Reply
Contributor
gary8158
Posts: 32
Registered: ‎05-06-2012
Accepted Solution

System infested:Worm W32.VBNA.b Activity

Hi, I'm new to the forums. I keep getting a message that an intrusion was blocked, and no further action needed. The thing is, I get it quite a lot. I've ran scans and there's no problem, and it's not mentioned as dealt with.

Then a while later the box comes into view telling me that this worm has been blocked.

The details are,

System infested:Worm W32.VBNA.b Activity
Attacker Url api.ipinfodb.com
source address. 67.212.77.13
Attacking computer 27.212.77.13, 80

Attack resulted from \DEVICE\HARDDISKVOLUME\USERS\GARYANDMERYL\APPDATA\TMP\LOCAL.EXE

 

It is obviously being detected and blocked, but does this mean I have some kin of infection, and can I get rid of it?

 

I'm not sure if I picked it up from Facebook, or when looking at an animal vet site in Australia (after my cat was ill).

 

Any ideas?

 

Thanks, Gary.

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: System infested:Worm W32.VBNA.b Activity

What is you Antivirus product installed??

 

Quads

Contributor
gary8158
Posts: 32
Registered: ‎05-06-2012

Re: System infested:Worm W32.VBNA.b Activity

Further to that, I found this on here.

 

System Infected: Worm W32.VBNA.b Activity

 
Severity: HighThis attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.
DescriptionWorm Win32.VBNA.b is a network-aware worm infection, which is also regarded by many experts as cloaked malware.
Additional InformationWorm Win32.VBNA.b is a network-aware worm infection, which is also regarded by many experts as cloaked malware.
Affected

Various

 

But no details as to how to deal with it.
Contributor
gary8158
Posts: 32
Registered: ‎05-06-2012

Re: System infested:Worm W32.VBNA.b Activity

Norton 360 version 6.2.0.9

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: System infested:Worm W32.VBNA.b Activity

ODD I had never heard of that detection name for Symantec products (and just looked it's not in the online database) but another AV uses thart name.

 

Please do not run any tools unless instructed to do so. 

  • We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.

Please read every post completely before doing anything. 

  • Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.



 

Please read carefully

 

1. Please download aswMBR hxxp://public.avast.com/~gmerek/aswMBR.exe to your desktop. (replace the hxxp with http)
Double click the aswMBR.exe icon to run it
it will ask to download extra definitions - ALLOW IT / Yes
Click the Scan button to start the scan
On completion of the scan, click the save log button, save it to your desktop and Please attach the log in the post back, Don't have the program fix anything.

 

2.   Download OTL   hxxp://oldtimer.geekstogo.com/OTL.exe   (change the hxxp to http) save it to your Desktop.

Double click on OTL.exe to run it.  Right click OTL.exe and select run as administator for Vista and Win 7.

Click the Scan All Users checkbox.

Change file age to 60 days


Press the 

 

Quads

 

Quads

Contributor
gary8158
Posts: 32
Registered: ‎05-06-2012

Re: System infested:Worm W32.VBNA.b Activity

Oops, accidentally clicked the solution button!

 

How do I download the aswMBR hxxp://public.avast.com/~gmerek/aswMBR.exe? I tried (I changed the 2 x's to tt) Should I just start at HTTP, or include aswMBR?

Contributor
gary8158
Posts: 32
Registered: ‎05-06-2012

Re: System infested:Worm W32.VBNA.b Activity

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-05-07 08:23:37
-----------------------------
08:23:37.699    OS Version: Windows x64 6.0.6002 Service Pack 2
08:23:37.699    Number of processors: 4 586 0x170A
08:23:37.699    ComputerName: GARYANDMERYL-PC  UserName: GaryandMeryl
08:23:39.540    Initialize success
08:24:03.366    The log file has been saved successfully to "C:\Users\GaryandMeryl\Documents\aswMBR.txt"


 

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: System infested:Worm W32.VBNA.b Activity

If you can't follow the instructions including the website addresses like others do then there is no point in me continuing with you and the more dangerous tools that may come.

 

Quads

Contributor
gary8158
Posts: 32
Registered: ‎05-06-2012

Re: System infested:Worm W32.VBNA.b Activity

Sorry. I made a mistake is all.

 

I'm normally OK with stuff, but was being a little dense.

 

I've got a log file from OTL. Posting it shown highlighted entries that this site won't accept. How would you have me deal with them?

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: System infested:Worm W32.VBNA.b Activity

Attach the OTL.txt log

 

Quads