Avast WEBforum

Other => Viruses and worms => Topic started by: adc on February 02, 2012, 10:40:01 PM

Title: Another consrv.dll Victim Needing Help
Post by: adc on February 02, 2012, 10:40:01 PM
Greetings All,

I've been working with a friend's Asus laptop that was infected with a fake security program.

I have been able to get Avast Internet Security (AIS) running and have removed and deleted;

(1) isecurity.exe  (Fake Security App)

(2) $REEEP7L.exe described as MSIL:Dropper

and

(3) other various temp, or infected files.

I've had some of the same problems as others here. Trying to repair, or move consrv.dll
which causes a boot problem which needs to be repaired before troubleshooting can be resumed.


A current scan with AIS shows that only 4 files remain that need some type of "Action".

(1)C:\...\consrv.dll      High      Threat: Win32:Siref-HO (Rtk)
(2)C:\...\consrv.dll      High      Threat: Win32:Siref-HO (Rtk)
(3)C:\...\RLO2j3.com      High      Threat: Win32:FakeAlert-BVT (Trj)
(4)C:\...\consrv.dll      High      Threat: Win32:Siref-HO (Rtk)


I believe it is time to try and run OTL and aswMBR, but I will definitely need some guidance.

The laptop's OS Windows 7 SP1, 64 bit.

Thanks for any help.
Al
Title: Re: Another consrv.dll Victim Needing Help
Post by: Pondus on February 02, 2012, 10:45:54 PM
Quote
I believe it is time to try and run OTL and aswMBR, but I will definitely need some guidance.
you find the guide here
http://forum.avast.com/index.php?topic=53253.0


attach the logs: lower left corner > additional options > attach
Title: Re: Another consrv.dll Victim Needing Help
Post by: essexboy on February 02, 2012, 10:50:23 PM
Monitoring
Title: Re: Another consrv.dll Victim Needing Help
Post by: adc on February 02, 2012, 11:19:56 PM
Thanks for link.

Results for MalwareBytes scan and repair.

OTL is on my Desktop. 8)

++++++++
Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Database version: v2012.02.02.08

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Jwoww :: J-PC [administrator]

2/2/2012 1:55:30 PM
mbam-log-2012-02-02 (13-55-30).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 215061
Time elapsed: 5 minute(s), 50 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 3
C:\Windows\System32\RLO2j3.com (Trojan.Krypt) -> Quarantined and deleted successfully.
C:\Windows\SysWOW64\RLO2j3.com (Trojan.Krypt) -> Quarantined and deleted successfully.
C:\Users\Jwoww\Downloads\FLVPlayerSetup.exe (Adware.Agent) -> Quarantined and deleted successfully.

(end)
Title: Re: Another consrv.dll Victim Needing Help
Post by: adc on February 03, 2012, 12:15:32 AM
OTL.txt attatched.
Title: Re: Another consrv.dll Victim Needing Help
Post by: adc on February 03, 2012, 12:19:17 AM
Extras.txt attached.

Note:Both files were too large in total to place both in one reply.


Should I wait for a reply to run aswMBR?
Title: Re: Another consrv.dll Victim Needing Help
Post by: Pondus on February 03, 2012, 12:42:02 AM
Quote
Should I wait for a reply to run aswMBR?
nope...run and attach log


Essexboy is logged out now. but will be back tomorrow. He is usually in here around 08:00pm - 11:59pm UK time
Title: Re: Another consrv.dll Victim Needing Help
Post by: adc on February 03, 2012, 01:09:38 AM
Completed aswMBR scan, and the log file is attached.

Should I "Fix", or wait for a reply?

Or,should I just wait for Essexboy's reply tomorrow?

THX
Al
Title: Re: Another consrv.dll Victim Needing Help
Post by: Pondus on February 03, 2012, 01:25:53 AM
Quote
Should I "Fix", or wait for a reply?
you wait for Essexboy....so this is done properly   ;)


OBS....that is the longest aswMBR logg i have seen 
Title: Re: Another consrv.dll Victim Needing Help
Post by: adc on February 03, 2012, 01:36:31 AM

you wait for Essexboy....so this is done properly   ;)

OBS....that is the longest aswMBR logg i have seen 

I thought I might have to split the log in two in order to attach.  ;D

THX again.
Al
Title: Re: Another consrv.dll Victim Needing Help
Post by: essexboy on February 03, 2012, 09:22:27 PM
aswMBR gets better every time


Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

If you have Malwarebytes 1.6 or better installed please disable it for the duration of this run

