<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: System Infected: Worm W32.VBNA.b Activity in Norton 360</title>
    <link>http://community.norton.com/t5/Norton-360/System-Infected-Worm-W32-VBNA-b-Activity/m-p/752474#M74522</link>
    <description>&lt;p&gt;The scan is running now. Would you like me to post these .txt files after the scan finishes?&lt;/p&gt;</description>
    <pubDate>Sat, 07 Jul 2012 04:14:30 GMT</pubDate>
    <dc:creator>ssapra</dc:creator>
    <dc:date>2012-07-07T04:14:30Z</dc:date>
    <item>
      <title>System Infected: Worm W32.VBNA.b Activity</title>
      <link>http://community.norton.com/t5/Norton-360/System-Infected-Worm-W32-VBNA-b-Activity/m-p/752148#M74502</link>
      <description>&lt;p&gt;Hello Norton community,&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I am using Norton Security Suite 2012. I have been getting a lot of intrusion attempts (every ten minutes; sometimes every hour). Here are all of the details.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Severity: High&lt;/p&gt;&lt;p&gt;Activity: An intrustion attempt by api.ipinfodb.com was blocked.&lt;/p&gt;&lt;p&gt;Status: Blocked&lt;/p&gt;&lt;p&gt;Recommended Action: No action required&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;IPS Alert Name: System Infected: Worm W32.VBNA.b Activity&lt;/p&gt;&lt;p&gt;Attacking Computer: api.ipinfodb.com (67.212.77.13, 80)&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Can anyone please advise how I can fix this?&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;This is the text when I copy this alert to the clipboard:&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;﻿Category: Intrusion Prevention&lt;br&gt;Date &amp;amp; Time,Risk,Activity,Status,Recommended Action,IPS Alert Name,Default Action,Action Taken,Attacking Computer,Attacker URL,Destination Address,Source Address,Traffic Description&lt;br&gt;2012-07-06 13:33:17,High,An intrusion attempt by api.ipinfodb.com was blocked.,Blocked,No Action Required,System Infected: Worm W32.VBNA.b Activity,No Action Required,No Action Required,&amp;quot;api.ipinfodb.com (67.212.77.13, 80)&amp;quot;,api.ipinfodb.com/v2/ip_query_country.php?key=e4e497e1ec0a03c3e5e49ab8868bdc755b520583cbf4e31605a016d82147ec63&amp;amp;timezone=off,67.212.77.13 (67.212.77.13),&amp;quot;TCP, www-http&amp;quot;&lt;br&gt;Network traffic from &amp;lt;b&amp;gt;api.ipinfodb.com/v2/ip_query_country.php?key=e4e497e1ec0a03c3e5e49ab8868bdc755b520583cbf4e31605a016d82147ec63&amp;amp;timezone=off&amp;lt;/b&amp;gt; matches the signature of a known attack.  The attack was resulted from \DEVICE\HARDDISKVOLUME3\WINDOWS\SYSWOW64\CALC.EXE.  To stop being notified for this type of traffic, in the &amp;lt;b&amp;gt;Actions&amp;lt;/b&amp;gt; panel, click &amp;lt;b&amp;gt;Stop Notifying Me&amp;lt;/b&amp;gt;.&lt;/p&gt;</description>
      <pubDate>Fri, 06 Jul 2012 18:47:06 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/System-Infected-Worm-W32-VBNA-b-Activity/m-p/752148#M74502</guid>
      <dc:creator>ssapra</dc:creator>
      <dc:date>2012-07-06T18:47:06Z</dc:date>
    </item>
    <item>
      <title>Re: System Infected: Worm W32.VBNA.b Activity</title>
      <link>http://community.norton.com/t5/Norton-360/System-Infected-Worm-W32-VBNA-b-Activity/m-p/752354#M74512</link>
      <description>&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;&lt;font color="#FF0000"&gt;ANY other user other than the thread starter is not to use any instructions, scripts or proceedures,  The work though in cleaning a system is individual and only for that system due to a number of factors.&lt;/font&gt;&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;&lt;font color="#FF0000"&gt;&lt;br&gt;&lt;/font&gt;&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;font color="#FF0000"&gt;&lt;strong&gt;Please do not run any tools unless instructed to do so.