vnc-4_1_1-x86_win32.exe

RealVNC Ltd

The application vnc-4_1_1-x86_win32.exe, “VNC Setup ” by RealVNC has been detected as a potentially unwanted program by 7 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. This file is typically installed with the program Trend Micro Worry-Free Business Security Advanced by Trend Micro Inc.. The file has been seen being downloaded from filehippo.com and multiple other hosts.
Publisher:
RealVNC Ltd.   (signed by RealVNC Ltd)

Description:
VNC Setup

MD5:
3538936fabb7dd3ca6d7b4e373497d8b

SHA-1:
a2c4dce78d7e2762d6a15f83139ea2da7325773c

SHA-256:
dd61085f6d4dea1844dea1cceef08ee219467544695e0ddaa2977b174e93f139

Scanner detections:
7 / 68

Status:
Potentially unwanted

Analysis date:
4/20/2024 5:11:05 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:PUP-gen [PUP]
2014.9-140703

Comodo Security
ApplicUnsaf.Win32.RemoteAdmin.WinVNC.4
18716

Dr.Web
Program.RemoteAdmin
9.0.1.0184

Kaspersky
not-a-virus:RemoteAdmin.Win32.WinVNC
14.0.0.3620

NANO AntiVirus
Riskware.Win32.WinVNC.ifhd
0.28.0.60475

ViRobot
RemoteApp.WinVNC.724960
2011.4.7.4223

XVirus List
Win32.Detected
2.7.3

File size:
708 KB (724,960 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Signed by:

Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
9/17/2004 7:10:00 AM

Valid to:
9/17/2005 7:10:00 AM

Subject:
CN=RealVNC Ltd, OU=Software, O=RealVNC Ltd, L=Cambridge, S=Cambridgeshire, C=UK

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
207014

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:zaimQfkLrLxcgACJHx6KBTCFnlwu2z6yXkD09fFM9jW3OApM768qRAAg+vATvp5D:2iXfkLH5ACJR6KBTCzwu2myYINSCeAFy

Entry address:
0x94E4

Entry point:
55, 8B, EC, 83, C4, D4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, E4, E8, E2, 9B, FF, FF, E8, 8D, AE, FF, FF, E8, 80, D0, FF, FF, E8, C7, D0, FF, FF, E8, DA, F5, FF, FF, BE, C4, BD, 40, 00, 33, C0, 55, 68, C0, 9B, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 76, 9B, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, B0, 40, 00, E8, EF, FE, FF, FF, E8, AE, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 40, D5, FF, FF, 8B, 55, F0, B8, B8, BD, 40, 00, E8, 93, 9C, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, B8, BD, 40, 00, B2, 01, B8...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
35.5 KB (36,352 bytes)

The file vnc-4_1_1-x86_win32.exe has been discovered within the following program.

Publisher's description - “Trend Micro™ Worry-Free™ Business Security Services provides enterprise-class protection for Windows, Mac, and Android devices from a secure, centralized, web-based management console. You can manage all of your devices from anywhere and know that your data is safe.”
www.trendmicro.com/us/small-business/product-security/worry-free-services/index.html
About 2% of users remove it
 
Powered by Should I Remove It?

The file vnc-4_1_1-x86_win32.exe has been seen being distributed by the following 13 URLs.

http://filehippo.com/it/download/file/.../

http://filehippo.com/download/file/.../

http://gsf-cf.softonic.com/a2c/4dc/.../file?SD_used=0&channel=WEB&fdh=no&id_file=6860&instance=softonic_en&type=PROGRAM&Expires=1474579212&Signature=XdiQfKnFN5cPQPJyWiyGnyGto4YmeM1M1abkxusm385Ah~8RN6rVASe53-c7vqO3P2qIyQrcQ62iugegi22QrZ199zh3cNQF05NRFEIArExhIvxF3laustc6ngbd8Bw23mvE1lPdQ34O9kCdDMH-je2n1~A~~iavkGxOojjj1-A_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=vnc-4_1_1-x86_win32.exe

http://gsf-cf.softonic.com/a2c/4dc/.../file?SD_used=0&channel=WEB&fdh=no&id_file=6860&instance=softonic_en&type=PROGRAM&Expires=1460942780&Signature=VLBtIMvV6aOm8ht6W8abFfNj5RVsDJiymdpqq1udyfyr8XzdwNP-xejRn4xVnubcNMPm9UQZ3jPAvKdCLkfil8Wy~mE38QnQpVQMUl8zQWPWZEK4EpAJamhdcAWZvpVdsgY2h925ZJFyxLWyYZVj4DwCcIykwvqYRoqemwNl4Uc_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=vnc-4_1_1-x86_win32.exe

http://filehippo.com/download/file/.../

http://software.oldversion.com/download.php?f=YTo1OntzOjQ6InRpbWUiO2k6MTQ0MDY4MTY3NjtzOjI6ImlkIjtpOjE1OTQ2O3M6NDoiZmlsZSI7czozNzoicmVhbHZuYy00LTEtMS12bmMtNF8xXzEteDg2X3dpbjMyLmV4ZSI7czozOiJ1cmwiO3M6NTA6Imh0dHA6Ly93d3cub2xkdmVyc2lvbi5jb20uZGUvd2luZG93cy9yZWFsdm5jLTQtMS0xIjtzOjQ6InBhc3MiO3M6MzI6ImQ2MDliNTMwYTAzZWE3MDhlZjFkMzJhMDc0OWM2ZDBiIjt9

Remove vnc-4_1_1-x86_win32.exe - Powered by Reason Core Security