Run OTL
THEN


Re-Run aswMBR

Click Scan

On completion of the scan
Click the   Fix Button

(http://i1224.photobucket.com/albums/ee362/Essexboy3/aswMBR%20shots/aswMBR_Zero.png)

Save the log as before and post in your next reply
Title: Re: Another consrv.dll Victim Needing Help
Post by: adc on February 03, 2012, 09:53:48 PM
Essexboy,

I started OTL 25 minutes ago (12:25 pm PST) and I got an alert box that read "Cannot create file C:\Windows\System32\drivers\etc\Hosts." I clicked "OK" and OTL has the message at the bottom that says "Resetting HOSTS file. DO NOT INTERRUPT..." and it has had that message for over 12 minutes.

OTL may be stuck.
Title: Re: Another consrv.dll Victim Needing Help
Post by: essexboy on February 03, 2012, 10:01:18 PM
OK close it out and manually reboot please - do you have spybot
Title: Re: Another consrv.dll Victim Needing Help
Post by: adc on February 03, 2012, 10:04:19 PM
OK close it out and manually reboot please - do you have spybot


Yes Spybot is installed on machine. I can remove if needed.
Title: Re: Another consrv.dll Victim Needing Help
Post by: essexboy on February 03, 2012, 10:06:33 PM
It is protecting the HOST file and it does need resetting.

So if you could uninstall when we do the final sweep OTL run
Title: Re: Another consrv.dll Victim Needing Help
Post by: adc on February 03, 2012, 10:15:26 PM
Spybot is uninstalled, and machine rebooted.

Waiting to restart OTL.
Title: Re: Another consrv.dll Victim Needing Help
Post by: essexboy on February 03, 2012, 10:21:24 PM
OK you will notice the biggest difference when aswMBR has done its thing
Title: Re: Another consrv.dll Victim Needing Help
Post by: adc on February 03, 2012, 10:24:19 PM
OK you will notice the biggest difference when aswMBR has done its thing

Don't we need to re-run OTL with your script first before running aswMBR?
Title: Re: Another consrv.dll Victim Needing Help
Post by: essexboy on February 03, 2012, 10:26:37 PM
When you ran the OTL fix resetting hosts is the last element - so it did the other removals


So go straight to aswMBR fix run now please
Title: Re: Another consrv.dll Victim Needing Help
Post by: adc on February 03, 2012, 11:16:59 PM
When you ran the OTL fix resetting hosts is the last element - so it did the other removals

So go straight to aswMBR fix run now please

The new scan with aswMBR indicated some removals had not been accomplished with OTL.

A 2nd scan with aswMBR and "FIX" appears to have quarantined all infected files.

The "fixed" aswMBR log file is attached.

Waiting for further instructions. :)
Title: Re: Another consrv.dll Victim Needing Help
Post by: essexboy on February 03, 2012, 11:22:32 PM
It does look better doesn't it  ;D

Could you now run a fresh OTL quick scan please to see what remains

How is the system behaving now ?
Title: Re: Another consrv.dll Victim Needing Help
Post by: adc on February 03, 2012, 11:28:18 PM
It does look better doesn't it  ;D

Could you now run a fresh OTL quick scan please to see what remains

How is the system behaving now ?

Yes, the log file looked much cleaner.  8)

And, I'm sure the machine is running better.

Will get a fresh OTL quick scan log for you shortly.







Title: Re: Another consrv.dll Victim Needing Help
Post by: essexboy on February 03, 2012, 11:33:46 PM
I will be off line soon as I need to listen to Harry's Game  ;D But I shall return on the morrow
Title: Re: Another consrv.dll Victim Needing Help
Post by: adc on February 03, 2012, 11:57:26 PM
I will be off line soon as I need to listen to Harry's Game  ;D But I shall return on the morrow

Attached is a "fresh" OTL log file.

Thank you.

I will monitor the laptop for awhile to watch for any strange operation.

I thought after all this, and being a member of the Avast forum since 2008, my status as "Newbie" would change, but alas it was not to be. ::)
Title: Re: Another consrv.dll Victim Needing Help
Post by: mchain on February 04, 2012, 10:56:55 AM
Quote
I thought after all this, and being a member of the Avast forum since 2008, my status as "Newbie" would change, but alas it was not to be.

