Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET NOD32 Antivirus Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #26  
Old November 10th, 2009, 06:38 PM
ccomputertek ccomputertek is offline
Frequent Poster
 
Join Date: Jul 2009
Posts: 365
Default Re: Win32/Olmarik.OF Virus - Can't Delete

Just assume that it's your C: drive and for some reason when you boot into the OS it's remapping it to a different drive letter, that said:

from the root of C which your allready on in recovery console " copy atapi.sys c:\windows\system32\drivers\ " is the command without the quotes.
  #27  
Old November 10th, 2009, 07:17 PM
azforexman azforexman is offline
Infrequent Poster
 
Join Date: Nov 2009
Posts: 16
Default Re: Win32/Olmarik.OF Virus - Can't Delete

Quote:
Originally Posted by ccomputertek
Just assume that it's your C: drive and for some reason when you boot into the OS it's remapping it to a different drive letter, that said:

from the root of C which your allready on in recovery console " copy atapi.sys c:\windows\system32\drivers\ " is the command without the quotes.

I tried that and here is what I get:

c:\windows>copy atapi.sys c:\windows\system32\drivers\

The system cannot find the file specified.

Any other ideas?

Thanks,
Jeff
  #28  
Old November 10th, 2009, 07:41 PM
ccomputertek ccomputertek is offline
Frequent Poster
 
Join Date: Jul 2009
Posts: 365
Default Re: Win32/Olmarik.OF Virus - Can't Delete

I don't know what you got going on then, you need to go into windows xp disk management from computer management in the administrative tools and delete that unused partition.

try to switch to the D: drive which is the next drive letter should be your CD drive the xp disc in it and try the expand command following instructions previously posted here all from recovery console.

make sure your in the D:\I386 dir when you do it.
  #29  
Old November 11th, 2009, 02:06 AM
trencan trencan is offline
Eset Staff
 
Join Date: Nov 2008
Posts: 119
Default Re: Win32/Olmarik.OF Virus - Can't Delete

Quote:
Originally Posted by azforexman
I tried that and here is what I get:

c:\windows>copy atapi.sys c:\windows\system32\drivers\

The system cannot find the file specified.

Any other ideas?

Thanks,
Jeff

It failed because if i remember well, last time when logged to XP you extracted atapi.sys file to I:. Now when you are in recovery console it should be in C:. But when you issued "copy" command, you were in C:\windows directory and there is no atapi.sys file. So you should type in recovery console:
copy c:\atapi.sys c:\windows\system32\drivers\

or switch to CD drive as ccomputertek wrote, go to I386 folder and type:
expand -r atapi.sy_ c:\windows\system32\drivers\
  #30  
Old November 11th, 2009, 02:19 AM
trencan trencan is offline
Eset Staff
 
Join Date: Nov 2008
Posts: 119
Default Re: Win32/Olmarik.OF Virus - Can't Delete

This I: volume looks really strange. Its size is 103 MB and filesystem is unknown.

Boot into XP, start cmd.exe and type: "diskpart" then "list disk" and "list volume". Post the output here.
  #31  
Old November 11th, 2009, 09:58 AM
azforexman azforexman is offline
Infrequent Poster
 
Join Date: Nov 2009
Posts: 16
Default Re: Win32/Olmarik.OF Virus - Can't Delete

Quote:
Originally Posted by trencan
This I: volume looks really strange. Its size is 103 MB and filesystem is unknown.

Boot into XP, start cmd.exe and type: "diskpart" then "list disk" and "list volume". Post the output here.

I attached the screenshot. I will try what you recommended from the previous post. I just have to wonder if I have something more going on then just the virus.

Thanks again for all your help.

Jeff
Attached Images
 
  #32  
Old November 11th, 2009, 04:24 PM
ccomputertek ccomputertek is offline
Frequent Poster
 
Join Date: Jul 2009
Posts: 365
Default Re: Win32/Olmarik.OF Virus - Can't Delete

As I said before, windows is switching around your drive letters, but from DOS which is the recovery console, it should always be the C: drive then your CD drive as the next letter D:
  #33  
Old November 11th, 2009, 09:45 PM
Durad's Avatar
Durad Durad is offline
Frequent Poster
 
Join Date: Aug 2005
Location: Canada
Posts: 450
Default Re: Win32/Olmarik.OF Virus - Can't Delete

You probably installed Windows with card reader attached to the PC, thats why its not C.

When you are installing Windows, always disconnect card reader and when instalation is done just plug it back
__________________
Debian Lenny with few hours of setup, no Antivirus
  #34  
Old November 11th, 2009, 09:48 PM
azforexman azforexman is offline
Infrequent Poster
 
Join Date: Nov 2009
Posts: 16
Default Re: Win32/Olmarik.OF Virus - Can't Delete

Quote:
Originally Posted by Durad
You probably installed Windows with card reader attached to the PC, thats why its not C.

When you are installing Windows, always disconnect card reader and when instalation is done just plug it back

You are correct. I did have a usb thumb drive attached. Is it possible to reassign the drive letters so they are the default setting? Or is it not worth it?

Jeff
  #35  
Old November 11th, 2009, 09:50 PM
azforexman azforexman is offline
Infrequent Poster
 
Join Date: Nov 2009
Posts: 16
Smile Re: Win32/Olmarik.OF Virus - Can't Delete

Success! Here is what worked: copy c:\atapi.sys c:\windows\system32\drivers\ I typed this in the recovery console and it replaced the file. I ran a full scan with no viruses found.

I appreciate the help from this forum.

