Reply
Contributor
gary8158
Posts: 32
Registered: ‎05-06-2012

Re: System infested:Worm W32.VBNA.b Activity

Not at the moment. But maybe if I go onto Facebook or elsewhere it might happen. They were just a few times a day, sometimes more.

Bot Obliterator
Quads
Posts: 13,266
Registered: ‎07-21-2008

Re: System infested:Worm W32.VBNA.b Activity

The attack came from Attack resulted from \DEVICE\HARDDISKVOLUME\USERS\GARYANDMERYL\APPDATA\TMP\LOCAL.EXE

 

I removed it as seen in the log

 

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2927403198-3598784137-2109375690-1000\Software\Microsoft\Windows\CurrentVersion\Run\\windows deleted successfully.
C:\Users\GaryandMeryl\AppData\Roaming\tmp\local.exe moved successfully.

C:\Users\GaryandMeryl\AppData\Roaming\tmp folder moved successfully.

 

Start  OTL, but this time click the Black  "CleanUp" button

 

Quads

Contributor
gary8158
Posts: 32
Registered: ‎05-06-2012

Re: System infested:Worm W32.VBNA.b Activity

Oh, Norton Sonar just removed OTL!

 

Bot Obliterator
Quads
Posts: 13,266
Registered: ‎07-21-2008

Re: System infested:Worm W32.VBNA.b Activity

Just go and delete the whole _OTL folder if it is still there and then delete from your recycle bin

 

You can delete aswMBR to.

 

Quads

Contributor
gary8158
Posts: 32
Registered: ‎05-06-2012

Re: System infested:Worm W32.VBNA.b Activity

Saw it as a risk for some reason.

Contributor
gary8158
Posts: 32
Registered: ‎05-06-2012

Re: System infested:Worm W32.VBNA.b Activity

You don't want me to re install OTL and run it agian just in case?

 

Gary.

Bot Obliterator
Quads
Posts: 13,266
Registered: ‎07-21-2008

Re: System infested:Worm W32.VBNA.b Activity

NO, just do as I say.   the OTL quarantine is the _OTL folder that is to be deleted  entirely.

 

Quads

Contributor
gary8158
Posts: 32
Registered: ‎05-06-2012

Re: System infested:Worm W32.VBNA.b Activity

Done. I misunderstood, as you'd said to run it on the black cleanup button, I thought it was something that had to be done. But Sonar must have detected the problem in there and deleted the whole thing.

 

I really am grateful for your help, and sorry again for the confusions. I was reading and doing as I saw, or at least I thought I was.

 

Kind regards.

Gary.

Bot Obliterator
Quads
Posts: 13,266
Registered: ‎07-21-2008

Re: System infested:Worm W32.VBNA.b Activity

You better hope you don't get a tougher infection otherwise you will be up the Nile without a boat with the harder instructions at times.

 

Quads

Contributor
gary8158
Posts: 32
Registered: ‎05-06-2012

Re: System infested:Worm W32.VBNA.b Activity

Just have to pay someone to do it. I got on so much better years ago with my old Millennium edition, and advice from Castlecops (AKA computercops).

 

Is it worth having more than 1 virus scanner, or do they clash?

I see that we were using AVAST there for a while, would they work hand in hand?