Avast WEBforum

Other => Viruses and worms => Topic started by: happyrawr on March 12, 2012, 08:43:30 AM

Title: Consrv.dll Removal Help
Post by: happyrawr on March 12, 2012, 08:43:30 AM
Hi. I've been infected with the Consrv.dll issue that others have recently had in other topics, and I need some help with removing it.

The problems it's been causing is that Google (and other search engines) will redirect to AbNow.com, Windows Firewall is deactivated and I can't change any settings, and Windows Defender is also deactivated. I've also had Pidgin (an instant messaging program) start to ask me about accepting unverified certificates when I sign-in, though I believe this is unrelated and just coincidentally having issues too. I'm not too worried about that, but thought I should mention that in case it's important. I use a gmail account with it, with the protocol set to MSN.

I've run Avast which did detect the infected files and removed them, but like others, it would result in Windows being unable to startup and then needing a system restore, which brings me back to having the infected files. I have also tried other anti-viruses (AVG, BitDefender, and others), and the ones that picked up on the infected files did the same thing.

Due to multiple system restores, I may have several anti-virus programs around on my computer (I know this is important for logs). I've also installed Comodo Firewall for now in place of Windows Firewall, and I'm not sure if any of the anti-viruses are currently active.

I'm not sure where or how I got the virus, as I haven't done anything unusual lately. I do have utorrent which could be the cause, but I haven't used it for anything since I've got the virus.

I hope that's enough information. I'm in no rush to get this fixed, but I'm not comfortable with doing manual fixes. Also, I am usually busy between things, so I may not be able to respond as quickly as possible, just to let anyone know. Any help with this will be greatly appreciated, thanks!
Title: Re: Consrv.dll Removal Help
Post by: polonus on March 12, 2012, 09:13:23 AM
Hi happyrawr,

Are you sure you do not have conflicting AV solutions running side by side on that computer. Two residential av solutions on one computer is a bad idea. However non-resident av and specific anti-malware solutions can be combined. Wait here until a qualified remover will look into your apparent infection,

polonus
Title: Re: Consrv.dll Removal Help
Post by: happyrawr on March 12, 2012, 09:23:33 AM
I've gone through several one-by-one, always uninstalling the previous anti-virus, but due to going through several system restores, the leftover folders are still on my computer. They're mostly empty, and I currently have no anti-virus in use, but I thought it might be an important detail to mention.

I normally also use just one anti-virus.
Title: Re: Consrv.dll Removal Help
Post by: essexboy on March 12, 2012, 12:08:05 PM
Could you follow the steps here http://forum.avast.com/index.php?topic=53253.0

Then post the logs in this thread
Title: Re: Consrv.dll Removal Help
Post by: happyrawr on March 12, 2012, 07:07:35 PM
Here are the logs:
Title: Re: Consrv.dll Removal Help
Post by: essexboy on March 12, 2012, 08:08:08 PM
OK found it

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

If you have Malwarebytes 1.6 or better installed please disable it for the duration of this run

Run OTL
THEN

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1  (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here  (http://forums.whatthetech.com/How_Disable_your_Security_Programs_t96260.html&pid=494216#entry494216)

1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Open notepad and copy/paste the text in the quotebox below into it:
Quote
File::
C:\Windows\SysNative\HWSCtrl.dll

NetSvc::
tdrpman

Driver::
tdrpman
Save this as CFScript.txt, in the same location as ComboFix.exe
(http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif)

Refering to the picture above, drag CFScript into ComboFix.exeWhen finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.

Title: Re: Consrv.dll Removal Help
Post by: happyrawr on March 13, 2012, 12:59:58 AM
When I hit Run Fix, I get an error message pop-up:

Cannot create file C:\windows\System32\drivers\etc\Host.

