voblaizdupla.exe

F

Frank

Hello,

Does anyone know anything about a file called voblaizdupla.exe?
My ZoneAlarm notified me this morning that it was trying to access the
internet.
It is living in c:\windows\system32 folder. No idea how it got there.
Not a single hit on Google.

FK
 
M

Malke

Frank said:
Hello,

Does anyone know anything about a file called voblaizdupla.exe?
My ZoneAlarm notified me this morning that it was trying to access the
internet.
It is living in c:\windows\system32 folder. No idea how it got
there. Not a single hit on Google.

It is common for malware to have random names like that. There is a high
probability that your computer is infested with something. Go through
these steps systematically to clean up your machine:

http://www.elephantboycomputers.com/page2.html#Removing_Malware

Malke
 
M

mark.reinertson

I got it too. I was playing quake 3 last night. I quit and zonealarm
asked me the same thing. It was in the same place. It was trying to
talk to 81.177.3.175:80?
Any news on this yet?
 
M

mark.reinertson

I got it too. I was playing quake 3 last night. I quit and zonealarm
asked me the same thing. It was in the same place. It was trying to
talk to 81.177.3.175:80?
Any news on this yet?
 
M

mark.reinertson

Read it. Basic stuff.
I know how to deal with it. I want to know what EXACTLY it is, what it
does, how did it get there?

Did the internic thing,

inetnum: 81.177.3.0 - 81.177.3.255netname: BESTTEST-RUdescr:
besTTest - HW lab,descr: Moscow, Russiacountry:
RUadmin-c: AV1919-RIPEtech-c: AV1919-RIPEstatus:
ASSIGNED PAmnt-by: AS8342-MNTsource: RIPE # Filtered
person: Anatoliy Voroninaddress: BesTTest HardWare
Lab.address: 125364, Moscow, Russiaaddress: Norilskaya
str., 13Ae-mail: (e-mail address removed)-mail:
(e-mail address removed): phone: +7 095 5447337phone:
+7 495 5447337remarks: fax-no: +7 095 5447337fax-no:
+7 495 5447337nic-hdl: AV1919-RIPEsource: RIPE #
Filteredremarks: modified for Russian phone area changes

Looks like a Russian Zombie Bot Master. My question would be "How did
he get his little file on my machine???"
 
M

Malke

Read it. Basic stuff.
I know how to deal with it. I want to know what EXACTLY it is, what it
does, how did it get there?

Did the internic thing,

inetnum: 81.177.3.0 - 81.177.3.255netname: BESTTEST-RUdescr:
besTTest - HW lab,descr: Moscow, Russiacountry:
RUadmin-c: AV1919-RIPEtech-c: AV1919-RIPEstatus:
ASSIGNED PAmnt-by: AS8342-MNTsource: RIPE # Filtered
person: Anatoliy Voroninaddress: BesTTest HardWare
Lab.address: 125364, Moscow, Russiaaddress: Norilskaya
str., 13Ae-mail: (e-mail address removed)-mail:
(e-mail address removed): phone: +7 095 5447337phone:
+7 495 5447337remarks: fax-no: +7 095
5447337fax-no:
+7 495 5447337nic-hdl: AV1919-RIPEsource: RIPE
#
Filteredremarks: modified for Russian phone area changes

Looks like a Russian Zombie Bot Master. My question would be "How did
he get his little file on my machine???"

Safe Hex:

http://www.wilderssecurity.com/showthread.php?t=27971 - So How Did I Get
Infected Anyway?
http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Introduction
http://www.claymania.com/safe-hex.html
http://www.aumha.org/a/parasite.htm - The Parasite Fight
http://msmvps.com/blogs/harrywaldron/archive/2006/02/05/82584.aspx - MVP
Harry Waldron - The Family PC - How to stay safe on the Internet
http://www.spywarewarrior.com/rogue_anti-spyware.htm - Eric Howes on
Rogue Antispyware Programs
http://www.microsoft.com/security/protect/default.asp - Protect Your PC
http://www.cert.org/homeusers/HomeComputerSecurity/ - Home Computer
Security

Malke
 
D

David H. Lipman

From: "Frank" <[email protected]>

| Hello,
|
| Does anyone know anything about a file called voblaizdupla.exe?
| My ZoneAlarm notified me this morning that it was trying to access the
| internet.
| It is living in c:\windows\system32 folder. No idea how it got there.
| Not a single hit on Google.
|
| FK
|


If you are using any version of Sun Java that is prior to JRE Version 5.0,
then you are strongly urged to remove any/all versions that are prior to JRE
Version 5.0. There are vulnerabilities in them and they are actively being exploited.
It is possible that is how you got infected with malware.

Therefore, it is highly suggested that if there are any prior versions of Sun Java
to Version 5 on the PC that they be removed and Sun Java JRE Version 5.0 Update 6
be installed ASAP.

http://www.java.com/en/download/manual.jsp


For non-viral malware...

