ldapauth.dll
File: N:\WinXP_SP2 & BART_UBCD4\BartPE\PROGRAMS\ultravnc\workgrpdomnt4.dll
File: N:\WinXP_SP2 & BART_UBCD4\BartPE_GK\PROGRAMS\ultravnc\workgrpdomnt4.dll
File: P:\WinXP_SP2 & BART_UBCD4\BartPE\PROGRAMS\ultravnc\workgrpdomnt4.dll
File: P:\WinXP_SP2 & BART_UBCD4\BartPE_GK\PROGRAMS\ultravnc\workgrpdomnt4.dll
File: P:\WinXP_SP2 & BART_UBCD4\UBCD_CD\BartPE\PROGRAMS\ultravnc\workgrpdomnt4.dll
File: P:\WinXP_SP2 & BART_UBCD4\UBCD_CD\BartPE_GK\PROGRAMS\ultravnc\workgrpdomnt4.dll
File: P:\WinXP_SP2 & BART_UBCD4\UBCD_CD\plugin\Network\ultravnc\files\workgrpdomnt4.dll
File: S:\Computer stuff\FM1_D\PC Diagnostics\UBCD_CD\plugin\Network\ultravnc\files\workgrpdomnt4.dll
File: N:\WinXP_SP2 & BART_UBCD4\BartPE\PROGRAMS\ultravnc\authadmin.dll
File: N:\WinXP_SP2 & BART_UBCD4\BartPE_GK\PROGRAMS\ultravnc\authadmin.dll
File: P:\WinXP_SP2 & BART_UBCD4\BartPE\PROGRAMS\ultravnc\authadmin.dll
File: P:\WinXP_SP2 & BART_UBCD4\BartPE_GK\PROGRAMS\ultravnc\authadmin.dll
File: P:\WinXP_SP2 & BART_UBCD4\UBCD_CD\BartPE\PROGRAMS\ultravnc\authadmin.dll
File: P:\WinXP_SP2 & BART_UBCD4\UBCD_CD\BartPE_GK\PROGRAMS\ultravnc\authadmin.dll
File: P:\WinXP_SP2 & BART_UBCD4\UBCD_CD\plugin\Network\ultravnc\files\authadmin.dll
File: S:\Computer stuff\FM1_D\PC Diagnostics\UBCD_CD\plugin\Network\ultravnc\files\authadmin.dll
File: N:\WinXP_SP2 & BART_UBCD4\BartPE\PROGRAMS\ultravnc\logging.dll
File: N:\WinXP_SP2 & BART_UBCD4\BartPE_GK\PROGRAMS\ultravnc\logging.dll
File: P:\WinXP_SP2 & BART_UBCD4\BartPE\PROGRAMS\ultravnc\logging.dll
File: P:\WinXP_SP2 & BART_UBCD4\BartPE_GK\PROGRAMS\ultravnc\logging.dll
File: P:\WinXP_SP2 & BART_UBCD4\UBCD_CD\BartPE\PROGRAMS\ultravnc\logging.dll
File: P:\WinXP_SP2 & BART_UBCD4\UBCD_CD\BartPE_GK\PROGRAMS\ultravnc\logging.dll
File: P:\WinXP_SP2 & BART_UBCD4\UBCD_CD\plugin\Network\ultravnc\files\logging.dll
File: S:\Computer stuff\FM1_D\PC Diagnostics\UBCD_CD\plugin\Network\ultravnc\files\logging.dll
File: N:\WinXP_SP2 & BART_UBCD4\BartPE\PROGRAMS\ultravnc\authSSP.dll
File: N:\WinXP_SP2 & BART_UBCD4\BartPE_GK\PROGRAMS\ultravnc\authSSP.dll
File: P:\WinXP_SP2 & BART_UBCD4\BartPE\PROGRAMS\ultravnc\authSSP.dll
File: P:\WinXP_SP2 & BART_UBCD4\BartPE_GK\PROGRAMS\ultravnc\authSSP.dll
File: P:\WinXP_SP2 & BART_UBCD4\UBCD_CD\BartPE\PROGRAMS\ultravnc\authSSP.dll
File: P:\WinXP_SP2 & BART_UBCD4\UBCD_CD\BartPE_GK\PROGRAMS\ultravnc\authSSP.dll
File: P:\WinXP_SP2 & BART_UBCD4\UBCD_CD\plugin\Network\ultravnc\files\authSSP.dll
File: S:\Computer stuff\FM1_D\PC Diagnostics\UBCD_CD\plugin\Network\ultravnc\files\authSSP.dll
File: N:\WinXP_SP2 & BART_UBCD4\BartPE\PROGRAMS\ultravnc\MSLogonACL.exe
File: N:\WinXP_SP2 & BART_UBCD4\BartPE_GK\PROGRAMS\ultravnc\MSLogonACL.exe
File: P:\WinXP_SP2 & BART_UBCD4\BartPE\PROGRAMS\ultravnc\MSLogonACL.exe
File: P:\WinXP_SP2 & BART_UBCD4\BartPE_GK\PROGRAMS\ultravnc\MSLogonACL.exe
File: P:\WinXP_SP2 & BART_UBCD4\UBCD_CD\BartPE\PROGRAMS\ultravnc\MSLogonACL.exe
File: P:\WinXP_SP2 & BART_UBCD4\UBCD_CD\BartPE_GK\PROGRAMS\ultravnc\MSLogonACL.exe
File: P:\WinXP_SP2 & BART_UBCD4\UBCD_CD\plugin\Network\ultravnc\files\MSLogonACL.exe
__________________
.


.
I'm not old!!
I'm age impaired

..
D_F


I DON'T PLAY GAMES

How to mark your thread as solved



HDD DIAG UTILS

TSF's Photographer's Corner
Done_Fishin is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 02-03-2007, 12:22 PM   #2 (permalink)
Moderator Hardware Team
 
Done_Fishin's Avatar
 
Join Date: Oct 2006
Location: Brit living in Greece
Posts: 7,526
OS: WinME, WinXP Pro SP3, Win7 Beta, Ubuntu 9.04 & Netbook Remix & CD2USB, Mepis 6.5, Fedora 10

My System

I applied the first file to virus total

this is the response I got

Quote:
VirusTotal
VirusTotal is a free file analisys service that works using several antivirus engines.


Select file : DistributeSSL

Enter your email, choose the file to be scanned with multiple antivirus engines and click Send.Menu:
News Hot news in the virus/antivirus sector.
Estadisticas Statistics of VirusTotal procesing.
Virustotal More info about Virustotal.


STATUS: FINISHEDComplete scanning result of "winvnc.exe", received in VirusTotal at 02.03.2007, 19:58:15 (CET).

Antivirus Version Update Result
AntiVir 7.3.1.34 02.03.2007 no virus found
Authentium 4.93.8 02.03.2007 no virus found
Avast 4.7.936.0 02.03.2007 no virus found
AVG 386 02.03.2007 no virus found
BitDefender 7.2 02.03.2007 no virus found
CAT-QuickHeal 9.00 02.03.2007 no virus found
ClamAV devel-20060426 02.03.2007 no virus found
DrWeb 4.33 02.03.2007 no virus found
eSafe 7.0.14.0 02.02.2007 no virus found
eTrust-InoculateIT 30.4.3364 02.02.2007 no virus found
eTrust-Vet 30.3.3366 02.03.2007 no virus found
Ewido 4.0 02.03.2007 no virus found
Fortinet 2.85.0.0 02.03.2007 no virus found
F-Prot 4.2.1.29 02.03.2007 no virus found
Ikarus T3.1.0.31 02.03.2007 no virus found
Kaspersky 4.0.2.24 02.03.2007 no virus found
McAfee 4955 02.02.2007 no virus found
Microsoft 1.2101 02.03.2007 UltraVNC (threat-c)
NOD32v2 2034 02.03.2007 no virus found
Norman 5.80.02 02.02.2007 no virus found
Panda 9.0.0.4 02.03.2007 no virus found
Prevx1 V2 02.03.2007 no virus found
Sophos 4.13.0 02.02.2007 no virus found
Sunbelt 2.2.907.0 02.02.2007 no virus found
Symantec 10 02.03.2007 no virus found
TheHacker 6.0.3.162 02.02.2007 no virus found
UNA 1.83 02.03.2007 no virus found
VBA32 3.11.2 02.03.2007 no virus found
VirusBuster 4.3.19:9 02.03.2007 no virus found


Aditional Information
File size: 974848 bytes
MD5: 665862c03eb975a6d0c0390884cd3e3c
SHA1: 34bd579c186c282289d2e36d90376eaae84fcc9c

VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.
> Go to: Home Contactar En Español
--------------------------------------------------------------------------------
www.virustotal.com :: ©Hispasec Sistemas 2004-06:: e-mail info@virustotal.com
Now just what am I supposed to understand from the fact that ONLY Microsoft considers this file to be a possible virus????
__________________
.


.
I'm not old!!
I'm age impaired

..
D_F


I DON'T PLAY GAMES

How to mark your thread as solved



HDD DIAG UTILS

TSF's Photographer's Corner
Done_Fishin is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 02-03-2007, 12:48 PM   #3 (permalink)
Moderator/ Rangemaster TSF Academy; Analyst, Security Team; Oor Wullie; TSF Surgeon and Resident Comic
 
Glaswegian's Avatar
 
Join Date: Sep 2005
Location: Glasgow
Posts: 25,537
OS: Win XP Pro SP3 / Win 7 Pro

My System

Blog Entries: 10
Hi DF

As you say, it's highlighted because it's function is to allow remote access to a system. Therefore there is a possibility of this being exploited by hackers etc. But of course, all you have there is genuine, so make of that what you will...
__________________
Iain - Defender of the Haggis and all things Scottish.
I don't help by PM - post in the Forums.



PC Safety & Security::PC running a bit slow?::Donate::Photographers Corner
Glaswegian is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 02-03-2007, 01:04 PM   #4 (permalink)
Moderator Hardware Team
 
Done_Fishin's Avatar
 
Join Date: Oct 2006
Location: Brit living in Greece
Posts: 7,526
OS: WinME, WinXP Pro SP3, Win7 Beta, Ubuntu 9.04 & Netbook Remix & CD2USB, Mepis 6.5, Fedora 10

My System

Thanks to another link raised by GG I have been doing some self help by checking out one of each of these similar files to the same virus scan engine.
So far I have scanned another 6 files (DLL's) & found that NONE are suspected of being infected. Not even by M$ !! The only conclusion that I can come up with is that someone wants to blacken the reputation of certain "EXEcutable" files. I would hazard a guess that I will find none yet a reputable company has now told me that these files are suspect .. where do they get their info from?
__________________
.


.
I'm not old!!
I'm age impaired

..
D_F


I DON'T PLAY GAMES

How to mark your thread as solved



HDD DIAG UTILS

TSF's Photographer's Corner
Done_Fishin is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 02-03-2007, 01:50 PM   #5 (permalink)
Moderator Hardware Team
 
Done_Fishin's Avatar
 
Join Date: Oct 2006
Location: Brit living in Greece
Posts: 7,526
OS: WinME, WinXP Pro SP3, Win7 Beta, Ubuntu 9.04 & Netbook Remix & CD2USB, Mepis 6.5, Fedora 10

My System

Confirmed that only one file was suspected of being a virus & ONLY by M$. The rest are considered to be virus free.
__________________
.


.
I'm not old!!
I'm age impaired

..
D_F


I DON'T PLAY GAMES

How to mark your thread as solved



HDD DIAG UTILS

TSF's Photographer's Corner
Done_Fishin is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 02-03-2007, 03:49 PM   #6 (permalink)
Roaming To Help
 
Join Date: Nov 2006
Posts: 5,642
OS: Many


Did WipeCMOS not give you a hacker alarm?

Usually it does but its a false positive.

On a side, if you haven't already take a look at UBCD4WIN which may be of use to you.
Kalim is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 02-04-2007, 12:45 AM   #7 (permalink)
Moderator Hardware Team
 
Done_Fishin's Avatar
 
Join Date: Oct 2006
Location: Brit living in Greece
Posts: 7,526
OS: WinME, WinXP Pro SP3, Win7 Beta, Ubuntu 9.04 & Netbook Remix & CD2USB, Mepis 6.5, Fedora 10

My System

THanks Kalim, I believe I already grabbed that download too .. one just can't have too many diagnostics & boot programs
__________________
.


.
I'm not old!!
I'm age impaired

..
D_F


I DON'T PLAY GAMES

How to mark your thread as solved



HDD DIAG UTILS

TSF's Photographer's Corner
Done_Fishin is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 09:42 AM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85