After that it seemingly does nothing. Is it supposed to take a long time (hours?) or is there a problem?
Title: Re: Consrv.dll Removal Help
Post by: essexboy on March 13, 2012, 11:58:14 AM
OK close down OTL and continue to the Combofix run, you have some protection on the host file, I will check that out later
Title: Re: Consrv.dll Removal Help
Post by: happyrawr on March 13, 2012, 04:47:29 PM
I did the procedure for Combofix, and while the program seemed to run fine, it didn't produce a log anywhere. I've done a full search on my computer for the log, and couldn't find it.
Title: Re: Consrv.dll Removal Help
Post by: essexboy on March 13, 2012, 07:24:04 PM
It should be at C:\Combofix.txt

If no could you please re-run it
Title: Re: Consrv.dll Removal Help
Post by: happyrawr on March 14, 2012, 12:33:04 AM
I have tried several times, and also re-downloaded Combofix, but no log is being created.

However, a file called "32788R22FWJFW" has appeared on my C Drive, and it links to My Computer, for whatever reason (ie, I can go back and forth by clicking C Drive and this file).
Title: Re: Consrv.dll Removal Help
Post by: essexboy on March 14, 2012, 01:45:30 PM
OK lets go a different route

Download aswMBR.exe (http://public.avast.com/~gmerek/aswMBR.exe) ( 4.1mb ) to your desktop.
 Double click the aswMBR.exe to run it  Click the "Scan" button to start scan 

(http://i1224.photobucket.com/albums/ee362/Essexboy3/aswMBR%20shots/aswMBRScan.gif)

On completion of the scan click save log, save it to your desktop and post in your next reply

(http://i1224.photobucket.com/albums/ee362/Essexboy3/aswMBR%20shots/aswMBRsavelog.gif)

THEN

Run OTL

netsvcs
%SYSTEMDRIVE%\*.exe
Drives
CREATERESTOREPOINT

Title: Re: Consrv.dll Removal Help
Post by: happyrawr on March 14, 2012, 06:15:37 PM
I ran OTL and it created the OTL file, but not the Extras one. Since CREATERESTOREPOINT disappears from the bottom during the quick scan, I thought I had mis-pasted, so I ran OTL a second time, and still no Extras file. I don't seem to be having any luck with this, heh.

If it helps at all, here are the two OTL logs I made:
Title: Re: Consrv.dll Removal Help
Post by: happyrawr on March 14, 2012, 06:16:49 PM
Sorry if double-posting is not allowed, but I forgot to include aswMBR:
Title: Re: Consrv.dll Removal Help
Post by: essexboy on March 14, 2012, 07:16:33 PM
OK most of it has gone, now I can fix the rest with combofix

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1  (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here  (http://forums.whatthetech.com/How_Disable_your_Security_Programs_t96260.html&pid=494216#entry494216)
(http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png)

(http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png)

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.



Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Title: Re: Consrv.dll Removal Help
Post by: happyrawr on March 15, 2012, 12:43:44 AM
I ran Combofix, but still no log. I checked my C drive and there's still the "32788R22FWJFW" file/folder thing, so I tried deleting it and then re-running Combofix, which created a new one.

There's no apparent changes with my computer's ability since running Combofix if that information helps.
Title: Re: Consrv.dll Removal Help
Post by: essexboy on March 15, 2012, 02:32:35 PM
On completion of this run could you run a boot scan with Avast please

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

If you have Malwarebytes 1.6 or better installed please disable it for the duration of this run

Run OTL
Title: Re: Consrv.dll Removal Help
Post by: happyrawr on March 16, 2012, 05:35:44 AM
The same thing as before, OTL won't run:

"Cannot create file C:\windows\System32\drivers\etc\Host."

I didn't do the boot scan since I'm not sure if I'm supposed to now.

Edit: After having turned off my computer and using it later, I got a black screen (ie, Explorer wouldn't start), though I was still able to use it via Task Manager. After running in safe mode and then normally, it seems to be fine with that issue. Just for informational purposes.
Title: Re: Consrv.dll Removal Help
Post by: essexboy on March 16, 2012, 05:15:52 PM
OK fun and games time again
 
For x64 bit systems download Farbar Recovery Scan Tool x64 (http://download.bleepingcomputer.com/farbar/FRST64.exe) and save it to a flash drive.
 
Plug the flashdrive into the infected PC.
 