&lt;/strong&gt; &lt;/font&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability. Do as the instructions ask nothing extra or run things twice&lt;/li&gt;&lt;li&gt;If I ask a Question just answer it, don't run anything unless it states.&lt;/li&gt;&lt;li&gt;Major steps used:&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;1&lt;/strong&gt;. Find&lt;/p&gt;&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Break&lt;/p&gt;&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Destroy&lt;/p&gt;&lt;p&gt;&lt;strong&gt;4.&lt;/strong&gt; Cleanup  (including system as a whole)&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;font color="#FF0000"&gt;&lt;strong&gt;Please read every post completely before doing anything.&lt;/strong&gt; &lt;/font&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Pay special attention to the &lt;strong&gt;NOTE:&lt;/strong&gt; lines, these entries identify an individual issue or important step in the cleanup process.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt; &lt;/p&gt;&lt;ul&gt;&lt;li&gt;Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be &lt;strong&gt;patient&lt;/strong&gt; while I analyze any logs you post. &lt;strong&gt;Please remember&lt;/strong&gt;, I am a &lt;font color="#FF0000"&gt;&lt;strong&gt;volunteer&lt;/strong&gt;&lt;/font&gt;, and I do have a life outside of these forum, (sometimes &lt;img title="Smiley LOL" alt=":smileylol:" src="http://norton.i.lithium.com/i/smilies/16x16_smiley-lol.gif" border="0"&gt;)&lt;br&gt;&lt;br&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Attention to detail is&lt;font color="#FF0000"&gt; important&lt;/font&gt;&lt;/strong&gt;&lt;font color="#FF0000"&gt;!&lt;/font&gt; Since I cannot see or directly interact with your computer &lt;strong&gt;I am dependent on you to &amp;quot;be my eyes&amp;quot; and provide as much information as you can regarding the current state of your computer.&lt;/strong&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;u&gt;&lt;font color="#FF0000"&gt;&lt;strong&gt;Please read carefully&lt;/strong&gt;&lt;/font&gt;&lt;/u&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;span&gt;1. Please download aswMBR h&lt;/span&gt;&lt;strong&gt;&lt;font color="#FF0000"&gt;xx&lt;/font&gt;&lt;/strong&gt;&lt;span&gt;p://public.avast.com/~gmerek/aswMBR.exe to your desktop. (replace the h&lt;/span&gt;&lt;strong&gt;&lt;font color="#FF0000"&gt;xx&lt;/font&gt;&lt;/strong&gt;&lt;span&gt;p with h&lt;/span&gt;&lt;strong&gt;&lt;font color="#FF0000"&gt;tt&lt;/font&gt;&lt;/strong&gt;&lt;span&gt;p)&lt;/span&gt;&lt;br&gt;&lt;span&gt;Double click the aswMBR.exe icon to run it&lt;/span&gt;&lt;br&gt;&lt;span&gt;it will ask to download extra definitions - &lt;/span&gt;&lt;font color="#FF0000"&gt;ALLOW IT / Yes&lt;/font&gt;&lt;br&gt;&lt;span&gt;Click the Scan button to start the scan&lt;/span&gt;&lt;br&gt;&lt;span&gt;On completion of the scan, click the save log button, save it to your desktop and &lt;/span&gt;&lt;strong&gt;Please attach the log in the post back, Don't have the program fix anything.&lt;/strong&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Sat, 07 Jul 2012 00:29:05 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/System-Infected-Worm-W32-VBNA-b-Activity/m-p/752354#M74512</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-07-07T00:29:05Z</dc:date>
    </item>
    <item>
      <title>Re: System Infected: Worm W32.VBNA.b Activity</title>
      <link>http://community.norton.com/t5/Norton-360/System-Infected-Worm-W32-VBNA-b-Activity/m-p/752458#M74519</link>
      <description>&lt;p&gt;Thank you for replying.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I have attached the aswMBR.txt file.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Just a question, I noticed that the MBR.dat file was also created. Since you have not told me anything about this file, I assume I should just leave it alone?&lt;/p&gt;</description>
      <pubDate>Sat, 07 Jul 2012 03:37:48 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/System-Infected-Worm-W32-VBNA-b-Activity/m-p/752458#M74519</guid>
      <dc:creator>ssapra</dc:creator>
      <dc:date>2012-07-07T03:37:48Z</dc:date>
    </item>
    <item>
      <title>Re: System Infected: Worm W32.VBNA.b Activity</title>
      <link>http://community.norton.com/t5/Norton-360/System-Infected-Worm-W32-VBNA-b-Activity/m-p/752472#M74521</link>
      <description>&lt;p&gt;Download OTL &lt;a href="http://www.bleepingcomputer.com/download/otl/" target="_blank" rel="nofollow"&gt;http://www.bleepingcomputer.com/download/otl/&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Disable Norton for say 30 minutes&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Start OTL,  &lt;/p&gt;&lt;p&gt;Click the &lt;strong&gt;Scan All Users&lt;/strong&gt; checkbox.&lt;/p&gt;&lt;p&gt;Change file age to&lt;strong&gt; 90 days&lt;/strong&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Press the &lt;img title="" alt="" align="center" border="0" src="http://www.bleepstatic.com/fhost/uploads/0/runscan.png"&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;An OTL.txt  and extras.txt will be created.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Sat, 07 Jul 2012 04:05:59 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/System-Infected-Worm-W32-VBNA-b-Activity/m-p/752472#M74521</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-07-07T04:05:59Z</dc:date>
    </item>
    <item>
      <title>Re: System Infected: Worm W32.VBNA.b Activity</title>
      <link>http://community.norton.com/t5/Norton-360/System-Infected-Worm-W32-VBNA-b-Activity/m-p/752474#M74522</link>
      <description>&lt;p&gt;The scan is running now. Would you like me to post these .txt files after the scan finishes?&lt;/p&gt;</description>
      <pubDate>Sat, 07 Jul 2012 04:14:30 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/System-Infected-Worm-W32-VBNA-b-Activity/m-p/752474#M74522</guid>
      <dc:creator>ssapra</dc:creator>
      <dc:date>2012-07-07T04:14:30Z</dc:date>
    </item>
    <item>
      <title>Re: System Infected: Worm W32.VBNA.b Activity</title>
      <link>http://community.norton.com/t5/Norton-360/System-Infected-Worm-W32-VBNA-b-Activity/m-p/752476#M74523</link>
      <description>&lt;p&gt;What do you think??  You can use the advanced program youself  and I will leave you to it.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Sat, 07 Jul 2012 04:18:25 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/System-Infected-Worm-W32-VBNA-b-Activity/m-p/752476#M74523</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-07-07T04:18:25Z</dc:date>
    </item>
    <item>
      <title>Re: System Infected: Worm W32.VBNA.b Activity</title>
      <link>http://community.norton.com/t5/Norton-360/System-Infected-Worm-W32-VBNA-b-Activity/m-p/752478#M74524</link>
      <description>&lt;p&gt;The scan finished. Here are the .txt files.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Please, sir. I do not know what to do after running the scan. There does not appear to be any notifications regarding the results of the scan, but this is probably in the two .txt files that have been generated. Please, I need your help to work through this.&lt;/p&gt;</description>
      <pubDate>Sat, 07 Jul 2012 04:29:17 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/System-Infected-Worm-W32-VBNA-b-Activity/m-p/752478#M74524</guid>
      <dc:creator>ssapra</dc:creator>
      <dc:date>2012-07-07T04:29:17Z</dc:date>
    </item>
    <item>
      <title>Re: System Infected: Worm W32.VBNA.b Activity</title>
      <link>http://community.norton.com/t5/Norton-360/System-Infected-Worm-W32-VBNA-b-Activity/m-p/752488#M74525</link>
      <description>&lt;p&gt;Ok, a user that uses VM and sandboxie with files like test, a handful of programs for security torrenting,  toolbars that are iffy, and it looks like Malware leftovers.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;You should know how to remove the malware yourself.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Sat, 07 Jul 2012 04:42:30 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/System-Infected-Worm-W32-VBNA-b-Activity/m-p/752488#M74525</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-07-07T04:42:30Z</dc:date>
