|
nod32 win32/olmarik operation memory
|
|
11-08-2010, 21:45
Bericht: #1
|
|||
|
|||
|
nod32 win32/olmarik operation memory
Hi,
I am using windows 7 Eset Nod32 detects win32 olmarik trojan in the operating memory but it fails to disinfect it. What should I do? Please find hijackthis.log attached to this post. Ta Citaat:Logfile of Trend Micro HijackThis v2.0.4 |
|||
|
11-08-2010, 22:39
Bericht: #2
|
|||
|
|||
|
RE: nod32 win32/olmarik operation memory
Hi,
* Please download Malwarebytes' Anti-Malware from Here Double Click mbam-setup.exe to install the application.
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly. Microsoft MVP - Consumer Security Director of Research @ Malwarebytes AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Preventie---Help! Mijn computer is traag!---Mijn Blog---Volg me op Twitter.
|
|||
|
11-08-2010, 22:45
(Dit bericht is het laatst bewerkt op 11-08-2010 om 22:46 door anex.)
Bericht: #3
|
|||
|
|||
|
RE: nod32 win32/olmarik operation memory
Downloaded mbam, scanned and removed found infected items. See below.
Asked me to restart the windows so that's what I'm gonna do now. Citaat:Malwarebytes' Anti-Malware 1.46 |
|||
|
11-08-2010, 22:47
Bericht: #4
|
|||
|
|||
|
RE: nod32 win32/olmarik operation memory
Yes, please reboot and also rescan with Hijackthis and post a new HijackThis log.
Microsoft MVP - Consumer Security Director of Research @ Malwarebytes AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Preventie---Help! Mijn computer is traag!---Mijn Blog---Volg me op Twitter.
|
|||
|
11-08-2010, 22:55
Bericht: #5
|
|||
|
|||
RE: nod32 win32/olmarik operation memory
Citaat:Logfile of Trend Micro HijackThis v2.0.4 |
|||
|
11-08-2010, 23:03
Bericht: #6
|
|||
|
|||
|
RE: nod32 win32/olmarik operation memory
Hi,
* Rightclick HijackThis and select to run as administrator. Click scan and Place a check against each of the following: R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6522 O1 - Hosts: 173.192.153.178 http://www.123.com O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) * Click on Fix Checked when finished and exit HijackThis. Make sure your Internet Explorer is closed when you click Fix Checked! Then, as a doublecheck... Open Internet Explorer, In IE: Tools Menu -> Internet Options -> Connections Tab ->Lan Settings > uncheck "use a proxy server" and check to "Automatically detect settings". This because your proxysettings were modified by malware as well. Post a new HijackThis log in your next reply. Also, rescan with Eset and let me know if it still detects Olmarik and what file is responsible for this detection (if detection is still present). Reason is because the infection you were dealing with may also patch/infect a legitimate system driver - but we'll find out later. Microsoft MVP - Consumer Security Director of Research @ Malwarebytes AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Preventie---Help! Mijn computer is traag!---Mijn Blog---Volg me op Twitter.
|
|||
|
12-08-2010, 00:35
Bericht: #7
|
|||
|
|||
|
RE: nod32 win32/olmarik operation memory
ESET didn't report anything.
Citaat:Logfile of Trend Micro HijackThis v2.0.4 |
|||
|
12-08-2010, 08:48
Bericht: #8
|
|||
|
|||
|
RE: nod32 win32/olmarik operation memory
Hi,
Good to hear. How are things now? Microsoft MVP - Consumer Security Director of Research @ Malwarebytes AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Preventie---Help! Mijn computer is traag!---Mijn Blog---Volg me op Twitter.
|
|||
|
12-08-2010, 18:40
Bericht: #9
|
|||
|
|||
|
RE: nod32 win32/olmarik operation memory
I Guess I'm cured now?
Thanks |
|||
|
12-08-2010, 19:01
Bericht: #10
|
|||
|
|||
|
RE: nod32 win32/olmarik operation memory
Well, at least your computer is cured if you don't notice any problems anymore.
Glad I could help. Please read my Prevention page with lots of info and tips how to prevent this in the future. And if you want to improve speed/system performance after malware removal, take a look here. Extra note: Make sure your programs are up to date - because older versions may contain Security Leaks. To find out what programs need to be updated, please run the Secunia Software Inspector Scan. Happy Surfing again! Microsoft MVP - Consumer Security Director of Research @ Malwarebytes AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Preventie---Help! Mijn computer is traag!---Mijn Blog---Volg me op Twitter.
|
|||
|
12-08-2010, 20:34
(Dit bericht is het laatst bewerkt op 12-08-2010 om 20:42 door anex.)
Bericht: #11
|
|||
|
|||
|
RE: nod32 win32/olmarik operation memory
Thanks again for your time and useful tips.
|
|||
|
12-08-2010, 20:36
Bericht: #12
|
|||
|
|||
|
RE: nod32 win32/olmarik operation memory
You're most welcome
Microsoft MVP - Consumer Security Director of Research @ Malwarebytes AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Preventie---Help! Mijn computer is traag!---Mijn Blog---Volg me op Twitter.
|
|||
|
12-08-2010, 20:54
Bericht: #13
|
|||
|
|||
|
RE: nod32 win32/olmarik operation memory
Didn't know you are a lady
This is my first time being guided by a lady at all. I am really impressed, you are a real goddess. |
|||
|
12-08-2010, 21:32
Bericht: #14
|
|||
|
|||
|
RE: nod32 win32/olmarik operation memory
Haha, thank you
Microsoft MVP - Consumer Security Director of Research @ Malwarebytes AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Preventie---Help! Mijn computer is traag!---Mijn Blog---Volg me op Twitter.
|
|||
|
13-08-2010, 13:25
Bericht: #15
|
|||
|
|||
|
RE: nod32 win32/olmarik operation memory
I am unable to run mbam.exe. Have to rename it to mbamm.exe and then it runs ok.
