Kryptik/Olmarik Virus's

Discussion in 'Malware Help (A Specialist Will Reply)' started by BDol1986, Jan 14, 2010.

  1. BDol1986

    BDol1986 Private E-2

    Ok I read the rules and I must apologize in advance because I'm sure you guys won't appreciate my post containing so little information...BUT

    I was going through your steps before posting and what to include and I really couldn't run any of them.

    I started with the Superantivirus deal and it ran found nothing so I really have nothing to show for it.

    I could install MB but It would not run at all, the process was there but the program wouldn't launch. My only anti virus is nod32 which was turned off at the time.

    I could install but not run the combo one as well. Process there, program not.

    I stopped there. I saw no point in continuing with 3 steps producing ZERO results, two that wouldn't even launch.

    As I type this I have lovely commercials playing sound occasionally through my laptop built in speakers and boy is that annoying as all heck.

    Nod 32 detected the kryptik and olmarik but couldn't do anything about them. Other PC symptoms include

    1. Internet redirects
    2. If I play videos through winamp they occasionally run choppy (annoying when watching movies)

    I wish I could give you more information but my system appears to have virus's/spyware that stop me from doing quite a bit.

    Perhaps someone can help me...I guess help you to help me better if that makes any sense.

    Again I apologize in advance and thank anyone for any help they can give me. I'm sure somehow I could have done more but Its late, im tired and I've been at this problem all day long with minimal success.


    Oh wait by the way I will say what I did besides your tutorials and such. Maybe this will better help.

    1. Tried to run spybot search and destroy, result installed couldn't be launched
    2. Tried to run AVG 9.0, result installed but couldn't be launched
    3. Googled all running system processes and apparently I'm good none are suspicious.
    4. Installed and ran Nod 32 successfully, did it help I'm not sure, don't think so. Although it gave me the names of the virus's I had so I guess it was of some use.
    5. Personally went through windows/system32/program files and killbotted anything suspicious
    6. Went to add/remove programs and knocked out 1-2 suspicious files they appeared to be adware at best.
    7. Successfully ran superantivirus for it to say my system is just fine, as commercials were playing. This program did me no good, not complaining just saying.
    8. Searched my computer for all files created in the past 2 days (when my problems occured) and found pretty much nothing. Except ONE suspicious file, of course this is my opinion, but the name and location is Tmp.edb - Windows\system32\catroot2, file size is a little over 1mb (1032ISH). I find a lot of files/folders that are 0 files 0 kb. Strikes me as odd but if they were malware I'd assume that they would have to have a size. Or else what could they do?

    I'm assuming my problem is probably something along the lines of a modified file which I would have to dig quite deep and I, myself, Probably wouldn't be able to find it without the help of a good AV program though it seems these days there isn't one to speak of. That or something that is telling my computer to do this nonsense via the internet.

    Also I might add If I disable my internet....my problems are virtually none. However in this day and age what good is a computer without the internet eh?

    I'm thinking I picked up the virus(s) with some crappy freeware I carelessly must have downloaded.

    Sorry for the novel just trying to provide as much information as I can. Again I wish I didn't have to break so many forum rules but the programs you want me to run aren't working so I don't know how else to go about this.


    EDIT
    IF it helps I remember one of the programs the adware and/or virus's tried to install was called "malware defender" the irony. (listens to another commercial, the pain ><)
     
  2. BDol1986

    BDol1986 Private E-2

    Ok sorry to bump I tried to edit, *sigh* I'm failing miserable tonight.

    Ok Rootrepeal found some stuff, 12 things. That log should be attached. This is the only "success" I hope I have had so far, this I hope helps more.

    I don't understand the MGTools I tried running it, got confused. Sorry.

    I'm tempted to go ahead and killbot all of the files on the rootrepeal but i'll hold off on that for some word for someone more knowledgable.

    EDIT I think this MGlog file is what you need, maybe? Sounds right.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    Please double-click the RootRepeal.exe previously downloaded.
    • Select File then Scan
    • On the Select Drives form select drive C by "ticking" the box for drive C and click OK
    • When the scan is complete - highlight each of the following file(s) (one at a time if more then one is listed) by left clicking it. Then use right mouse click and select the Wipe File option only for each file.
      • C:\WINDOWS\system32\H8SRTfmnuxixwmu.dat
      • C:\WINDOWS\system32\H8SRTgtwnhkvujf.dll
      • C:\WINDOWS\system32\h8srtkrl32mainweq.dll
      • C:\WINDOWS\system32\H8SRTlrqhybsxdj.dll
      • C:\WINDOWS\system32\h8srtshsyst.dll
      • C:\WINDOWS\system32\H8SRTupmlusuwrp.dll
      • C:\WINDOWS\system32\H8SRTurskxlhdnn.dll
      • C:\WINDOWS\Temp\H8SRTb910.tmp
      • C:\WINDOWS\system32\drivers\H8SRTkbwvcuhnkx.sys
      • C:\Documents and Settings\Training\Local Settings\Temp\H8SRTea3b.tmp
      • C:\Documents and Settings\Training\Local Settings\Temp\h8srtmainqt.dll
    • After Wiping all files, immediately reboot your pc!
    After reboot, download/install/update and run the scanning tools you couldn't run!

    Attach the logs from the scans to your next reply.


    Also now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. BDol1986

    BDol1986 Private E-2

    Thanks for the reply, didn't know rootrepeal would wipe out that stuff for me. I ran the malwarebytes and rootrepeal again along with mgtools. Here are the results for those 3.

    Malwarebytes picked up a bunch of stuff.

    Some symptoms my system is experiencing though are internet randomly closing and REALLY slow internet. Like I have 5meg cable modem and it moves slower than 56K on a BAADDDDD day.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You ran steps in the wrong order. MGtools should have been run after the other scans not before. Please always complete instructions in the order given.

    What about the logs from SUPERAntiSpyware and ComboFix which were part of the original instructions you could not run?

    Also you need to do the below which was also requested in the READ & RUN ME.


    Uninstall the below software:
    Java(TM) 6 Update 2
    Viewpoint Media Player <-- should have been uninstalled in step 5 of the READ ME

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    You also need to cleanup all the junk in your root folder and also should read the below:
    Warning about Porn, Keygens, Cracks, and other Illegal Software
     
    Last edited: Jan 17, 2010

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds