Various
05-06-2012 11:51 PM
Hi, I'm new to the forums. I keep getting a message that an intrusion was blocked, and no further action needed. The thing is, I get it quite a lot. I've ran scans and there's no problem, and it's not mentioned as dealt with.
Then a while later the box comes into view telling me that this worm has been blocked.
The details are,
System infested:Worm W32.VBNA.b Activity
Attacker Url api.ipinfodb.com
source address. 67.212.77.13
Attacking computer 27.212.77.13, 80
Attack resulted from \DEVICE\HARDDISKVOLUME\USERS\GARYANDMERYL\APPDATA\
It is obviously being detected and blocked, but does this mean I have some kin of infection, and can I get rid of it?
I'm not sure if I picked it up from Facebook, or when looking at an animal vet site in Australia (after my cat was ill).
Any ideas?
Thanks, Gary.
Solved! Go to Solution.
05-06-2012 11:56 PM
What is you Antivirus product installed??
Quads
05-06-2012 11:59 PM
Further to that, I found this on here.
System Infected: Worm W32.VBNA.b Activity
Various
05-07-2012 12:00 AM
Norton 360 version 6.2.0.9
05-07-2012 12:13 AM
ODD I had never heard of that detection name for Symantec products (and just looked it's not in the online database) but another AV uses thart name.
Please do not run any tools unless instructed to do so.
Please read every post completely before doing anything.
Please read carefully
1. Please download aswMBR hxxp://public.avast.com/~gmerek/aswMBR.exe to your desktop. (replace the hxxp with http)
Double click the aswMBR.exe icon to run it
it will ask to download extra definitions - ALLOW IT / Yes
Click the Scan button to start the scan
On completion of the scan, click the save log button, save it to your desktop and Please attach the log in the post back, Don't have the program fix anything.
2. Download OTL hxxp://oldtimer.geekstogo.com/OTL.exe (change the hxxp to http) save it to your Desktop.
Double click on OTL.exe to run it. Right click OTL.exe and select run as administator for Vista and Win 7.
Click the Scan All Users checkbox.
Change file age to 60 days
Press the 
Quads
Quads
05-07-2012 12:21 AM
Oops, accidentally clicked the solution button!
How do I download the aswMBR hxxp://public.avast.com/~gmerek/aswMBR.exe? I tried (I changed the 2 x's to tt) Should I just start at HTTP, or include aswMBR?
05-07-2012 12:26 AM
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-05-07 08:23:37
-----------------------------
08:23:37.699 OS Version: Windows x64 6.0.6002 Service Pack 2
08:23:37.699 Number of processors: 4 586 0x170A
08:23:37.699 ComputerName: GARYANDMERYL-PC UserName: GaryandMeryl
08:23:39.540 Initialize success
08:24:03.366 The log file has been saved successfully to "C:\Users\GaryandMeryl\Documents\aswMBR.txt"
05-07-2012 12:38 AM
If you can't follow the instructions including the website addresses like others do then there is no point in me continuing with you and the more dangerous tools that may come.
Quads
05-07-2012 12:52 AM
Sorry. I made a mistake is all.
I'm normally OK with stuff, but was being a little dense.
I've got a log file from OTL. Posting it shown highlighted entries that this site won't accept. How would you have me deal with them?
05-07-2012 12:53 AM
Attach the OTL.txt log
Quads