That leads me to the idea that I am still infected plus I am being redirected to random jump ad sites while trying to reach results from google. Please advise goddess. |
|||
|
13-08-2010, 13:29
Bericht: #16
|
|||
|
|||
|
RE: nod32 win32/olmarik operation memory
Alright, let's have an extra look..
* Please visit this webpage for instructions for downloading and running ComboFix: http://www.bleepingcomputer.com/combofix...e-combofix Post the log from ComboFix in your next reply. Please make sure you disable ALL of your Antivirus/Antispyware/Firewall before running ComboFix..This because Security Software may see some components ComboFix uses (prep.com for example) as suspicious and blocks the tool, or even deletes it. Please visit HERE if you don't know how. Microsoft MVP - Consumer Security Director of Research @ Malwarebytes AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Preventie---Help! Mijn computer is traag!---Mijn Blog---Volg me op Twitter.
|
|||
|
13-08-2010, 14:49
Bericht: #17
|
|||
|
|||
|
RE: nod32 win32/olmarik operation memory
After renaming combofix.exe to a different name.exe I was able to run it.
Here is the log... Citaat:ComboFix 10-08-12.03 - Pavlin 08.2010 г. 13:27:05.1.2 - x86 Additionally I ran mbam again... Citaat:Malwarebytes' Anti-Malware 1.46 |
|||
|
13-08-2010, 15:14
Bericht: #18
|
|||
|
|||
|
RE: nod32 win32/olmarik operation memory
Hi,
I already had the feeling previously that there would still something be there, because this is what I posted previously: Citaat:Also, rescan with Eset and let me know if it still detects Olmarik and what file is responsible for this detection (if detection is still present).And you were indeed dealing with a patched infected system file. But since your Eset remained quiet and you didn't notice any problems anymore afterwards, I thought it was fixed after all, until today when you started to notice new problems again. I'm unsure if you also managed to get reinfected with something else on top, because I see malwarebytes suddenly reports some extra malware that wasn't present before, including a keygen. Keep in mind that cracks and keygens are the main reason why people get infected, so I suggest you stay away from that in the future if you would like to keep your system clean. Anyway, Combofix and Malwarebytes have taken care of the rest now, so you should be OK. But please run an extra scan with Malwarebytes first and selet to delete what it found, because in above report it shows that no action was taken. Then reboot. There are also still two files that need to get deleted though.. But I would like to have a sample of them first. We can do this with Combofix, so do next please.. * Open notepad - don't use any other texteditor than notepad or the script will fail. Copy/paste the text in the quotebox below into notepad: Citaat:Collect::[8] Save this as txtfile CFScript Then drag the CFScript into ComboFix.exe as you see in the screenshot below. ![]() This will start ComboFix again. Then, please visit this site: http://www.bleepingcomputer.com/submit-m...?channel=8 Where it says: "Browse to the file you want to submit", use the Browse button to navigate to the following file: C:\Qoobox\Quarantine\[8]-Submit_date_time.zip (date_time will be replaced with the date and time when this file was created) Then click the "Send File" button below in order to upload it. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply. Microsoft MVP - Consumer Security Director of Research @ Malwarebytes AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Preventie---Help! Mijn computer is traag!---Mijn Blog---Volg me op Twitter.
|
|||
|
13-08-2010, 18:05
Bericht: #19
|
|||
|
|||
|
RE: nod32 win32/olmarik operation memory
I have uploaded the zipped file [8]-Submit_2010-08-13_16.49.08
Citaat:ComboFix 10-08-12.03 - Pavlin 08.2010 г. 16:49:14.2.2 - x86 |
|||
|
13-08-2010, 19:23
Bericht: #20
|
|||
|
|||
|
RE: nod32 win32/olmarik operation memory
Hi,
Thanks for the files. This looks OK again. * Go to start > run and copy and paste next command in the field: ComboFix /Uninstall Make sure there's a space between Combofix and / Then hit enter. This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again. Let me know in your next reply how things are now. Microsoft MVP - Consumer Security Director of Research @ Malwarebytes AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Preventie---Help! Mijn computer is traag!---Mijn Blog---Volg me op Twitter.
|
|||
|
|
Gebruikers die deze discussie lezen: 3 gast(en)






![[Afbeelding: mvp.gif]](http://users.telenet.be/bluepatchy/miekiemoes/linksimages/mvp.gif)
![[Afbeelding: mbammini.png]](http://users.telenet.be/bluepatchy/miekiemoes/linksimages/mbammini.png)
![[Afbeelding: MiekiemoesBlog.2.gif]](http://feeds.feedburner.com/MiekiemoesBlog.2.gif)

![[Afbeelding: CFScript.gif]](http://users.telenet.be/bluepatchy/miekiemoes/images/CFScript.gif)