Reply
Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: System infested:Worm W32.VBNA.b Activity

You are not getting it.

 

Go into the C:/_OTL folder

 

Quads

Contributor
gary8158
Posts: 32
Registered: ‎05-06-2012

Re: System infested:Worm W32.VBNA.b Activity

 C:/_OTL

Not finding it.

 

Maybe I should run script again. I copied from your attachment.

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: System infested:Worm W32.VBNA.b Activity

DON'T!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

 

You go into you hard drive seen as C in Computer

 

Quads

Contributor
gary8158
Posts: 32
Registered: ‎05-06-2012

Re: System infested:Worm W32.VBNA.b Activity

I have it. It mentions moved files. I can''t see a log.

 

I did have a noterpad come up saying this though, when it restarted.

 

 

All processes killed
========== OTL ==========
Process local.exe killed successfully!
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2927403198-3598784137-2109375690-1000\Software\Microsoft\Windows\CurrentVersion\Run\\windows deleted successfully.
C:\Users\GaryandMeryl\AppData\Roaming\tmp\local.exe moved successfully.
Registry value HKEY_USERS\S-1-5-21-2927403198-3598784137-2109375690-1000\Software\Microsoft\Windows\CurrentVersion\Run\\WMPNSCFG deleted successfully.
Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
C:\Windows\Downloaded Program Files\gp.inf not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{E54729E8-BB3D-4270-9D49-7389EA579090} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E54729E8-BB3D-4270-9D49-7389EA579090}\ deleted successfully.
C:\Windows\SysWOW64\ezUPBHook.dll moved successfully.
C:\Users\GaryandMeryl\AppData\Roaming\tmp folder moved successfully.
C:\Users\GaryandMeryl\AppData\Roaming\PCCUStubInstaller folder moved successfully.
C:\Windows\msdownld.tmp folder deleted successfully.
C:\Users\GaryandMeryl\AppData\Roaming\wklnhst.dat moved successfully.
C:\Users\GaryandMeryl\Documents\You have a Sky iD!.eml moved successfully.
ADS C:\Users\GaryandMeryl\Documents\Fw_ Your ASDA Travel Booking Confirmation [AA1F4F4A].eml:OECustomProperty deleted successfully.
Unable to delete ADS C:\Users\GaryandMeryl\Documents\You have a Sky iD!.eml:OECustomProperty .
ADS C:\Users\GaryandMeryl\Documents\Ryanair Travel Itinerary Knock.eml:OECustomProperty deleted successfully.
ADS C:\Users\GaryandMeryl\Documents\Your ASDA Travel Booking Confirmation [ATED2361].eml:OECustomProperty deleted successfully.
ADS C:\Users\GaryandMeryl\Documents\Your ASDA Travel Booking Confirmation [AA1F4F4A].eml:OECustomProperty deleted successfully.
========== FILES ==========
File\Folder C:\Users\GaryandMeryl\AppData\Roaming\tmp\local.exe not found.
C:\Users\GaryandMeryl\Documents\Your ASDA Travel Booking Confirmation [ATED2361].eml moved successfully.
C:\Users\GaryandMeryl\Documents\Your ASDA Travel Booking Confirmation [AA1F4F4A].eml moved successfully.
C:\Users\GaryandMeryl\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10\d7a950a-189dafec moved successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 41044 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: GaryandMeryl
->Temp folder emptied: 123117793 bytes
->Temporary Internet Files folder emptied: 78894664 bytes
->Java cache emptied: 1527385 bytes
->Google Chrome cache emptied: 47429032 bytes
->Flash cache emptied: 42271 bytes
 
User: Public
 
User: TEMP
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 202470 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33237 bytes
RecycleBin emptied: 93342 bytes
 
Total Files Cleaned = 240.00 mb
 
 
[EMPTYFLASH]
 
User: All Users
 
User: Default
->Flash cache emptied: 0 bytes
 
User: Default User
->Flash cache emptied: 0 bytes
 
User: GaryandMeryl
->Flash cache emptied: 0 bytes
 
User: Public
 
User: TEMP
 
Total Flash Files Cleaned = 0.00 mb
 
 
[EMPTYJAVA]
 
User: All Users
 
User: Default
 
User: Default User
 
User: GaryandMeryl
->Java cache emptied: 0 bytes
 
User: Public
 
User: TEMP
 
Total Java Files Cleaned = 0.00 mb
 
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.42.3 log created on 05072012_103419

Files\Folders moved on Reboot...
C:\Users\GaryandMeryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ET9W7IIT\3[1].htm moved successfully.
C:\Users\GaryandMeryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BLX6NPEY\fastbutton[1].htm moved successfully.
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.

Registry entries deleted on Reboot...

 

 

Contributor
gary8158
Posts: 32
Registered: ‎05-06-2012

Re: System infested:Worm W32.VBNA.b Activity

That was in a file under moved files.

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: System infested:Worm W32.VBNA.b Activity

That is the log, but you pasted it instead 

 

You should not be getting any more alerts by Norton any more as I took the ADS's files and folders.

 

Quads

Contributor
gary8158
Posts: 32
Registered: ‎05-06-2012

Re: System infested:Worm W32.VBNA.b Activity

Does this appear to have solved it?

 

I'm sorry if our wires were crossed a few times. Obviously this is something you do a lot. But should not understanding the inner workings stop me from using a PC. I mainly use if for photography, Facebook chatting, and forums.

 

I'm hoping this is solved.

 

 

Why would Norton not be able to resolve it?

Contributor
gary8158
Posts: 32
Registered: ‎05-06-2012

Re: System infested:Worm W32.VBNA.b Activity

I would like to thank you for your help.

 

 

I take it the worm is now removed. I wonder how I got it in the first place. Should Norton 360 have stopped it?

Contributor
gary8158
Posts: 32
Registered: ‎05-06-2012

Re: System infested:Worm W32.VBNA.b Activity

Do I need to keep OTL and asw MBR?

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: System infested:Worm W32.VBNA.b Activity

Are you getting these any more from Norton

 

The details are,

System infested:Worm W32.VBNA.b Activity
Attacker Url api.ipinfodb.com
source address. 67.212.77.13
Attacking computer 27.212.77.13, 80

Attack resulted from \DEVICE\HARDDISKVOLUME\USERS\GARYANDMERYL\APPDATA\TMP\LOCAL.EXE

 

Quads