Avast WEBforum
Other => Viruses and worms => Topic started by: shadowspiker on February 07, 2012, 03:41:39 PM
-
Basically self explanatory.
I have a reoccurring virus called consrv.dll in C:\windows\system32
i can delete it with avast but it comes back every 10min
the properties of the virus say its a Win32:Sirefef-HO [Rtk]
the virus hasnt had a chance to actually do anything cos it gets deleted straight away
Also when i run scans with malware bytes and avast they pick up nothing saying my pc is clean.
would appreciate any help to stop this.
Also just started getting a new virus in C\windows\Assembly
Temp\U there are multiple files called 80000004.$
80000032.$
80000032.@
the properties of this virus say its a Win64:Zaccess-A [Trj]
I am running Windows 7 by the way
same issue with deleting them and then they come back a few minutes later
-
This needs further analysis by a malware removal specialist:
Go to this topic http://forum.avast.com/index.php?topic=53253.0 (http://forum.avast.com/index.php?topic=53253.0) for information on Logs to assist in cleaning malware. Use the information about getting and using the logs and attach the logs here, not in the LOGS topic.
-
Hi this appears to be the new one
First could you go to taskmanager and select services
Look for a service called Safety Settings Service or something similar
Right click and select "go to process"
Make a note of the file that it shows
Re-Run aswMBR
Click Scan
On completion of the scanClick the Fix Button
(http://i1224.photobucket.com/albums/ee362/Essexboy3/aswMBR%20shots/aswMBR_Zero.png)
Save the log as before and post in your next reply
-
i just reinstalled windows
i was able to get rid of the reoccurring consrv.dll but i was constantly getting the 80000032.@ file and random .ini and .dlls were popping up everywhere
so i cut my losses and reformatted.
thank you so much for the help though
-
The reason I believed it was the new one is due to you having run combofix yet the consrv came back.. Did you try an aswMBR fix at all prior to coming here ?