Author Topic: OTL Analysis for consrv.dll  (Read 12484 times)

0 Members and 1 Guest are viewing this topic.

Phobophile89

  • Guest
OTL Analysis for consrv.dll
« on: February 07, 2012, 10:54:36 PM »
Hi,
   I finaly got rid of the Win7 Recovery virus, got everything back to normal like a boss!, almost. I still have this consrv.dll threats spawning again and again. Seems like that problems need a particular treatment for every case, so i got that "OTL by oldtimer" tool and did the scan. I don't seem to find an official forum to analyse the result, i noticed their's a few post of that kind and as i use Avast! i think it's the best place to post it !

Thank you !

UP : I'll folow the procedure form "Logs to assist in cleaning malware"
« Last Edit: February 08, 2012, 05:59:52 PM by Phobophile89 »

Phobophile89

  • Guest
Re: OTL Analysis for consrv.dll
« Reply #1 on: February 08, 2012, 06:02:38 PM »
Malware Byte's log
« Last Edit: February 08, 2012, 06:21:33 PM by Phobophile89 »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: OTL Analysis for consrv.dll
« Reply #2 on: February 08, 2012, 06:07:07 PM »
Quote
I still have this consrv.dll threats spawning again and again
this can be the Zero Access rootkit.......
continue with the rest of the logs from the guide ("Logs to assist in cleaning malware")  attach, not copy and paste


see below: Attachments and other options


Essexboy is notified.....
« Last Edit: February 08, 2012, 06:16:17 PM by Pondus »

Phobophile89

  • Guest
Re: OTL Analysis for consrv.dll
« Reply #3 on: February 08, 2012, 06:31:15 PM »
OTL by oldtimer didn't output the Extras.txt .
Here is the OTL.txt


Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: OTL Analysis for consrv.dll
« Reply #4 on: February 08, 2012, 06:53:52 PM »
Quote
OTL by oldtimer didn't output the Extras.txt .
that only happens at first run....so if you have run it before ?
anyway it is not that important....just some extra sys info
« Last Edit: February 08, 2012, 07:01:46 PM by Pondus »

Phobophile89

  • Guest
Re: OTL Analysis for consrv.dll
« Reply #5 on: February 08, 2012, 08:04:16 PM »
Finaly aswMBR.txt

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: OTL Analysis for consrv.dll
« Reply #6 on: February 08, 2012, 10:11:50 PM »
Looks like Avast is stopping it from respawning - so lets kill those files now

Let me know if the alerts continue

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

If you have Malwarebytes 1.6 or better installed please disable it for the duration of this run

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    Quote
    :OTL
    O2 - BHO: (no name) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No CLSID value found.
    [2012-02-06 12:31:18 | 000,000,304 | ---- | M] () -- C:\ProgramData\~nkABaemCYmTnry
    [2012-02-06 12:31:17 | 000,000,192 | ---- | M] () -- C:\ProgramData\~nkABaemCYmTnryr
    [2012-02-06 12:26:45 | 000,000,448 | ---- | M] () -- C:\ProgramData\nkABaemCYmTnry
    [2012-02-04 11:52:34 | 000,000,320 | ---- | M] () -- C:\ProgramData\~RGhqt5dtvRJvHx
    [2012-02-04 11:52:34 | 000,000,216 | ---- | M] () -- C:\ProgramData\~RGhqt5dtvRJvHxr

    :Files
    ipconfig /flushdns /c
    C:\windows\tasks\At*.job

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [CREATERESTOREPOINT]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

Phobophile89

  • Guest
Re: OTL Analysis for consrv.dll
« Reply #7 on: February 10, 2012, 07:28:06 PM »
Here's the other OTL Log, and their's an output i got after rebooting, i joined it too.
P.S.: At each boot i get a Desktop.ini opening.
« Last Edit: February 10, 2012, 07:39:12 PM by Phobophile89 »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: OTL Analysis for consrv.dll
« Reply #8 on: February 10, 2012, 08:26:16 PM »
That is a know bug with 7 - Ms has a small fixit for it here http://support.microsoft.com/kb/330132 just run the fixit button

How is the computer behaving now ?

Phobophile89

  • Guest
Re: OTL Analysis for consrv.dll
« Reply #9 on: February 10, 2012, 09:59:41 PM »
Tried the MS fix, doesn't work.
and consrv.dll still their

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: OTL Analysis for consrv.dll
« Reply #10 on: February 10, 2012, 10:03:12 PM »
Could you re-run aswMBR please as according to the last run it was not there

Phobophile89

  • Guest
Re: OTL Analysis for consrv.dll
« Reply #11 on: February 10, 2012, 11:10:49 PM »
Here's the fresh aswMBR log runned as an administrator.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: OTL Analysis for consrv.dll
« Reply #12 on: February 10, 2012, 11:26:59 PM »
Where is the indication of the infection coming from ?

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1
Link 2
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks




  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.[/b]
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.



Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

Phobophile89

  • Guest
Re: OTL Analysis for consrv.dll
« Reply #13 on: February 11, 2012, 12:34:17 AM »
So during step 2, dumphive.3xe "yes, (three)xe" crashed, after the reboot it recrashed, then combofix was telling me not to open any program because it hasn't had finished, it was idle like this for about 10 minutes untill i juste shut it, i can't open anything, Wordpad, NotePad, Google Chrome, internet explorer, avast!, OTL, combofix, adobe reader, i can't run no program, i don't have the consrv.dll threat alert, but i don't have any anti-virus nor anti malware, my computer is TOTALY unoperational, the only thing it will do is telling me i tried an unauthorised operation on a registy key marked as "to delete" (Excuse my raw french/english translation)
The threats was comming from "Objet : c:\Windows\system32\consrv.dll / infection : Win32:Sirefef... / Process : c:\windows\system32\svchost.dll"


and here's the log.

Sorry for the registy thing, i rebooted as instructed  :-[

So after a reboot and a Avast! scan, i got twice the c:\windows\system32\consrv.dll and on c:\windows\system64\consrv.dll wich i deleted, the system64 on was unreachable so every action failed, after i shut Avast!, i got the c:\windows\system32\consrv.dll threats pop-up
« Last Edit: February 11, 2012, 01:11:28 AM by Phobophile89 »

Phobophile89

  • Guest
Re: OTL Analysis for consrv.dll
« Reply #14 on: February 11, 2012, 02:27:09 AM »
Up,
So i rebooted to cure the registry issue, once done i waited for Avast! to detecte consrv.dll ... Nothing, nice. I launched a scan wich got me twice the consrv.dll in system32 and consrv.dll in system64 (Wut???), i tried to delete all, but the system64 one has the error, fill doesn't exist.

So i clicked do nothing for the system64 infection, i got that pop-up telling me consrv.dll in system32 was the win32:Sirefef... [HO] and asked me to scan at reboot, during the scan i deleted 3 time consrv.dll, then rebooted, and still get warned about the consrv.dll

The ComboFix log is in my last post.