Author Topic: Consrv.dll, cant find the dropper  (Read 12400 times)

0 Members and 1 Guest are viewing this topic.

BigmaccyD

  • Guest
Re: Consrv.dll, cant find the dropper
« Reply #30 on: February 17, 2012, 09:33:06 PM »
i already changed the permissions,   ::) the file was owned by the system, so i couldnt edit it

i did say in my previous post that i had added the reg edit and that i had deleted the required lines

best wishes
« Last Edit: February 17, 2012, 09:35:05 PM by BigmaccyD »

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5675
  • Spartan Warrior
Re: Consrv.dll, cant find the dropper
« Reply #31 on: February 18, 2012, 03:43:15 AM »
Quote
109.163.226.208 www.google-analytics.com.
109.163.226.208 ad-emea.doubleclick.net.
109.163.226.208 www.statcounter.com.
67.215.245.19 www.google-analytics.com.
67.215.245.19 ad-emea.doubleclick.net.
67.215.245.19 www.statcounter.com.

Browser settings in your browser can prevent third-party cookies from actively set setttings.  Most have settings to untick third party cookies from even entering the browser cache.

The above are known to be third-party cookie providers.
Windows 10 Home 64-bit 22H2 Microsoft Windows Defender - Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.4.6112 (build 24.4.9067.762) UI version 1.0.803

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Consrv.dll, cant find the dropper
« Reply #32 on: February 18, 2012, 04:52:51 AM »
Quote
The above are known to be third-party cookie providers.
Do you think google subcontrcted to an outfit in Romania? pacificrack.com is a bit shady.  Everytime one of those sites (the text) are accessed they go to the numerical site.

@BigmaccyD

Sorry I missed that in your post. By default Win7 will not allow you to save anything the any subfolder of the System32 folder. However an elevated notepad does have permission to edit the hosts.

We can clean up the tools.



From your desktop, please delete, if present
  • any notepads/logs that we created
  • DDS.scr
  • mbr.dat
  • mbr.zip
  • aswMBR.exe
  • AVG Removal Tool
You can also delete anything we saved to your usb device.

Next

press the Windows key and the R key at the same time, a run box should open. Copy and paste the following line into the run box and click OK
Combofix /uninstall

Next

Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet -  allow this.  A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.

I suggest you keep MBAM. Keep it updated and use it regularly.



Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. Windows7 firewall is pretty good so you have the basics.

You should also use Spyware Blaster to help immunize your computer.

 - SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.
 
OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.

-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

- Make sure you have reset Automatic Updates to your chosen optionClick your start button > Control Panel > System and Security > Windows updates

- Keep your antivirus program updated, as well as any other security programs you have.

-More tips and programs can be found HERE

 Please post back if you have any problems with these steps.

Thanks

BigmaccyD

  • Guest
Re: Consrv.dll, cant find the dropper
« Reply #33 on: February 18, 2012, 05:13:27 AM »
all steps completed :) apart from i dont use internet explorer, i use firefox how would i do the same in firefox as in explorer?

thanks for all your help

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5675
  • Spartan Warrior
Re: Consrv.dll, cant find the dropper
« Reply #34 on: February 18, 2012, 05:29:59 AM »
oldman,

Well, thanks to the HOSTS link, which I already have installed, I cannot connect to the numerical URL's, so this is not a problem for me.

Clicking the url results in no connection to the site.

Where did pacificrack.com come from?  Did I miss it in following this thread somewhere?  Pondus is good at getting info re this sort of stuff, so we'll see if he drops in for a moment.

VirusTotal shows re pacificrack.com:  https://www.virustotal.com/url/d135376e5b6342969957fdbd704244bc4d08dd8afd91035048b0dc18ee17fcd3/analysis/1329539040/  as clean. 

pacificcrack.com:
VT url scan  https://www.virustotal.com/url/05c8e0d49ea22e776347c1f07bb809b2d24bbc5157aad2916967812462b29972/analysis/1329539148/  in case it was a typo.

 :-\
Windows 10 Home 64-bit 22H2 Microsoft Windows Defender - Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.4.6112 (build 24.4.9067.762) UI version 1.0.803

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Consrv.dll, cant find the dropper
« Reply #35 on: February 18, 2012, 10:59:47 AM »
Hi BigmaccyD,

Security for fireFox is done through addons

http://www.notebookreview.com/default.asp?newsID=5805&review=Top+10+Best+Firefox+Security+Add-ons



@mchain

This is where those links should take you.

Quote
Host Name  : www.google-analytics.com.

IP Address : 173.194.41.133 and 173.194.41.134 and 173.194.41.135 and 173.194.41.136 and 173.194.41.137 and 173.194.41.138 and 173.194.41.139 and 173.194.41.140 and 173.194.41.141 and 173.194.41.142 and 173.194.41.143 and 173.194.41.128 and 173.194.41.129 and 173.194.41.130 and 173.194.41.131 and 173.194.41.132

Host Name  : ad-emea.doubleclick.net.

IP Address : 173.194.41.155

Host Name  : www.statcounter.com.

IP Address : 174.35.64.20 and 174.35.64.46


BigmaccyD

  • Guest
Re: Consrv.dll, cant find the dropper
« Reply #36 on: February 18, 2012, 12:54:45 PM »
ok old man, well thanks for all your time and effort in helping me resolve my problem.

thanks and best wishes

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Consrv.dll, cant find the dropper
« Reply #37 on: February 18, 2012, 07:28:09 PM »
Hi BigmaccyD,

You're welcome. Take care.