Enter System Recovery Options.
 
To enter System Recovery Options from the Advanced Boot Options:
To enter System Recovery Options by using Windows installation disc:
On the System Recovery Options menu you will get the following options:Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt
[/list]
Title: Re: Consrv.dll Removal Help
Post by: happyrawr on March 16, 2012, 05:41:40 PM
What exactly will that do?
Title: Re: Consrv.dll Removal Help
Post by: true indian on March 16, 2012, 05:46:10 PM
What exactly will that do?

It will give a log that will give essexboy the picture of what is running and will make the cleanup task easier as when essex gives u a fix to run it via FRST the fix will be made outside windows....hence it will be wacking the malware wen it is inactive...
Title: Re: Consrv.dll Removal Help
Post by: happyrawr on March 16, 2012, 05:59:34 PM
Alright, here's the log:
Title: Re: Consrv.dll Removal Help
Post by: essexboy on March 16, 2012, 07:26:43 PM
As this is working before windows has loaded all services are inert

Download the attached fixlist.txt to the USB that has FRST on it

Go to system recovery options as before
Run FRST
(http://i1224.photobucket.com/albums/ee362/Essexboy3/Farbar/FRST2.gif)
Then press the Fix button
A fix log will be generated on the USB please post that

On completion return to normal windows and run Combofix
This should now produce a log
Title: Re: Consrv.dll Removal Help
Post by: happyrawr on March 17, 2012, 12:43:05 AM
I'm assuming fixlist works automatically with the program, since I didn't do anything otherwise?

It ran fine, produced a log, Combofix ran fine, but still no log. However, there is a Combofix file on my C Drive, that acts just like the previous "log" I've been getting (sending me to My Computer). But also, the old 32788R22FWJFW thing has turned into a folder, with sub-folder EN-US, and inside that cmd.3Xe.mui, which is 128 kb.

Fixlog:

EDIT: After rebooting and using my computer some, things are looking a lot better! I am no longer getting redirected to abnow, my internet speed is back at full, and even Pidgin is working perfectly too! :D

However, I still do not have access to Windows Firewall and Defender.
Title: Re: Consrv.dll Removal Help
Post by: essexboy on March 17, 2012, 01:08:26 PM
OK lets use another farbar tool to check out the firewall and defender - clever fellow is this one  ;D I love his tools

Once I have the log from this I will probably need to run OTL and look for specific files/registry entries.  As this programme will just tell me what is wrong

run farbar service scanner (http://download.bleepingcomputer.com/farbar/FSS.exe)

(http://i1224.photobucket.com/albums/ee362/Essexboy3/Farbar/FSS-1.jpg)

Tick "All" options.
Press "Scan".
It will create a log (FSS.txt) in the same directory the tool is run.

Please copy and paste the log to your reply.
Title: Re: Consrv.dll Removal Help
Post by: happyrawr on March 17, 2012, 06:31:20 PM
Successful:
Title: Re: Consrv.dll Removal Help
Post by: essexboy on March 17, 2012, 07:36:17 PM
Farbar Service Scanner Version: 01-03-2012


Microsoft Windows 7 Home Premium  Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Yahoo IP is accessible.


Windows Firewall:
=============
mpsdrv Service is not running. Checking service configuration:
The start type of mpsdrv service is OK.
The ImagePath of mpsdrv service is OK.

MpsSvc Service is not running. Checking service configuration:
Checking Start type: Attention! Unable to open MpsSvc registry key. The service key does not exist.
Checking ImagePath: Attention! Unable to open MpsSvc registry key. The service key does not exist.
Checking ServiceDll: Attention! Unable to open MpsSvc registry key. The service key does not exist.

bfe Service is not running. Checking service configuration:
Checking Start type: Attention! Unable to open bfe registry key. The service key does not exist.
Checking ImagePath: Attention! Unable to open bfe registry key. The service key does not exist.
Checking ServiceDll: Attention! Unable to open bfe registry key. The service key does not exist.


Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============

Windows Update:
============

Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is OK.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend: "%ProgramFiles(x86)%\Windows Defender\mpsvc.dll".


