Author Topic: Worm removal - Win32:VB-AQN  (Read 4094 times)

0 Members and 1 Guest are viewing this topic.

jim

  • Guest
Worm removal - Win32:VB-AQN
« on: September 11, 2006, 10:47:03 PM »
I haven't been infected for years so my removal skills are non-existent.  Avast Home on-access scanner first discovered this infection in a file in the X1 desktop search folder: bszip.dll.  I understand bszip.dll is a common zip utility.  Avast was unable to clean it and I have been unable to delete the X1 folder (or remove the program) because the computer reports that I don't have sufficient privileges.  An attempted scan of that folder by Avast failed because Avast reported that the folder doesn't exist.  I am currently doing a thorough scan of the entire drive, but I wonder what the next step is.  My next step is a boot scan. Can someone recommend a how-to if I need to do more?  Thanks.

Jim

I'm using WinXP Pro (up to date)

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: Worm removal - Win32:VB-AQN
« Reply #1 on: September 11, 2006, 11:01:10 PM »
Hi jim,

Here is the technical info on this worm:
http://www.sophos.com/security/analyses/w32brontokbh.html

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Worm removal - Win32:VB-AQN
« Reply #2 on: September 11, 2006, 11:10:55 PM »
A boot time scanning is not bad.
Maybe using ewido and a-squared in the Admin account will be good too.
There is a possibility (in my opinion) of this detection be a false positive.
Can you submit the file to on-line scanners?
Jotti
Trendmicro
Virustotal
ewido
The best things in life are free.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: Worm removal - Win32:VB-AQN
« Reply #3 on: September 11, 2006, 11:22:28 PM »
Hi Tech,

That was also the reason for giving the technical detail, so jim can establish himself that this is real or a FP. The latter was crossing my mind also, but better make sure once and for all.
If uploading reveals that there is a FP involved, he should send the file to avast,

polonus
« Last Edit: September 11, 2006, 11:44:19 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Worm removal - Win32:VB-AQN
« Reply #4 on: September 11, 2006, 11:31:32 PM »
Hi Tech, That was also the reason for giving the technical detail, so jim can establish himself that this is real or a FP. The later was crossing my mind also, but better make sure once and for all. If uploading reveals that there is a FP involved, he should send the file to avast
Yeah, you're fully right  8)
The best things in life are free.