Home Malware Programs Worms Worm.Win32.VBNA.alpv

Worm.Win32.VBNA.alpv

Posted: March 14, 2011

Threat Metric

Threat Level: 5/10
Infected PCs: 14
First Seen: December 8, 2010
OS(es) Affected: Windows

Worm.Win32.VBNA.alpv is a worm that corrupts innocent running processes with Worm.Win32.VBNA.alpv's malicious code and creates general security vulnerabilities in the affected system. These vulnerabilities can allow variants of Worm.Win32.VBNA.alpv to install other malware and may make the computer open to control by remote attackers. Worm.Win32.VBNA.alpv also damages the Windows Registry by adding startup entries for itself and deleting other entries to limit your file-viewing capabilities. Obviously, this worm is a high threat to your PC, so finding Worm.Win32.VBNA.alpv on your hard drive is cause for deleting Worm.Win32.VBNA.alpv with as much force and promptness as can be mustered.

Worm.Win32.VBNA.alpv's Malicious Code is not a Content to Keep to Itself

Worms like Worm.Win32.VBNA.alpv are able to spread through networks and removable drives by using Autorun-based exploits along with copying their files to shared locations and using the Hidden attribute to keep them from being seen. Any PC infected by Worm.Win32.VBNA.alpv should have all network-shared resources disabled temporarily, and not be used with removable drive devices that have contact with other computers.

Worm.Win32.VBNA.alpv corrupts the Windows Registry in two different ways: firstly, Worm.Win32.VBNA.alpv adds entries to make sure its own malicious code runs with Windows in the background. Secondly, Worm.Win32.VBNA.alpv deletes entries that allow the user to view certain Hidden files and extensions. This makes it easier for Worm.Win32.VBNA.alpv to disguise itself as another file or remain completely undetected.

Worm.Win32.VBNA.alpv can intercept and block or alter warnings and other messages from applications by abusing system hooks. In some cases, Worm.Win32.VBNA.alpv may also contact external servers to download malware or transfer information from your computer to a remote attacker.

The worst attack Worm.Win32.VBNA.alpv has in its arsenal, however, is Worm.Win32.VBNA.alpv's ability to corrupt running processes with Worm.Win32.VBNA.alpv's own code. The following processes may be hijacked and used to continue the Worm.Win32.VBNA.alpv plague:

  • Processes related to Adobe Reader.
  • Anti-virus, anti-malware or security application processes.
  • Miscellaneous and potentially malicious files like 360tray.exe.

So far, fortunately, there haven't been any indications of Worm.Win32.VBNA.alpv corrupting default Windows operating system processes. However, the infection of the above processes can make it more difficult to detect or delete Worm.Win32.VBNA.alpv or other malware.

Worm.Win32.VBNA.alpv Has Its Own Files to Cram Down Your Throat, Too

In addition to infecting processes, Worm.Win32.VBNA.alpv creates various .dll, .exe, .sys and .cmd files on the infected computer. These files are primarily hidden in the user profile subdirectory, but can also be in temporary files folders or essential Windows OS folders.

Manually removing Worm.Win32.VBNA.alpv isn't suggested, since it can be easy to delete the wrong file and harm your operating system. Instead, you should consider using an industry-approved anti-malware application to scan for and remove Worm.Win32.VBNA.alpv's many possible infections. Different scanners may pick up Worm.Win32.VBNA.alpv as Malware.Changeup, Worm.Win32.Vobfus or Downloader-CJX.gen.g.

If you're using any version of Windows from Windows 98 to Windows 7, you're vulnerable to attack by Worm.Win32.VBNA.alpv. Protect your PC accordingly from this worm so Worm.Win32.VBNA.alpv can't spread further than it's already managed to do!

Aliases

WORM_VBNA.SMN [TrendMicro]W32.Changeup.C [Symantec]Mal/SillyFDC-D [Sophos]W32/VobfusLNK.A [Panda]Win32/AutoRun.VB.RT [NOD32]Worm:Win32/Vobfus.gen!B [Microsoft]Downloader-CJX.gen.g [McAfee]Worm.Win32.VBNA.alpv [Kaspersky]Worm.Win32.Vobfus [Ikarus]Worm:W32/Vobfus.BS [F-Secure]Win32/Vobfus.FH [eTrust-Vet]Trojan.MulDrop1.40418 [DrWeb]Worm.VBNA.gen [CAT-QuickHeal]Trojan.Downloader.VB.WPO [BitDefender]Worm/VB.12.AF [AVG]
More aliases (25)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%USERPROFILE%\jypuz.exe File name: jypuz.exe
Size: 138.24 KB (138240 bytes)
MD5: f2b03893142dc94ac27061c49084ab46
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: December 8, 2010
%USERPROFILE%\jixeb.exe File name: jixeb.exe
Size: 138.24 KB (138240 bytes)
MD5: 4a2e6ed86c44416e5d68ed7a9bc18669
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: December 8, 2010
Loading...