File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit


**** End of log ****
Quote
MpsSvc Service
bfe Service
OK these two are the problem

From my site download the zip file with your name
https://skydrive.live.com/?cid=32D8666F4048075B&id=32D8666F4048075B%21117
Extract the three reg files to the desktop
Right click each file and select merge
Reboot the computer

Retry firewall and Defender
Title: Re: Consrv.dll Removal Help
Post by: happyrawr on March 17, 2012, 08:45:07 PM
Would you mind editing out my name please.

Edit: I merged all 3 files and Windows Defender appears to be working, but not Windows Firewall.
Title: Re: Consrv.dll Removal Help
Post by: essexboy on March 17, 2012, 08:57:02 PM
I will delete the file once you have downloaded it - i.e. now  ;D

Could you re-run Farbar please

Then run a fresh OTL log
Title: Re: Consrv.dll Removal Help
Post by: happyrawr on March 17, 2012, 08:57:48 PM
I mean the log you posted.
Title: Re: Consrv.dll Removal Help
Post by: essexboy on March 17, 2012, 08:59:03 PM
Fixed
Title: Re: Consrv.dll Removal Help
Post by: happyrawr on March 17, 2012, 09:02:32 PM
Farbar and OTL ran fine. For OTL I assumed Scan All Users and Quick Scan:
Title: Re: Consrv.dll Removal Help
Post by: essexboy on March 17, 2012, 09:15:23 PM
Ok whilst I look at the OTL log could you go to
Control Panel > Adminstrative tools > Services
And ensure that both BFE (base filtering engine) and windows firewall are set to automatic and started

Title: Re: Consrv.dll Removal Help
Post by: happyrawr on March 17, 2012, 09:20:25 PM
Both are set to Automatic and neither are Started.
Title: Re: Consrv.dll Removal Help
Post by: essexboy on March 17, 2012, 09:25:56 PM
Start both services and let me know the result

OK another task

Go to control panel > Folder options
Select the View tab
Ensure that the following are deselected :
Hide protected System operating files
Hide hidden files and drives

Accept the warnings

Then go to this MS page and run the fixit there http://support.microsoft.com/kb/972034
Once run then reverse the steps that you previously did

Final task for now

Open an elevated command prompt :

Go Start > All programs > Accessories
Right click command prompt and select run as administrator
Then Type/copy/paste the following commands pressing enter after each :

netsh winsock reset catalog
netsh int ip reset reset.log hit
Title: Re: Consrv.dll Removal Help
Post by: happyrawr on March 17, 2012, 09:42:03 PM
I went to those two services and I'm unable to start either:

BFE: Error 5: Access Denied
Firewall: Error 1068: The dependency service or group failed to start.

I also noticed Windows Defender is Automatic (Delayed Start), and does start after a small delay.

I ran the Fixit, it ran fine, then ran those commands in command prompt, which worked fine too.

After restarting, I still am unable to start Firewall or BFE, but Defender seems to be fine now.
Title: Re: Consrv.dll Removal Help
Post by: essexboy on March 17, 2012, 10:07:37 PM
It is a permissions problem on bfe

I will give you a full export of my 64 bit key and see if that solves it

It is now at the same place as before with your name on it

Extract the bfe reg file, merge and reboot

Let me know if that works

Otherwise I will have to work out a way to change permissions for you
Title: Re: Consrv.dll Removal Help
Post by: happyrawr on March 17, 2012, 10:13:52 PM
Downloaded, merged, rebooted, but nothing changed.
Title: Re: Consrv.dll Removal Help
Post by: essexboy on March 17, 2012, 10:15:46 PM
OK 'tis a while since I changed permissions in the registry so bear with me whilst I ensure I get it right
Title: Re: Consrv.dll Removal Help
Post by: essexboy on March 17, 2012, 11:43:44 PM
OK lets get at it

First create a restore point

Download SWReg (http://fstaal01.home.xs4all.nl/downloads/swreg.exe) and save to the desktop


Create and Run a Batch File

1.
Please copy everything in the code box below into notepad. To do this highlight all text, then right click and click Copy.