User rankings dependent on number of posts made by user.   :)

It's just that you have had few problems, which is a good thing.
Title: Re: Another consrv.dll Victim Needing Help
Post by: essexboy on February 04, 2012, 12:30:52 PM
That looks pretty - could you now do the following to reset the TCPIP stack
Run the MSFixit on this page http://support.microsoft.com/kb/299357

Please download Malwarebytes' Anti-Malware[/b] (http://www.malwarebytes.org/mbam-download.php)
 
Double Click mbam-setup.exe to install the application.
Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.[/b]
Title: Re: Another consrv.dll Victim Needing Help
Post by: adc on February 04, 2012, 05:52:11 PM
That looks pretty - could you now do the following to reset the TCPIP stack
Run the MSFixit on this page http://support.microsoft.com/kb/299357


Cheers... ;D

Applied MSFixit without any error message.


I had already run a quick scan after you signed off yesterday, but ran it again this morning as you request.


Attached is the log.


Title: Re: Another consrv.dll Victim Needing Help
Post by: adc on February 04, 2012, 06:00:32 PM

It's just that you have had few problems, which is a good thing.
mchain,

You are correct. I am fortunate to have had only one "serious" problem in 4 years. :)

cheers,
Al
Title: Re: Another consrv.dll Victim Needing Help
Post by: essexboy on February 04, 2012, 06:25:37 PM
Any further problems apparent ?
Title: Re: Another consrv.dll Victim Needing Help
Post by: adc on February 04, 2012, 06:54:44 PM
Any further problems apparent ?


I do have a question about an error with the firewall as I get a Windows Firewall error when try to "Use recommended settings".

"Windows Firewall can't change some of your settings.
Error code 0x80070424"


Is this something AIS is causing, or something that needs to be corrected?

Neither Zonealarm, or Comodo are installed.

Other than this everything seems to be running normally.


Edit Added:

Windows Defender is stopped and issues an error when attempting to Start.

"The specified service does not exist as an installed service. (Error Code: 0x80070424)"
Title: Re: Another consrv.dll Victim Needing Help
Post by: essexboy on February 04, 2012, 07:00:58 PM
OK lets check for damage

run farbar service scanner (http://"http://download.bleepingcomputer.com/farbar/FSS.exe")

(http://i1224.photobucket.com/albums/ee362/Essexboy3/Farbar/fss.jpg)

Tick "All" options.
Press "Scan".
It will create a log (FSS.txt) in the same directory the tool is run.

Please copy and paste the log to your reply.
Title: Re: Another consrv.dll Victim Needing Help
Post by: adc on February 04, 2012, 07:22:56 PM
Your link doesn't work, but I found it.  :)

FSS.txt attached.
Title: Re: Another consrv.dll Victim Needing Help
Post by: essexboy on February 04, 2012, 07:35:40 PM
Oops my error a different forum software

Quote
MpsSvc Service is not running. Checking service configuration:
Checking Start type: Attention! Unable to open MpsSvc registry key. The service key does not exist.
Checking ImagePath: Attention! Unable to open MpsSvc registry key. The service key does not exist.
Checking ServiceDll: Attention! Unable to open MpsSvc registry key. The service key does not exist.

bfe Service is not running. Checking service configuration:
Checking Start type: Attention! Unable to open bfe registry key. The service key does not exist.
Checking ImagePath: Attention! Unable to open bfe registry key. The service key does not exist.
Checking ServiceDll: Attention! Unable to open bfe registry key. The service key does not exist.

wscsvc Service is not running. Checking service configuration:
Checking Start type: Attention! Unable to open wscsvc registry key. The service key does not exist.
Checking ImagePath: Attention! Unable to open wscsvc registry key. The service key does not exist.
Checking ServiceDll: Attention! Unable to open wscsvc registry key. The service key does not exist.

I am just going to upload to my site the registry keys that you are missing
Download them to your desktop
Right click each one and select merge
Accept the warnings and then re-run Farbar

https://skydrive.live.com/?cid=32D8666F4048075B&id=32D8666F4048075B%21117&sc=documents

Files are :
wscsvc.reg
bfe.reg
MpsSvc64.reg
Title: Re: Another consrv.dll Victim Needing Help
Post by: adc on February 04, 2012, 07:57:35 PM
All 3 Reg files Merged successfully.

FSS.txt attached.

Title: Re: Another consrv.dll Victim Needing Help
Post by: essexboy on February 04, 2012, 09:51:15 PM
Could you now reboot and try the firewall and defender
Title: Re: Another consrv.dll Victim Needing Help
Post by: adc on February 04, 2012, 10:10:06 PM
Reboot...

Windows Defender is still stopped and issues an error when attempting to Start.

