How to Remove “vncviewer.exe”

What is vncviewer.exe?

vncviewer.exe is a legitimate process file popularly known as RSS Server. It belongs to UltraVNC VNCViewer application developed by UltraVNC. It is located in C:\Program Files by default. Malware programmers create files with virus scripts and name them after vncviewer.exe with an intention to spread virus on the internet.

Affected Platform: Windows OS

How to check if your computer is infected with vncviewer.exe malware?

Keep an eye for the following symptoms to see if your PC is infected with vncviewer.exe malware:

  • Internet connection fluctuates
  • vncviewer.exe takes too much CPU space
  • PC slows down significantly
  • Browser automatically redirects to some irrelevant websites
  • Unsolicited ads and popups starts appearing
  • Screen freezes constantly

Take the following steps to diagnose your PC for possible vncviewer.exe malware attack:

Step 1: Simultaneously press CTRL+ALT+DEL keys to open Task Manager.

Step 2: If you notice the file located outside C:\Program Files, then you should run an antivirus scan to get rid of the malware.

How to remove vncviewer.exe malware from system using Comodo Antivirus?

Step 1: Download the award-winning Free Antivirus.

Step 2: Installation configuration frames will be displayed. Select the configuration you would like to apply.

Step 3: After network detection is complete, press “Close” button for a scan window.

Step 4: Restart your PC.

Step 5: It will take some time for the Comodo Internet Security to update the antivirus.

Step 6: Proceed with a quick scan that automatically begins after the update.

Step 7: If threats are found during the scanning, you will be prompted with an alert screen.

Step 8: Comodo Antivirus will remove the vncviewer.exe virus from your computer including all other malwares!

6

Malware Entries

First Seen: 17 September 2008 at 7:20 pm
No. Company File Type SHA1 MD5 Malware
Name
Digitally
Signed
File
Version
Product
Version
Submitted
From
Malware Behavior
1 UltraVNC Executable 7693e6efcbd3e645
afa89c8f62755160
98553412
95973838df1345ab
4a28f346443f1cf3
ApplicUnsaf.
Win32.Remote
Admin.WinVNC
.1102
No 1.1.0.2 1.1.0.2 China N/A
2 AT&T Laboratories Cambridge Executable 11c09c99487dff74
96c6de4875306c0c
72123ccd
396f4e891335fafb
555c298f4534e252
Unclassified
Malware
No 3, 3, 3, 2 3, 3, 3, 2 104.236.253.252/32 N/A
3 UltraVNC Executable 7693e6efcbd3e645
afa89c8f62755160
98553412
95973838df1345ab
4a28f346443f1cf3
ApplicUnsaf.
Win32.Remote
Admin.WinVNC
.1102
No 1.1.0.2 1.1.0.2 United States N/A
4 RealVNC Ltd. Executable 30820823654f3127
480e4e6d9f51caf0
72d59ec2
2f045bfd51c2886b
e43cc676708a17c7
ApplicUnsaf.
Win32.Remote
Admin.WinVNC
.~IE
Yes 4.1.2 4.1.2 United States N/A
Display 4 items per page
  • 4 items per page
  • 8 items per page
  • 16 items per page
  • 32 items per page
27

Safe Entries

First Seen: 16 July 2008 at 8:05 am
No. Company File Type SHA1 MD5 Digitally
Signed
File
Version
Product
Version
Submitted
From
1 TightVNC Group Executable 31acd0f7990413df
d14cd2bc9a756e0a
95f73cbb
f2f8f2d266481550
aa5eba0d48076acd
No 1, 3, 10,
0
1, 3, 10,
0
United States
2 UltraVNC Executable 8545b642680a2fef
4d902d2d88216b90
8edbc6e4
ffe91616220507ee
934858b024f87a09
Yes 1.1.2 1.1.2 United States
3 UltraVNC Executable 5c4f35f53a3e32ed
ad0efbd678cda76f
7df6d75c
d5ff2348a1b52af1
93fb7ba1ad88eb7d
Yes 1.1.9.5 1.1.9.5 United States
4 UltraVNC Executable bc5adad4b4205398
a280d14d1d1a7011
173c493b
ed8734e721c733e5
135ef9e784d81111
Yes 1.1.9.0 1.1.9.0 United States
Display 4 items per page
  • 4 items per page
  • 8 items per page
  • 16 items per page
  • 32 items per page
 
Exclusive Offer
Get Free Endpoint Protection
Get Advanced
Endpoint
Protection

Award-Winning Security to Protect Your Clients from Cyber Attacks

Comodo Internet Security Pro

Free Antivirus protection from hackers! Get the ultimate Antivirus solution to keep your PC clean and to remove viruses from a slow or infected PC. Improve the PC performance at home or use it on-the-go!

Get Comodo Internet Security Comodo Internet Security