Code: [Select]
@Echo Off
CLS
SWReg ACL HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BFE /P /GE:F
exit
This will put a new file on the Desktop named Fix.bat

The file icon will look like this  (http://img524.imageshack.us/img524/9383/batmp6.jpg)

2. Close all open windows and any open Browsers.

3. Right click Fix.bat file on the desktop and select run as administrator. A command window will open briefly, then close. This is quite normal.

When the command window has closed, Reboot the computer to make the changes effective.
Title: Re: Consrv.dll Removal Help
Post by: happyrawr on March 18, 2012, 06:28:01 AM
Alright! That seemed to do the trick and now Defender, Firewall and everything is back 100%!

So I'm sure there's a check via log you can instruct me to do, to make sure everything truly is all finished, and after that's done, I'd like some suggestions on setting myself up for protection so I never have to do this again, but we can discuss that later.

Thanks so much for everything and all the hard work! You have my support for Avast!
Title: Re: Consrv.dll Removal Help
Post by: essexboy on March 18, 2012, 01:44:31 PM
Nice  ;D

The only check left now is a quick run with Malwarebytes and a fresh OTL scan - to look for any orphans

If you could post/attach both logs
Title: Re: Consrv.dll Removal Help
Post by: happyrawr on March 18, 2012, 07:26:57 PM
Both ran fine:
Title: Re: Consrv.dll Removal Help
Post by: essexboy on March 18, 2012, 11:32:11 PM
Looks OK - any outstanding problems ?
Title: Re: Consrv.dll Removal Help
Post by: happyrawr on March 19, 2012, 12:03:53 AM
None that I've encountered.

Alright, so my last question is how to set myself up properly. Would combining Comodo Firewall, Malwarebytes and Avast (Free) be effective and work together without problems? Also, would it be best to uninstall and reinstall each after having gone through this virus removal?

And one other important (small) problem is that in the past when I've used Avast (Free), it would result in me needing to do a System Restore after rebooting my computer, similar to how it would when deleting Consrv.dll. I imagine this is because of some sort of virus I must've had then, and I imagine in general this is not a problem, but am I able come back to my current fixed state in the event that it happens again?
Title: Re: Consrv.dll Removal Help
Post by: essexboy on March 19, 2012, 11:36:57 AM
It would not go amiss I feel to reinstall all security programmes after this attack - the programmes themselves are probably OK so in a way it is your choice.
Anyway a fresh install ensures that there are no old version files hanging around

Avast with a firewall and MBAM is a good layered protection
Title: Re: Consrv.dll Removal Help
Post by: happyrawr on March 19, 2012, 06:38:15 PM
Alright, that should be everything then!

Thanks again for helping out! Greatly appreciated!
Title: Re: Consrv.dll Removal Help
Post by: essexboy on March 19, 2012, 06:42:55 PM
Subject to no further problems   :)

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems 

Now the best part of the day ----- Your log now appears clean  :thumbsup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset  System Restore points:

Run OTLRemove ComboFix

Run OTL and hit the cleanup button.  It will remove all the programmes we have used plus itself. 

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
(http://users.telenet.be/bluepatchy/miekiemoes/images/javaicon.gif)
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version of Java components and upgrade the application.

 Upgrading Java:
SPRING CLEAN

To manually create a new Restore Point
 Now we can purge the infected ones
Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:
(http://img233.imageshack.us/img233/7729/mbamicontw5.gif)
Malwarebytes (http://www.malwarebytes.org/mbam-download.php).  Update and run weekly to keep your system clean

Download and install FileHippo update checker (http://www.filehippo.com/updatechecker/) and run it monthly it will show you which programmes on your system need updating and give a download link

It is critical to have both a firewall and anti virus to protect your system and to keep them updated. To keep your operating system up to date visit
To learn more about how to protect yourself while on the internet read our little guide  How did I get infected in the first place ? (http://www.geekstogo.com/forum/topic/225044-preventing-malware-and-safe-computing/)

Keep safe  :wave: