Had EvilVNC Beta - Now Clean?

Discussion in 'Malware Help (A Specialist Will Reply)' started by albionmoon, Jan 10, 2007.

  1. albionmoon

    albionmoon Private E-2

    Hi -

    I have a P4 2.8GHz PC with 1.49GB of RAM running XP SP2 and Panda Antivirus 2007. The other day I noticed a strange pop up every so often coming from my taskbar - but it appears up and down so quickly I can't read it. I thought - oh, no - virus. So I scanned with Panda - nothing. Then I scanned with XoftSpySE and it turned up 5 instances of EvilVNC Beta which sounded pretty nasty.

    I had XoftSpySE get rid of those instances - rebooted and checked again with XoftSPYSE and it came back clean. I still get those quick pop-ups though, so I'm not sure if I'm clean - or if it's even related. Can you help me figure it out?

    I went through all the prep steps according to the new Chaslang sticky post and I'm attaching the log files. However - when I did the bitdefender in safe mode IE crashed right when it finished (I got an error that read IE has encountered a problem with an add on and needs to close - that add on was oscan81.ocx, described as the bitdefender online scanner). Since the scan didn't find anything, I didn't want to re-run it for two more hours.

    Then the panda active scan - it also turned up nothing, but there was no place I could see where it said "save a report". As it finished, a pop up appeared that asked for a "Profile" with a drop down menu that started with "Outlook". Since I didn't know what the profile popup meant, I closed it. The scan then ended, but like I said, there was no place to save a report.

    So, I apologize that I don't have those two scans, but I have everything else. I'd really appreciate it if you could let me know what you think. Also, let me know if my HJT log will help you. Thanks -
    Albionmoon
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have a log from XoftSpySE? I tend to doubt this is correct. You probably had WinVNC or UltraVNC (both legit programs if you installed them) on your PC at one time and it may have found remnants of these. It falsely detects them as EvilVNC Beta all the time which they should learn to fix. Did you purchase XoftSpy?


    I also see Yahoo Antispyware and Windows Defender installed. Do you use Yahoo Antispyware and keep it updated? I think they use Pest Patrol as their antispyware package.

    Uninstall the CounterSpy trial now, we are finished with it and you have too many realtime blocking tools installed now. The delete the below two folder which its uninstall will not remove:
    C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software


    Is XoftSpySE a realtime blocker too or is it just an after the fact scanner?

    I'm not seeing and malware based on what you posted. I need more logs. How about a HijackThis log.

    You are out of date with your Sun Java and FireFox updates!

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6
    Mozilla Firefox (1.5.0.9)

    Make sure you reboot after uninstalling the above!


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox
     
  3. albionmoon

    albionmoon Private E-2

    Chaslang - Thanks so much for looking into my logs and getting back to me.

    Do you have a log from XoftSpySE? ... Did you purchase XoftSpy?

    Unfortunately, I don't have a log from XoftSpySE - but I wrote down the results when the EvilVNC came up:

    software\orl\winvnc3\locksetting
    software\orl\winvnc3\lquerysetting
    software\orl\winvnc3\socketconnect
    software\orl\winvnc3\querytimeout
    software\orl\winvnc3\idletimeout

    So it looks like you were right that XoftSpy was probably getting a false positive from an old instance of winvnc. I wish I had consulted you first since yeah, I did buy the XoftSpySE to get rid of those instances. Drag.


    I also see Yahoo Antispyware and Windows Defender installed. Do you use Yahoo Antispyware and keep it updated? I think they use Pest Patrol as their antispyware package.

    I don't really use the Yahoo AntiSpyware - I think it installed once with the yahoo toolbar. Should I get rid of it?


    Is XoftSpySE a realtime blocker too or is it just an after the fact scanner?

    Just a scanner as far as I can tell.

    I'm not seeing and malware based on what you posted. I need more logs. How about a HijackThis log.

    I'm attaching a HJT log from yesterday.

    You are out of date with your Sun Java and FireFox updates!

