Results 1 to 4 of 4

Thread: How To Remove Win32/Olmarik.TDL4 Trojan

  1. #1
    Join Date
    Oct 2011
    Posts
    71

    How To Remove Win32/Olmarik.TDL4 Trojan

    Yesterday at night when I turned on my computer then I saw that all desktop icons are missing and it is completely blacked out. The start menu and folders are empty and along with that task manager was also disabled. After scanning the system with antivirus I found that my computer was infected with n32/Olmarik.TDL4 Trojan and it is not getting removed. So if anyone knows how to remove this nasty from my pc then please help me out. Thanks

  2. #2
    Join Date
    Jul 2011
    Posts
    355

    Re: How To Remove Win32/Olmarik.TDL4 Trojan

    I would like to know which variant do you have in your system. So for knowing that, you need to download a tool called aswMBR.exe from here and save it to your desktop. It is only a 4.8mb file. After the download gets completed you need to double click the aswMBR.exe file to run it and then click on Scan buttong to start the scan. Once the process is complete then click save log and then save it to your desktop and post it here in your next reply.

  3. #3
    Join Date
    Jul 2011
    Posts
    419

    Re: How To Remove Win32/Olmarik.TDL4 Trojan

    I would like to ask you to download the latest version of TDSSKiller from internet and save it to your desktop. Now double click on TDSSKiller.exe to run it and then click on Change Parameters. After that tick the boxes beside Verify Driver Digital Signature and Detect TDLFS file system and then click ok. Now click Start Scan button. If anything suspicious is found then the default action will be Skip and click on Continue. Make sure that Cure is selected and then click Continue and then Rboot to finish the cleaning process. Incase Cure is not available then do no choose delete unless you are said.

  4. #4
    Join Date
    Mar 2011
    Posts
    387
    To remove this virus, first boot your pc to Safe Mode with Networking. After that open Control Panel and seach for Folder Options. Go to View tab and tick Show hidden files and folders and untick Hide protected operating system files and then press ok. Now click on Start > Search and then delete the below files created by this virus:

    %AllUsersProfile%\Application Data\
    %AllUsersProfile%\Application Data\.exe
    %UserProfile%\Start Menu\Programs\ Win32/01marik.TDL4 \
    Software\Microsoft\Windows\CurrentVersion\Run “.exe”

    After that stop any processes of win32/olmarik.tdl4 in Task Manager. Then open Registry editor and delete the below entry:

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = ’1′
    HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B6AC5E3C-5CEB-4E72-B451-F0E1BA983C14}
    HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{94366E2C-9923-431C-B0D6-747447DD0F2B}
    HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B6AC5E3C-5CEB-4E72-B451-F0E1BA983C14}
    HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B9C7CE32-DA91-43C2-B7E9-0E9AAFC675CD}
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system “DisableTaskMgr” = ’1′
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “CheckExeSignatures” = ‘no’

Similar Threads

  1. unable to remove Win32/Olmarik.TDL4 in ESET
    By Nityaa in forum Networking & Security
    Replies: 6
    Last Post: 28-12-2011, 08:37 AM
  2. How to remove Trojan: win32/fakesysdef and trojan@winnt/alureon.s.
    By Barnard in forum Networking & Security
    Replies: 8
    Last Post: 28-08-2011, 09:50 AM
  3. Replies: 2
    Last Post: 28-07-2011, 12:47 PM
  4. How can we prevent infected from Olmarik Trojan and remove it
    By brynhildur in forum Networking & Security
    Replies: 3
    Last Post: 22-12-2010, 03:15 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,713,958,146.72274 seconds with 16 queries