    </item>
    <item>
      <title>Re: System Infected: Worm W32.VBNA.b Activity</title>
      <link>http://community.norton.com/t5/Norton-360/System-Infected-Worm-W32-VBNA-b-Activity/m-p/752490#M74526</link>
      <description>&lt;p&gt;Sir, I downloaded sandboxie TODAY and I have not used it because I didn't know how to get it to work. Please, I'm begging you, tell me how to remove the malware. How would I know the source? Just remove all of these toolbars? I really need your help. All I ask is for a little of your time.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;PLEASE.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I will be honest with you. I do NOT know how to remove the malware.&lt;/p&gt;</description>
      <pubDate>Sat, 07 Jul 2012 05:12:53 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/System-Infected-Worm-W32-VBNA-b-Activity/m-p/752490#M74526</guid>
      <dc:creator>ssapra</dc:creator>
      <dc:date>2012-07-07T05:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: System Infected: Worm W32.VBNA.b Activity</title>
      <link>http://community.norton.com/t5/Norton-360/System-Infected-Worm-W32-VBNA-b-Activity/m-p/752492#M74527</link>
      <description>&lt;p&gt;No,   &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I will let you keep installing programs and using them including VM,  I can see some of the malware objects and what appears that you also had or have as well as the programs.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&amp;quot;&lt;span&gt;How would I know the source&amp;quot; that is what the programs are for  and the use other the likes of  VM, but I don't use VM like software.&lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;span&gt;Good luck with all the programs, items VM, Sandboxie and the Malware.&lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;span&gt;Quads&lt;/span&gt;&lt;/p&gt;</description>
      <pubDate>Sat, 07 Jul 2012 05:24:06 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/System-Infected-Worm-W32-VBNA-b-Activity/m-p/752492#M74527</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-07-07T05:24:06Z</dc:date>
    </item>
    <item>
      <title>Re: System Infected: Worm W32.VBNA.b Activity</title>
      <link>http://community.norton.com/t5/Norton-360/System-Infected-Worm-W32-VBNA-b-Activity/m-p/752588#M74533</link>
      <description>&lt;p&gt;So I keep installing programs to find the source?&lt;/p&gt;&lt;p&gt;You can see the malware objects? Well, what are they?&lt;/p&gt;&lt;p&gt;I'm still confused how installing programs will help me find the source. And why do you keep mentioning VM?&lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Sat, 07 Jul 2012 12:19:43 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/System-Infected-Worm-W32-VBNA-b-Activity/m-p/752588#M74533</guid>
      <dc:creator>ssapra</dc:creator>
      <dc:date>2012-07-07T12:19:43Z</dc:date>
    </item>
    <item>
      <title>Re: System Infected: Worm W32.VBNA.b Activity</title>
      <link>http://community.norton.com/t5/Norton-360/System-Infected-Worm-W32-VBNA-b-Activity/m-p/752874#M74559</link>
      <description>&lt;p&gt;You have programs like VM installed,  (doesn't think I can read logs by the looks) and test files.   So I am not touching this system and it's setups with users that use these programs for testing.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I do see some of the objects  as I have already stated, but no, with the way the system is I am not saying or doing anything else.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Sun, 08 Jul 2012 00:07:49 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/System-Infected-Worm-W32-VBNA-b-Activity/m-p/752874#M74559</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-07-08T00:07:49Z</dc:date>
    </item>
  </channel>
</rss>

