Win32/Olmarik.TDL4 Analysis
Win32/Olmarik.TDL4 is a Rootkit infection that cannot be accessed according to NOD32. At the mention of Rootkit, we should know that the most important feature of this category is that they permit unauthorized access to the target system and make changes with admin privilege. In other words, the Trojan will elevate the privilege if the infected user does not belong to the admin one by modifying system registry entries. At the same time, a start-up entry will be added too to make its program codes activated once Windows gets loaded.Win32/Olmarik.TDL4 establishes network connection with remote server via a special protocol. Before doing so, if may terminate certain security-related program such as Firewall and installed antivirus program to make sure the payloads can be carried out without obstacles. Olmarik clan is found to be stealthy and sends gathered information, such as Windows edition, banking details and important log-in credentials, to the distant attacker. Besides, it may also fetch other malicious files to update this Trojan or drop other malware.
There are occasions that the audio ads will be played on the computer even before opening any browser. Some victims also observed that the computer is slow to a crawl with a high CPU consumption. Besides, it should also take full responsibility for the ransom blue screen of death or restart difficulties.
Seen in this light it's important and necessary for users to completely remove Win32/Olmarik.TDL4 before it further corrupts the system integrity and compromise end users personal information.