Best regards,
Jeff - AZForexman
  #36  
Old November 12th, 2009, 01:42 AM
trencan trencan is offline
Eset Staff
 
Join Date: Nov 2008
Posts: 119
Default Re: Win32/Olmarik.OF Virus - Can't Delete

There is no drive letter assigned to that 103 MB partition in your XP.

You can run "diskpart" and type:
select disk 0
detail disk
list partition

What's the output?
  #37  
Old November 12th, 2009, 02:33 PM
SolidState SolidState is offline
Infrequent Poster
 
Join Date: Dec 2007
Posts: 14
Default Re: Win32/Olmarik.OF Virus - Can't Delete

I'd nuke the install period as you seem to be one of those people who don't understand how to delete a partition when you reinstall your OS or understand that having a card reader connected at windows install will cause drive letter assignment issues. It's a real nightmare to change the windows drive letter back to C: from I: because a lot of your applications are installed pointing to I: Dude it's a borked windows install... reinstall but be sure to delete your partitions first.

Solid-State

PS When you do reinstall windows you have to remove your internal card reader from your USB controller or you'll just have the same problem over and over again!
  #38  
Old November 12th, 2009, 05:35 PM
format_c's Avatar
format_c format_c is offline
Regular Poster
 
Join Date: May 2008
Posts: 74
Default Re: Win32/Olmarik.OF Virus - Can't Delete

Quote:
Originally Posted by azforexman
Thanks for the response. Do you have any links to instructions on how to do this? I have the OS disk but I'm not sure how to replace just that file.

it's very easy to clean the system, just run Dr.Web CureIt!. why must someone do so stupid things like the file replacement?!
__________________
Using:
brains and hands
  #39  
Old November 12th, 2009, 06:59 PM
azforexman azforexman is offline
Infrequent Poster
 
Join Date: Nov 2009
Posts: 16
Default Re: Win32/Olmarik.OF Virus - Can't Delete

Quote:
Originally Posted by trencan
There is no drive letter assigned to that 103 MB partition in your XP.

You can run "diskpart" and type:
select disk 0
detail disk
list partition

What's the output?

Ok. I attached the screenshot.

Thanks again,
Jeff
Attached Images
 

Last edited by azforexman : November 12th, 2009 at 07:05 PM.
  #40  
Old November 12th, 2009, 08:09 PM
SolidState SolidState is offline
Infrequent Poster
 
Join Date: Dec 2007
Posts: 14
Default Re: Win32/Olmarik.OF Virus - Can't Delete

Quote:
Originally Posted by azforexman
Ok. I attached the screenshot.

Thanks again,
Jeff


If that machine is a prefab then it's the recovery partition. I wouldn't nuke that friend.

Solid-State
  #41  
Old November 12th, 2009, 11:03 PM
ccomputertek ccomputertek is offline
Frequent Poster
 
Join Date: Jul 2009
Posts: 365
Default Re: Win32/Olmarik.OF Virus - Can't Delete

Recovery partition would not be 103 MB in size.But he can check whats on the drive.
  #42  
Old November 13th, 2009, 02:25 AM
SolidState SolidState is offline
Infrequent Poster
 
Join Date: Dec 2007
Posts: 14
Default Re: Win32/Olmarik.OF Virus - Can't Delete

Yeah that's rather small. It's some remnant of a partition he manged to create when he reinstalled windows with the borked I: active partition.

Solid-State

PS if windows install fails at some point could it leave this behind but still manage to get a working install?

Last edited by SolidState : November 13th, 2009 at 02:38 AM.
  #43  
Old November 13th, 2009, 11:32 AM
ESS3's Avatar
ESS3 ESS3 is offline
Infrequent Poster
 
Join Date: Dec 2007
Posts: 37
Wink Re: Win32/Olmarik.OF Virus - Can't Delete

Quote:
Originally Posted by Marcos
It's a rootkit so the best would be to boot from a clean media and replace atapi.sys with a clean file from the Windows installation cd or another clean computer with the very same OS.
Marcos
Hi,

I shot a video clip(HD) clean Olmarik(atapi.sys) with the aid of Eset SysRescue: http://www.youtube.com/watch?v=IgOKCC2lAMw

http://smages.com/i/be/85/be85920e8e...4dee38f318.png

__________________
ESET Smart Security 4.0.467.0
Windows Vista Ultimate x64 SP2
  #44  
Old November 15th, 2009, 12:08 AM
Nomad Soul's Avatar
Nomad Soul Nomad Soul is offline
Infrequent Poster
 
Join Date: Jul 2009
Location: Russia, Khabarovsk
Posts: 12
Default Re: Win32/Olmarik.OF Virus - Can't Delete

Dr.Web CureIt, that's the answer. The only antivirus that can cure this active rootkit.
__________________
Dr.Web Security Space Windows 7 Ultimate x32
  #45  
Old November 15th, 2009, 12:10 AM
Fajo's Avatar
Fajo Fajo is offline
Very Frequent Poster
 
Join Date: Jun 2008
Location: La La Land.
Posts: 1,045
Default Re: Win32/Olmarik.OF Virus - Can't Delete

Quote:
Originally Posted by Nomad Soul
Dr.Web CureIt, that's the answer. The only antivirus that can cure this active rootkit.

This should not be in the Eset Support form. He aint looking for recommendations for other AV's just how to fix his current problem.
__________________
Norton Intenet Secuirty 2010. (Real time Protection)
Linksys WRT54G v4 Running DD-WRT v24 SP2 Special Edition. (Firewall)
"Things in my signature are being currently tested or trialed this is not my main setup and may not be up to date."
 

Wilders Security Forums > Official ESET Support Forum > ESET NOD32 Antivirus Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 07:56 PM.


Powered by vBulletin® Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2009, Wilders Security Forums