Page 3 of 4 FirstFirst 1234 LastLast
Results 21 to 30 of 40

Thread: Looking to remove Win32/Olmarik.AJL trojan.

  1. #21
    Junior Member
    Join Date
    Mar 2011
    Posts
    21

    Default

    Volume in drive C has no label.

  2. #22
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    Does ESET still alert about that item or/and are there any other symptoms there?
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  3. #23
    Junior Member
    Join Date
    Mar 2011
    Posts
    21

    Default

    Nothing no. But there is still two items that come up red in aswMBR.

  4. #24
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    Please run aswMBR, scan and then fix mbr (reboot when prompted). It should create a log. Post that back here.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  5. #25
    Junior Member
    Join Date
    Mar 2011
    Posts
    21

    Default

    aswMBR version 0.9.4 Copyright(c) 2011 AVAST Software
    Run date: 2011-04-13 11:01:46
    -----------------------------
    11:01:46.264 OS Version: Windows 6.1.7600
    11:01:46.265 Number of processors: 4 586 0x402
    11:01:46.265 ComputerName: ELSQUIDO-PC UserName: El Squido
    11:01:46.825 Initialize success
    11:01:48.014 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T0L0-5
    11:01:48.015 Disk 0 Vendor: SAMSUNG_HD103SJ 1AJ100E4 Size: 953869MB BusType: 3
    11:01:48.017 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP3T1L0-6
    11:01:48.019 Disk 1 Vendor: ST3500630AS 3.AAK Size: 476940MB BusType: 3
    11:01:48.021 Disk 2 \Device\Harddisk2\DR2 -> \Device\Ide\IdeDeviceP2T0L0-3
    11:01:48.023 Disk 2 Vendor: ST3200820AS 3.AAD Size: 190782MB BusType: 3
    11:01:50.029 Disk 0 MBR read successfully
    11:01:50.031 Disk 0 MBR scan
    11:01:52.034 Disk 0 scanning sectors +1953520065
    11:01:52.063 Disk 0 scanning C:\windows\system32\drivers
    11:01:56.672 Service scanning
    11:01:57.648 Disk 0 trace - called modules:
    11:01:57.658 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll >>UNKNOWN [0x857791f8]<<
    11:01:57.661 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x866b85a0]
    11:01:57.665 3 CLASSPNP.SYS[8baba59e] -> nt!IofCallDriver -> [0x86584918]
    11:01:57.669 5 ACPI.sys[8b3413b2] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP3T0L0-5[0x8652b908]
    11:01:57.673 \Driver\atapi[0x86529298] -> IRP_MJ_CREATE -> 0x857791f8
    11:01:57.678 Scan finished successfully

  6. #26
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Good. Please run ComboFix one more time and post back its log.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  7. #27
    Junior Member
    Join Date
    Mar 2011
    Posts
    21

    Default

    Argh! It's come back up in NOD32 again.

  8. #28
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Does ESET show what item it flags as bad? Did you run ComboFix as requested, yet?
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  9. #29
    Junior Member
    Join Date
    Mar 2011
    Posts
    21

    Default

    Quote Originally Posted by Blade81 View Post
    Does ESET show what item it flags as bad? Did you run ComboFix as requested, yet?
    19/04/2011 11:35:58 Startup scanner boot sector MBR sector of the 0. physical disk Win32/Olmarik.AJL trojan ElSquido-PC\El Squido


    It seems to be messing up my graphic drivers, crashing the internet (Firefox) and my brother said NOD was trying to block an I.P from a website.

    I'll run ComboFix after your reply, maybe I should reformat.

  10. #30
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    1. Download TDSSKiller and extract its contents into a folder in desired location (i.e. c:\tdsskiller).
    2. Execute the file TDSSKiller.exe.
    3. Click Start Scan. If threats are found, select cure and click Continue (tool may prompt for a reboot).
    4. Post back contents of log file in c: drive root (name should be in UtilityName.Version_Date_Time_log.txt format)

    After that run ComboFix and post back its report + fresh dds logs.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •