Malware Removal Instructions

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Tuesday, 17 May 2011

Remove Win32/Olmarik (Uninstall Guide)

Posted on 11:54 by Unknown
Win32/Olmarik is a Trojan horse that may secretly download and install malware on your computer. It may also display fake security warnings and misleading pop ups to scare you into downloading malicious software voluntarily. Usually, Win32/Olmarik displays misleading warnings saying that your computer is infected with spyware, viruses and other malicious software. If clicked upon, these fake security alerts begin downloading rogue anti-virus software or spyware. Win32/Olmarik may also collect data (keywords entered into search engines, operating system version, etc.) and serve as a backdoor. Some variants of this Trojan can be controlled remotely. For example: Win32/Olmarik.AGF. It also replaces the original (Master Boot Record) of the hard disk drive with its own program code. There is also the Win32/OlmarikTdl4 which is a newest version of this Trojan horse. Unfortunately, Win32/Olmarik can not be manually deleted. Thankfully, there are standalone removal tools that are capable of removing this dangerous infection from your computer for free. If you computer is infected with Win32/Olmarik, please follow the removal instructions below. Clarifications and comments are welcome as usual. If you have questions, please leave a comment below. Good luck and be safe online!

Malicious processes created by Win32/Olmarik:



Win32/Olmarik variants:
  • Win32/Olmarik.AGF
  • Win32/Olmarik.RN
  • Win32/Olmarik.XG
  • Win32/Olmarik.AMN
  • Win32/Olmarik.KW
  • Win32/Olmarik.TX
  • Win32/Olmarik.ADA
  • Win32/Olmarik.JK
  • Win32/Olmarik.AJL

Win32/Olmarik removal instructions:

1. Download EOlmarikRemover and EOlmarikTdl4Cleaner (Win32/Olmarik removal tools from ESET).

2. Run both programs and follow the on-screen instructions.





3. After the rebooting, please download and run anti-malware software (direct download) to remove the leftovers of this virus from your computer.

It's possible that an infection is blocking Spyware Doctor from properly installing. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe. Don't forget to update the installed program before scanning.


Associated Win32/Olmarik files and registry values:

Files:
  • C:\WINDOWS\Zcepia.exe
  • C:\Documents and Settings\[UserName]\Local Settings\Temp\Zbl.exe
  • C:\WINDOWS\system32\rundll32.exe
  • rundll32.exe C:\WINDOWS\system32\sshnas21.dll,GetHandle
  • C:\Documents and Settings\[UserName]\pimon.exe
Registry values:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "C:\Documents and Settings\[UserName]\Local Settings\Temp\Zbl.exe"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "C:\Documents and Settings\[UserName]\pimon.exe /w"
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SSHNAS\Parameters "C:\WINDOWS\system32\sshnas21.dll"
Share the knowledge:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in Trojans | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Antivired.com and other Antivirus Monitor Related Domains
    Just a short note about several malicious domains related to the Antivirus Monitor fraud. This rogue anti-virus program reports non-existent...
  • How to Remove Easy Scan (Uninstall Guide)
    Easy Scan is a rogue application that pretends to be legitimate software, in this case registry cleaner and hard drive optimization program...
  • What is wrtc.exe and how to remove it?
    wrtc.exe - by Perion Network Ltd. What is wrtc.exe? wrtc.exe is a part of IncrediMail software, digitally signed by Perion Network Ltd. This...
  • Trojan.MBRlock, Внимание! Ваш компьютер заблокирован
    Trojan.MBRlock is a very disturbing piece of malicious code which infects the master boot record (MBR) and prevents Windows from starting. ...
  • False Positive: Ikarus and Comodo detecting TDSSKiller as a Trojan horse
    This awkward moment when you realize that your favorite rootkit removal utility is detected as malware. I probably wouldn't even have no...
  • Facebook Security and Privacy Best Practices
    Facebook is the most popular social networking site. Nearly all of my friends have Facebook accounts. They log on to Facebook at least a cou...
  • Smartphone Security: Using Your Mobile Phone Safely
    Smartphone is like a little copy of your computer with lots of personal information: photos, text messages, access to e-mail account and oth...
  • Antispyis.com and other Antivirus Scan related domains
    New additions of misleading websites which promote a rogue security application called Antivirus Scan. antispyis.com afantispy.net softwaree...
  • Fake avast! Antivirus: Avast-antivirus-francais.exe
    Cyber-criminals are attempting to benefit from unexperienced web users who are looking for anti-virus software. We found a couple of mislead...
  • Show Hidden Files and Folders in Windows
    By default Microsoft Windows hides important files from being seen with Windows Explorer in order to protect these files from being modified...