    Thanks for noticing - I have updated them. And thanks again for all the help. If you see something creepy in the HJT logs, let me know.
    -albionmoon
     

    Attached Files:

  4. albionmoon

    albionmoon Private E-2

    Figured I'd also put a HJT log from today in there since things have changed. Thanks.
    albionmoon
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well I see that XoftSpy still has the same old false positive issues that cause it to be added to the rogue tool list at one time. I'm not sure why they removed it from the list.

    How did you manage to get the below driver for your Epson printer loading three times?[quote]
    O4 - HKLM\..\Run: [Auto EPSON Stylus Photo R200 Series on AVID] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P43 "Auto EPSON Stylus Photo R200 Series on AVID" /O12 "\\AVID\EPSON" /M "Stylus Photo R200"
    O4 - HKLM\..\Run: [EPSON Stylus Photo R200 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P39 "EPSON Stylus Photo R200 Series (Copy 1)" /O6 "USB001" /M "Stylus Photo R200"
    O4 - HKLM\..\Run: [EPSON Stylus Photo R200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P30 "EPSON Stylus Photo R200 Series" /O5 "LPT1:" /M "Stylus Photo R200"[/quote] I would think that one should be sufficient and you should should fix two of them. However the first appears to be slightly different in that it says on AVID in the message. Is AVID a shared drive from another PC?

    Yes you should uninstall Yahoo Antispyware if you don't use it.

    Now run this Disable/Remove Windows Messenger to remove Windows Messenger.

    Now let's remove a strange service that does not appear to be valid!
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to JEJTARVD or JEJTARVD - Sysinternals
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteJEJTARVD into the box that opens, and press OK
    • If HJT cannot find this (it probably will not) or you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Make sure viewing of hidden files is enabled (per the tutorial).
    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Look for the below process(es) and if found, End them:

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
    O23 - Service: JEJTARVD - Sysinternals - www.sysinternals.com - C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\JEJTARVD.exe <--- this should already be gone if the previous steps worked.

    After clicking Fix, exit HJT.
    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode

    Now run Ccleaner

    Also delete all files in the below folder except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Documents and Settings\HP_Owner\Local Settings\Temp\

    Now attach the below new logs and tell me how the above steps went.

    1. ShowNew
    2. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. albionmoon

    albionmoon Private E-2

    Chaslang -

    I removed ms messenger and was starting down the road to deleting the service you mentioned (I think it's from a process explorer that I installed awhile back - but it would be good to get rid of it). I was just unclear on one thing you mentioned.

    If HJT cannot find this (it probably will not) or you receive any error messages just ignore them and continue.

    HJT did in fact find JEJTARVD and I didn't know if I should have HJT delete it or not. Sorry if I didn't understand your direction - just wasn't absolutely certain that you wanted me to have HJT delete it.

    Thanks - just being cautious.
    albionmoon
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes delete it! Sorry it was not clean. I did not think HJT would find it because the naming convention for services was not followed properly. That service should not be running anyway and it should not be running from a Temp folder either. No valid service should be run from there and Process Explorer does not run as a service nor does it need one. Yes it said SysInternals.com in there but it sure does not look valid and doubt they would be stupid enough to name a service like that and locate it in that folder.
     
  8. albionmoon

    albionmoon Private E-2

    Chaslang -

    Okay, I went through your directions and got rid of that Jejtarvd service and I am attaching the two logs you requested. Everything seems okay now, I haven't noticed that strange pop up by the taskbar - but it goes up and down so quickly and randomly that it's not easy to see. Hopefully it's gone.

    Let me know if you spot something strange in the logs.

    By the way - yes, it's a drag that I have all those Epson drivers loading - I think it's because I have the printer on a network, but one time I had to connect it locally to this computer and it made me reinstall the drivers - then when I switched it back to the network, it must've created another instance. Just speculating, but that's how I remember it.

    Okay, thanks again -
    Albionmoon
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're logs are clean but you should delete the below dup folder for Windows Defender:
    C:\Program Files\Windows Defender(2)


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds