Worm.Win32.VBNA

Bookmark and Share

 

1. What is the Worm.Win32.VBNA

Worm.Win32.VBNA.b is a cyber creature that poses a tangible risk to your computer in case it gets inside. The conventional name of this malicious thing hints at it being a PC worm, i.e. a tiny application that imperceptibly sneaks into a workstation and then quickly populates the injected system. The rapidity of Worm.Win32.VBNA.b’s propagation inside the targeted computer is explained by the specificity of its nature. It can replicate itself, i.e. create small copies of its malcode in different directories and locations. Therefore, first thing you know after Worm.Win32.VBNA.b entered your computer is it has firmly grabbed hold of your Operating System. Let’s move on and keep analyzing this infection. Worm.Win32.VBNA.b is not some piece of malware that infiltrates computer just for fun, or just because it is a worm parasite. Worm.Win32.VBNA.b has a different mission which can be manifold and very fraudulent. It tends to establish a rootkit connection with a remote host which is run by criminals, aka hackers as they are generally denominated. Once this hidden connection gets set up, the fraudsters will be able to easily transmit some unsafe files on to your machine, without letting you know of course. So it becomes obvious that Worm.Win32.VBNA.b is a component of some malware distribution tactics being conducted by the bad software guys. The worm can contribute to spreading spyware, rogue anti-spyware, trojans etc. And this feature adds some hazardousness to Worm.Win32.VBNA.b, believe us. For instance, spyware can steal your identity; scareware can annoy you into wasting your money; trojan horses are capable of completely driving your system out of order. Anyway, Worm.Win32.VBNA.b is a dangerous specimen of malicious software that does not belong on your PC if you want it to work well. This is why Worm.Win32.VBNA.b should be included on your ‘to-be-removed’ list, and the cleaning better be performed as quickly as possible otherwise the pest will completely overcome your computer’s security and defense ability. Worm.Win32.VBNA.b removal tips are there for you in the post section below.

 

2.Technical Details:

 

a. The following files were created in the system:

 

No. Filename Size
1 %System%\winamp.exe 86,016 bytes
2 %System%\ydjqebiu.bat 124 bytes
  • Note:
    • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).

b. Memory Modifications

  • There was a new process created in the system:

Process Name Main Module Size
winamp.exe 77,824 bytes

c. Registry Modifications

  • The newly created Registry Value is:
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      • Winamp Agent = "%System%\winamp.exe"
  • d. Other details

    • There were registered attempts to establish connection with the remote hosts. The connection details are:

    Remote Host Port Number
    174.139.92.250 6764

     

    3. How-to's

    a. How to prevent the  Worm.Win32.VBNA ?

    Please update the policy basic knowledge of Sax2  in time, Once  Ax3soft sax2 detects  the communication of these trojans, it will break them and  ensure your network & business security.

    b. How to Remove the Worm.Win32.VBNA   Manually?

    Step 1 : Stop the following Worm.Win32.VBNA processes
    %System%\winamp.exe

    Step 2 : Remove the following Worm.Win32.VBNA.cxc registry keys
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    • Winamp Agent = "%System%\winamp.exe

    Step3: Locate and delete the following Worm.Win32.VBNA files

    %System%\winamp.exe
    %System%\ydjqebiu.bat

    c. How to Remove these trojans Instantly?

    Manual removal is a difficult process and it is not recommend unless you are an expert in this field. Therefore, you best defense is to download and install a reliable anti-spyware program to scan spyware on your machine. In order to detect computer threats in the easiest and fastest way possible, we advised trying the  Malwarebytes' Anti-Malware, it is an anti-malware application that can thoroughly remove even the most advanced malware. It includes a number of features, including a built in protection monitor that blocks malicious processes before they even start. visit http://www.ids-sax2.com/Malwarebytes-Anti-Malware.htm and download Malwarebytes' Anti-Malware to help you.

     

    4. Appendix

    For more information, please visit  http://www.ids-sax2.com/ComputerSecurityNewsletter.htm

  •