Categories

  • Adware
  • Answers
  • Antivirus software
  • Browser Hijackers
  • Cloud Computing
  • Fake Alerts
  • Giveaways
  • Hoax
  • How-To
  • IaaS
  • Internet
  • Malicious websites
  • Malware
  • PaaS
  • Parental Controls
  • Passwords
  • Phishing
  • Process Information
  • Ransomware
  • Rogue programs
  • Rootkits
  • SaaS
  • Security Advisories
  • Spam
  • Spyware
  • Trojans
  • Viruses
  • Web Browsers
  • Worms

Blog Archive

  • ►  2013 (173)
    • ►  December (6)
    • ►  November (13)
    • ►  October (11)
    • ►  September (20)
    • ►  August (4)
    • ►  July (17)
    • ►  June (31)
    • ►  May (25)
    • ►  April (15)
    • ►  March (17)
    • ►  February (7)
    • ►  January (7)
  • ►  2012 (86)
    • ►  November (2)
    • ►  October (4)
    • ►  September (6)
    • ►  August (6)
    • ►  July (11)
    • ►  June (1)
    • ►  May (5)
    • ►  April (7)
    • ►  March (7)
    • ►  February (17)
    • ►  January (20)
  • ▼  2011 (239)
    • ►  December (8)
    • ►  November (18)
    • ►  October (21)
    • ►  September (24)
    • ►  August (28)
    • ►  July (32)
    • ►  June (16)
    • ▼  May (23)
      • How to Remove Mac Guard (Uninstall Guide)
      • How to Remove ScanQuery (Uninstall Guide)
      • Remove Die offizielle Mitteilung des Bundeskrimina...
      • How to Remove Security Solution 2011 (Uninstall Gu...
      • How to Remove Security Center (Uninstall Guide)
      • "Your Windows has been blocked" Ransomware Removal...
      • How to Remove Security Shield Pro 2011 (Uninstall ...
      • How to Remove Antivirus Pro (Uninstall Guide)
      • How to Remove Essential Cleaner (Uninstall Guide)
      • Remove Win32/Olmarik (Uninstall Guide)
      • Remove Apple security center (Uninstall Guide)
      • "System process at address 0xE4783995 have just cr...
      • Remove Windows Tasks Optimizer (Uninstall Guide)
      • Remove Windows XP Recovery (Uninstall Guide)
      • Remove Windows Attention Utility (Uninstall Guide)
      • Remove Mac Protector (Uninstall Guide)
      • How to Remove "Malware Protection" (Uninstall Guide)
      • Remove Windows Oversight Center (Uninstall Guide)
      • Remove Mac Security (Uninstall Guide)
      • How to Remove PC Security Guardian (Uninstall Guide)
      • Remove "Warning! Spyware detected on your computer...
      • Remove BUNDESPOLIZEI Ransomware (Uninstall Guide)
      • Remove MACDefender (Uninstall Guide)
    • ►  April (15)
    • ►  March (16)
    • ►  February (9)
    • ►  January (29)
  • ►  2010 (2)
    • ►  December (2)
Powered by Blogger.

About Me

Unknown
View my complete profile