Home Malware Programs Rootkits Win32/Olmasco.O

Win32/Olmasco.O

Posted: December 28, 2011

Threat Metric

Ranking: 14,625
Threat Level: 8/10
Infected PCs: 199
First Seen: December 28, 2011
Last Seen: September 25, 2023
OS(es) Affected: Windows

Win32/Olmasco.O is an extremely dangerous rootkit parasite that usually initiates its destructive path from the Master Boot Record (MBR). By infecting the MBR, Win32/Olmasco.O may have full access to block actions to remove the Win32/Olmasco.O parasite. Additionally, Win32/Olmasco.O runs in the background going virtually undetected by common antivirus applications. The use of an updated antimalware program designed to specifically detect and remove rootkit infections may be necessary to rid a PC of Win32/Olmasco.O.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%TEMP%\.exe File name: %TEMP%\.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = '1'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ".exe"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ""
Loading...