Please download, install and update the following software...

* Ad-aware SE v1.06
http://www.lavasoft.de/
http://www.lavasoftusa.com/
http://www.lavasoft.de/ms/index.htm

* SpyBot Search and Destroy v1.4
http://security.kolla.de/
http://www.safer-networking.org/microsoft.en.html

After the software is updated, I suggest scanning the system in Safe Mode.

I also suggest downloading, installing and updating BHODemon for any Browser Helper Objects
that may be on the PC.

* BHODemon

http://www.majorgeeks.com/downloadget.php?id=3550&file=11&evp=245a87539eea8ed6904332b4b8b8442d

For viral malware...

* Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file. http://www.ik-cs.com/multi-av.htm

Additional Instructions:
http://harrisonrj.home.comcast.net/step_by_step_pc_cleaning_process.htm#Step_3_%96_Getting_Help


* * * Please report back your results * * *
 
M

MAP

Read it. Basic stuff.
I know how to deal with it. I want to know what EXACTLY it is, what it
does, how did it get there?

This is from a thread in another newsgroup.



Hi all, this is a virus...

I did a scan on :
http://www.kaspersky.com/scanforvirus

and it came up with the following feedback...

Scanned file: voblaizdupla.exe - Infected

voblaizdupla.exe - infected by Trojan-Downloader.Win32.Small.ciw

Must be new, because Yahoo was the only SE I could find and informatio on
it...
 
D

David H. Lipman

From: "MAP" <[email protected]>


|
| This is from a thread in another newsgroup.
|
| Hi all, this is a virus...
|
| I did a scan on :
| http://www.kaspersky.com/scanforvirus
|
| and it came up with the following feedback...
|
| Scanned file: voblaizdupla.exe - Infected
|
| voblaizdupla.exe - infected by Trojan-Downloader.Win32.Small.ciw
|
| Must be new, because Yahoo was the only SE I could find and informatio on
| it...
|

Then the Kaspersky module of my Multi AV Scanning Tool should take care of this.
 
F

Frank

Frank said:
Hello,

Does anyone know anything about a file called voblaizdupla.exe?
My ZoneAlarm notified me this morning that it was trying to access the
internet.
It is living in c:\windows\system32 folder. No idea how it got there.
Not a single hit on Google.

FK

Here's what this thing is doing on my PC:
Each day when I first access the internet it sends something to the url
shown on the third line from the bottom below and then to the one on the
very last line.
It only happens the very first time of the day. It will not repeat if I
close the browser, re-open and go to a different site.
I have tried AdAware, Spybot Search and Destroy, Pest Patrol, BHO Demon and
apart from BHO Demon which found a possible threat but could not identify
it, none of the others report anything wrong.

FK

2006-03-26 11:35:37 TCP from 192.168.1.119:2507 to
toolbar.google.com(72.14.203.104):80
2006-03-26 11:35:37 TCP from 192.168.1.119:2508 to
www.google.com(72.14.207.99):80
2006-03-26 11:35:53 TCP from 192.168.1.119:2510 to
www.officepirates.com(205.188.238.109):80
2006-03-26 11:35:55 TCP from 192.168.1.119:2516 to 64.236.42.80:80
2006-03-26 11:35:56 TCP from 192.168.1.119:2519 to
timeofficepirates.122.2o7.net(66.150.208.106):80
2006-03-26 11:35:56 TCP from 192.168.1.119:2520 to
64.236.42.80(64.236.42.80):80
2006-03-26 11:35:56 TCP from 192.168.1.119:2521 to
timeofficepirates.122.2o7.net(66.150.208.106):80
2006-03-26 11:35:56 TCP from 192.168.1.119:2522 to
fpdownload.macromedia.com(208.185.219.177):80
2006-03-26 11:35:57 TCP from 192.168.1.119:2523 to
ad.doubleclick.net(216.73.86.181):80
2006-03-26 11:35:57 TCP from 192.168.1.119:2524 to
m.2mdn.net(216.73.85.57):80
2006-03-26 11:35:58 TCP from 192.168.1.119:2526 to
www.macromedia.com(216.104.212.88):443
2006-03-26 11:35:58 TCP from 192.168.1.119:2527 to
qwgixxxitwrmijgy.com(67.19.31.194):80
2006-03-26 11:35:59 TCP from 192.168.1.119:2529 to
fpdownload.macromedia.com(208.185.219.177):443
2006-03-26 11:35:59 TCP from 192.168.1.119:2530 to
sleepycunt.com(67.19.85.34):80
 
G

Guest

If you have this infected file on your computer don't perform a windows update.
After a windows update basicly all applications don't work/start anymore.
As result my register file got corrupted and a new admin user needed to be
defined.

When everything worked again I updated the mcafee virusscanner who founded
and removed this infected file "voblaizdupla.exe" with the following message:
"found trojan horse: Downloader-ARL".

Regards,
Chris

..I perienced after the update problems: all office applications including
outlook didn't
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top