Help! Computer guys... trojan... PARAD.RAW.EXE

Status
Not open for further replies.

JHZR2

Staff member
Joined
Dec 14, 2002
Messages
56,219
Location
New Jersey
Hi,

I recently got a T-mobile GPRS card, so that I can get internet anywhere that I have cellphone service... A good thing. I installed it on the fiancee's laptop, and it worked great, but I got it for me, so today I installed it on my laptop.

I went to tracert.org to use their bandwidth meter... This was the only site that I had gone to, as the first thing I did once I installed the software and wireless card was go to symantec to download the latest updates (mine were about 30 days old - I dont use my laptop that much).

Well, as soon as liveupdate started, I began getting these email scan notifications... 10 or 20 of them. I have never used outlook or outlook express, and dont have any oither email programs on this laptop - I use webmail only. But somehow something was sending out spam mail form my computer.

I looked in the task manager and found PARAD.RAW.EXE. Right away I realized that the file name was not correct, so I did a search, but havent found that much info on it. I need to save my computer.

I downloaded the live updates, and it crashed a few times as I guess the trojan messed up my t-mobile connection. Finally I got some of it downloaded and installed, and now liveupdate is trying to download and install an 11mb update! I sure hope that it is an OK file, and not something tricking me.

Any info or advice? Please help!

Thanks in advance,

JMH
 
Is the prevx software OK to download and use to clean up??? Its the only thing Ive found on the net. It seems that symantec virus and firewall dropped the ball... i think this thing screwed them up too, as I no longer have an option in NAV to scan now, and the 'ad blocking' option in firewall went away too.

JMH
 
OK, so Im looking at symantec firewall (I used to have black ice, which Im learning was much better and easier to use...

parad.raw is unable to be terminated and is on port 1153, voblaizdupla is unable to be terminated anbd is on port 1124... I cant find how to block those ports in symantec firewall... i dont want outbound stuff going through there form my machine.

I only have symantec live update going, bt the firewall claims 3-5 online content open connections going on all the time... email scanner does not come up anymore... and there are 33-41 network connections always goingon. Im going to disconnect the tmobile as soon as I get the live update.

UGH!!!

JMH
 
Should I force quit parad raw and the files that I know from internet searching that are associated?

Thanks again!

JMH
 
I agree - disconnect from the internet. I've never gotten a virus that bad though.

You could try restarting Windows and hope you can get into Safe Mode - that keeps a lot of services from starting up. You then should do a search for all those files and try to delete them.

Also - not being logged in as an Administrator seriously reduces your vulnerability to viruses/worms because they won't have access to do the things that they do. Always good to create a user account with limited access and use that - especially when surfing the web.
 
Ive never gotten a virus before... ever. The worst Ive had is a macro once in word that didnt even do anything... And this is with a T1 line since 1997 and at least two windows machines on it since... Ive only been using antivirus software since last year!

And alas, I have never gotten a virus until going to tracert.org today! Ive used this site before to gauge bandwidth, and I know my fiancee's father has used it quite a bit as well...

Ugh, so annoying... Running spybot S&D seems to have made most traces go away. I dont see the file running anymore in the applications list, and it isnt an inbound/outbound player in my firewall statistics anymore.

I put a frule to block the ports I caught the thing sending/recieving on before, and it caught it once, but since this restart... nothing.

parad.raw.exe is still on the machine. I have the latest NAV updates, so I hope it finds it and helps me to remove this thing.

Interestingly, bazooka spyware searcher found a couple ______.biz malware entities on the computer that must have been installed with this trojan.

How annoying.

JMH
 
Download (if you can) Spybot Search & Destroy. It's free. Spybot might clean the trojan from your system. It sure can't hurt anything.
 
spybot is what I have on my machine... I updated it, ran a search, and it didnt name the trojan (VOBLAIZDUPLA.EXE parad.raw.exe zlbw.dll) or any of its associated files... but betwen it running and me adding soe blocked ports on my firewall, it seems to be under control.

Now I need to learn how to remove the files and the registry entries so it does not coem back...

Some good info is here:
http://www.wilderssecurity.com/showthread.php?t=124925

JMH
 
Some programs are very annoying in that they have a buddy program that immediately reloads the first if it gets terminated. And the first reloads the buddy program if you terminate it.

try running the cleaner in Safe Mode
 
doing that right now...

Ran norton antivirus (corporate edition, distributed by the Navy), and it found the trojan. I then ran kaspersky online virus scanner, and found another virus... it was listed as a virus. It must have been downloaded by the other program.

Im running the symantec removal tool for the trojan right now in safe mode. Then, Ill run it again in safe mode, and then run kaspersky online scanner and NAV full scan again.

I sure hope this works...

Thanks for the info.

JMH
 
If I was runing opera or firefox instead of IE< would I have gotten this? It had to come from the tracert.org website... and had to load through IE.

JMH
 
Since loading Spyware Blaster 3.5.1 (free) and updates daily neither Spybot S&D nor MS Antispyware (now deleted) nor my Panda Titanium Internet Security have found any spyware whereas they did previously. Just loaded O&O Defragger v4.0 (German and excellent) and Registry Mechanic free from a CD with a mag I bought and that fixed a bunch of stuff. Reg Mech alone found 113 problems. May not help your specific problem(s) but thought you might find it useful info?
 
quote:

Originally posted by JHZR2:
If I was runing opera or firefox instead of IE< would I have gotten this?
JMH


No.


For cleaning systems, I use Trojan Hunter, SpySweeper, AdAware, Counterspy and Trojan Remover. All the downloads have evals that are either free or free to use for a certain period of time. You can run them all without spending a dime. Give them a try...
 
Get rid of that virus incubator of an operating system and %99.99+ of your problems will go away for good.
wink.gif
 
LOL, I have a mac mini on my desk right now, waiting for transition... Alas, I need a windows computer for some of my work stuff... and Ive historically been quite good about not getting viruses.

I think Ive cleared it and all is well now.

JMH
 
SPyware BLaster is a top notch (free) program. My spyware scanners havent really detected anything since I downloaded Spyware Blaster.
 
Status
Not open for further replies.
Back
Top Bottom