"The specified service does not exist as an installed service. (Error Code: 0x80070424)"

The Firewall is still giving the same error as before.
Title: Re: Another consrv.dll Victim Needing Help
Post by: essexboy on February 04, 2012, 10:23:43 PM
Well all the related files and keys are there so lets go for an automated fix to kick start them

Download  Windows Repair (all in one)  from this site (http://www.tweaking.com/content/page/windows_repair_all_in_one.html)

Install the programme then run

Go to step 2 and allow it to run Disc check (This stage can be skipped)
(http://i1224.photobucket.com/albums/ee362/Essexboy3/Capture3.gif)

Once that is done then go to step 3 and allow it to run SFC
(http://i1224.photobucket.com/albums/ee362/Essexboy3/Capture.gif)


On the start repairs tab select advanced mode and click start
(http://i1224.photobucket.com/albums/ee362/Essexboy3/Capture1.gif)

Select the items ticked(remove the ticks from the rest ) and tick restart system when finished
Title: Re: Another consrv.dll Victim Needing Help
Post by: adc on February 04, 2012, 11:26:47 PM
Tweaking is still working hard at Step 5.... ::)

I forgot to tick Restart. Presume manual restart okay?
Title: Re: Another consrv.dll Victim Needing Help
Post by: essexboy on February 04, 2012, 11:41:28 PM
Aye that will work

Did the sfc scan do any changes ?
Title: Re: Another consrv.dll Victim Needing Help
Post by: adc on February 04, 2012, 11:47:29 PM
Aye that will work

Did the sfc scan do any changes ?

SFC results indicated;

"Windows Resource Protection did not find any integrity violations."

Tweaking just finished. Asking for restart.

p.s.
It's getting to be pretty late where you are..

How much longer will you be available?
Title: Re: Another consrv.dll Victim Needing Help
Post by: adc on February 04, 2012, 11:58:50 PM
Machine is back up.

The Firewall and Defender are still down.
The Firewall error appears to have changed from "0x80070424"

Current error;
"Windows Firewall can't change some of your settings.
Error code 0x8007042c"


Can't restart Defender either.
Title: Re: Another consrv.dll Victim Needing Help
Post by: adc on February 05, 2012, 03:52:41 AM
During the current lull period I ventured to the below Microsoft website and within the 11 pages I found the solution, as did many others. My Base Filtering Engine (BFE), Windows Firewall, Windows Defender are currently running.  :)

Error Code 0x80070424 with Windows Firewall, Defender in Windows 7 (http://answers.microsoft.com/en-us/windows/forum/windows_7-security/error-code-0x80070424-with-windows-firewall/ec3fc3b8-69ec-4b4b-a703-4b745fe6e8ee)

In addition I found that the protections on the laptop's 2nd Hard drive (D:) had been removed. Protection was probably disabled on D: drive during the recent Malware Attack, and rendered it unusable. I re-enabled protection on it to bring it back to life. :)

I will continue to monitor the operation of the laptop, and see if there is anything else that falls in the category of strange behavior of the OS.

For now everything is going okay, and I have attached a current FSS.exe scan. ;D

Thank you again for your expertise, and time.

I will be standing by in case you have any other requests.

Cheers,
Al
Title: Re: Another consrv.dll Victim Needing Help
Post by: adc on February 05, 2012, 09:16:07 AM
Essexboy,

I no longer have the laptop in my possession as the owner came tonight to pick it up.

It was recommended that the owner just shut the laptop off and bring it back to me immediately if the Fake Security Malware appears again. Hopefully the problem won't come back.  ::)

THX to all.  ;D  8)

Al


 
Title: Re: Another consrv.dll Victim Needing Help
Post by: essexboy on February 05, 2012, 01:33:41 PM
Yes that looked clear.  The problem I saw with the last Farbar scan was that the services were set to disabled and windows repair should have reset them as all the keys and files were in the right place just not started

The only follow up I was going to do was to remove the tools

Title: Re: Another consrv.dll Victim Needing Help
Post by: adc on February 05, 2012, 06:34:22 PM
Yes that looked clear.  The problem I saw with the last Farbar scan was that the services were set to disabled and windows repair should have reset them as all the keys and files were in the right place just not started.

The only follow up I was going to do was to remove the tools

I received a call from the laptop's owner last late night, and he was very pleased that the malware infection was eliminated.  ;D

It was a pleasure to work with you.

Clean-up accomplished.  :)  Removing the tools, reg files, and logs was the last item of business before returning the laptop.  ;D 8)

Cheers,
Al 


Title: Re: Another consrv.dll Victim Needing Help
Post by: essexboy on February 05, 2012, 06:47:10 PM
No problem - I hope you got some good tools out of it  ;D