Solved Operating memory - Win32/Olmarik.TDL4 trojan - unable to clean

Discussion in 'Virus, Spyware and Malware Removal' started by decografics, Aug 3, 2012.


Thread Status:
Not open for further replies.
  1. decografics Bronze Member

    I've Donated!
    Bronze
    Message Count:
    24
    Likes Received:
    2
    My System
    Loading...
    Hi.
    I am getting this warning from ESET NOD32 after i scanned my PC:
    Operating memory - Win32/Olmarik.TDL4 trojan - unable to clean . I cannot remove it , and has slow down my pc very bad.
    I attached the files there, and i tried to run the aswMBR.exe but it doesn't.
    Can you help?
    Thanks in advance.

    Attached Files:

  2. decografics Bronze Member

    I've Donated!
    Bronze
    Message Count:
    24
    Likes Received:
    2
    My System
    Loading...
    I read a previous topic, but i also saw that the fix is for that user only.
  3. decografics Bronze Member

    I've Donated!
    Bronze
    Message Count:
    24
    Likes Received:
    2
    My System
    Loading...
  4. Google Advertisement

  5. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,916
    Likes Received:
    3,669
    My System
    Loading...
    Sorry for the delay. But you had several responses to your thread so it appeared you were already being helped.

    There are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.

    Please note that as long as you are using any form of P2P networking to download files you can anticipate infestations of malware to occur.

    P2P file sharing used to be fairly safe. This is no longer true; continue to use P2P sharing at your own risk!

    Keep in mind that this practice may be the source of your current malware infestation.

    References... citing the risk factors, of using P2P programs:
    How cyber criminals infect victims via P2P with pirated software on Vimeo
    Malware: Help prevent the Infection
    Perils of P2P File Sharing
    How to Prevent the Online Invasion of Spyware and Adware

    I strongly recommend that you uninstall:

    BitTorrent

    You can do so using the Control Panel >> Add or Remove Programs function. However, that choice is up to you.

    As long as you have the P2P program(s) installed, per PCHF Policy, We can offer you no further assistance.

    If you choose to remove these programs, when finished: Please generate a new set of OTL logs and we'll go from there.
    decografics likes this.
  6. decografics Bronze Member

    I've Donated!
    Bronze
    Message Count:
    24
    Likes Received:
    2
    My System
    Loading...
    Thank you for your reply.
    Here is the new OTL logs file.
    Let me know what to do next.

    Attached Files:

  7. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,916
    Likes Received:
    3,669
    My System
    Loading...
    Please download TDSSKiller from here and save it to your Desktop.

    • Doubleclick TDSSKiller.exe to run the tool
    • Choose Change Parameters and make sure all the options are checked
    • Click the Start Scan button
    • After the scan has finished, click the Close button
    • Click the Report button and attach the contents of it into your next reply
    Note:It will also create a log in the C:\ directory.
  8. decografics Bronze Member

    I've Donated!
    Bronze
    Message Count:
    24
    Likes Received:
    2
    My System
    Loading...
    i got the TDSS_Undetectable.exe. Is okay? Because the usual one don't want to run...
  9. decografics Bronze Member

    I've Donated!
    Bronze
    Message Count:
    24
    Likes Received:
    2
    My System
    Loading...
    Here is the report from TDSSkiller...

    Attached Files:

  10. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,916
    Likes Received:
    3,669
    My System
    Loading...
    The log was cut off at the bottom
  11. decografics Bronze Member

    I've Donated!
    Bronze
    Message Count:
    24
    Likes Received:
    2
    My System
    Loading...
    This is from C:\ directory.

    Attached Files:

  12. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,916
    Likes Received:
    3,669
    My System
    Loading...
    Hi,

    Download Combofix from any of the links below, and save it to your desktop.

    Link 1
    Link 2


    To prevent your anti-virus application interfering with ComboFix we need to disable it. See here for a tutorial regarding how to do so if you are unsure.
    • Close any open windows and double click ComboFix.exe to run it.

      You will see the following image:
    [IMG]

    Click I Agree to start the program.

    ComboFix will then extract the necessary files and you will see this:

    [IMG]

    As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. This will not occur in Windows Vista and 7

    It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

    If you did not have it installed, you will see the prompt below. Choose YES.

    [IMG]

    Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [IMG]

    Click on Yes, to continue scanning for malware.

    When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).

    Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so.

    Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.
  13. decografics Bronze Member

    I've Donated!
    Bronze
    Message Count:
    24
    Likes Received:
    2
    My System
    Loading...
    here is the combofix log:

    Attached Files:

  14. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,916
    Likes Received:
    3,669
    My System
    Loading...
    Do you know what this file is? c:\program files\080420128083722.bat

    How is the machine running?
  15. decografics Bronze Member

    I've Donated!
    Bronze
    Message Count:
    24
    Likes Received:
    2
    My System
    Loading...
    i don't know that file, but the system is same.
    when restart it shows the NOD32 bubble warning about the virus.
    Shell i delete that file?
  16. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,916
    Likes Received:
    3,669
    My System
    Loading...
    Yes, delete that file and try running TDSSKiller once more please

Operating memory - Win32/Olmarik.TDL4 trojan - unable to clean

Thread Status:
Not open for further replies.