Author Topic: consrv.dll ZeroAccess?  (Read 14888 times)

0 Members and 1 Guest are viewing this topic.

lotorien

  • Guest
consrv.dll ZeroAccess?
« on: January 20, 2012, 11:45:01 AM »
Hi, I've a laptop with windows 7 and i think i've trojan MAX++ (zeroAccess)

I've tried with various tools and antivirus but it is impossible clean consrv.dll

I can not modify the registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Sub Systems\ and HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems

If i delete consrv.dll, windows7 not boot and i´ve to restore it.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: consrv.dll ZeroAccess?
« Reply #1 on: January 20, 2012, 11:46:25 AM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: consrv.dll ZeroAccess?
« Reply #2 on: January 20, 2012, 11:53:42 AM »
Quote
consrv.dll
you should not remove this on your own...if you do it wrong you may have a none working comp

you need help fom Essexboy on this so follow the guide Asyn gave you

lotorien

  • Guest
Re: consrv.dll ZeroAccess?
« Reply #3 on: January 20, 2012, 12:30:49 PM »
Thanks very much

Attach actual log Malwarebytes and another (2012-01-19) with the problem.

lotorien

  • Guest
Re: consrv.dll ZeroAccess?
« Reply #4 on: January 20, 2012, 01:03:41 PM »
Atttach OTL log

Sorry, but i lost extra.log and if i run again OTL, it only appears OTL.txt

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: consrv.dll ZeroAccess?
« Reply #5 on: January 20, 2012, 01:05:53 PM »
Quote
Sorry, but i lost extra.log and if i run again OTL, it only appears OTL.txt
the extra is only produced at first run....just some extra technical info. OTL.txt is the important one

From that log it seems you have TrendMicro AV and not avast...is this correct?

dont worry, Essexboy will fix it anyway....just curious   ;D
« Last Edit: January 20, 2012, 01:11:25 PM by Pondus »

lotorien

  • Guest
Re: consrv.dll ZeroAccess?
« Reply #6 on: January 20, 2012, 01:19:33 PM »
It is a corporative laptop  :-X I don´t like Trend Micro.
Attach aswMBR

lotorien

  • Guest
Re: consrv.dll ZeroAccess?
« Reply #7 on: January 20, 2012, 01:27:15 PM »
And RogueKiller report.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: consrv.dll ZeroAccess?
« Reply #8 on: January 20, 2012, 01:29:31 PM »
Essexboy is usually in here around 08:00pm - 11:59pm UK time

lotorien

  • Guest
Re: consrv.dll ZeroAccess?
« Reply #9 on: January 20, 2012, 01:32:05 PM »
Thanks very much

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: consrv.dll ZeroAccess?
« Reply #10 on: January 20, 2012, 01:40:50 PM »
I see that you have run combofix - could you post that log please


lotorien

  • Guest
Re: consrv.dll ZeroAccess?
« Reply #11 on: January 20, 2012, 01:55:50 PM »
Yes, but after it runs, i've to restore windows.
Attach the log.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: consrv.dll ZeroAccess?
« Reply #12 on: January 20, 2012, 02:07:09 PM »
That would suggest that it is not replacing the registry key so I will need to have a look at that

  • Run OTL.
  • Select All Users
  • Under the Custom Scan box paste this in
netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
consrv.dll
/md5stop
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystem /s
hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs
CREATERESTOREPOINT

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Post both logs

lotorien

  • Guest
Re: consrv.dll ZeroAccess?
« Reply #13 on: January 20, 2012, 08:42:42 PM »
Here it's OTL's log

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: consrv.dll ZeroAccess?
« Reply #14 on: January 20, 2012, 10:19:40 PM »
OK there does not appear to be a subsystem key which is a tad weird

So could you go to my site https://skydrive.live.com/?cid=32d8666f4048075b#cid=32D8666F4048075B&id=32D8666F4048075B%21117
Locate and download subsystem.reg to your desktop

Once done I will use OTL to kill all processes and delete the offending file


OTL FIX

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    Quote
    :PROCESSES
    KILLALLPROCESSES

    :Files
    c:\windows\system32\consrv.dll
    c:\windows\assembly\tmp\U
  • Then click the Run Fix button at the top
  • Let the program run unhindered.


Do not reboot

Right click the reg file and select merge
Accept the warnings
Run an Avast quick scan