Author Topic: Consrv.DLL Rootkit problems  (Read 8024 times)

0 Members and 2 Guests are viewing this topic.

h4zmat

  • Guest
Consrv.DLL Rootkit problems
« on: February 14, 2012, 08:46:55 AM »
I've been running every program I've ever used to clean up infected systems with no luck removing this one. Avast keeps showing that svchost is creating consrv.dll right when I turn on my computer and then again every few hours or so.
The only other symptom aside from the Avast popup is that my shortcut icons aren't showing, MBAM and Avast cleaned it up pretty well.

Thanks for any input, I appreciate the help

true indian

  • Guest
Re: Consrv.DLL Rootkit problems
« Reply #1 on: February 14, 2012, 12:00:19 PM »
malware removal expert essexboy is notified...
« Last Edit: February 14, 2012, 12:02:13 PM by true indian »

akama1

  • Guest
Re: Consrv.DLL Rootkit problems
« Reply #2 on: February 14, 2012, 12:37:12 PM »
you have to ask essexboy then :) the last time i gave my own opinion post was deleted so i dont think i sould post anymore of my suggestions here though....

jeffce

  • Guest
Re: Consrv.DLL Rootkit problems
« Reply #3 on: February 14, 2012, 04:38:44 PM »
Hi h4zmat,

Please delete the current version of Combofix.exe from your desktop and download a new version from here to your desktop.
----------

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
Code: [Select]
File::
C:\Windows\SysNative\websensecpmcommunicationagent.dll

Driver::
stunnel

NetSvcs::
stunnel
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.



  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
----------
« Last Edit: February 14, 2012, 10:15:27 PM by jeffce »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Consrv.DLL Rootkit problems
« Reply #4 on: February 14, 2012, 08:32:06 PM »
Jeff a word of caution the latest variant of this may need two or three runs with a cfscript to clear it..  I have a few like that at the moment, trying to clear the left over service with OTL may necessitate a system restore 

And welcome again to the madhouse  ;D

jeffce

  • Guest
Re: Consrv.DLL Rootkit problems
« Reply #5 on: February 14, 2012, 10:23:47 PM »
Thanks essexboy!  Yep I have been looking over some of the logs you are working as well and being sure to keep notes.  :D

h4zmat

  • Guest
Re: Consrv.DLL Rootkit problems
« Reply #6 on: February 15, 2012, 01:59:59 AM »
I ran Combofix and Avast hasn't blocked anything yet, looking good so far. All of my icons are still blank though.

jeffce

  • Guest
Re: Consrv.DLL Rootkit problems
« Reply #7 on: February 15, 2012, 02:46:50 AM »
Hi h4zmat,

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
Code: [Select]
ClearJavaCache::

AtJob::

DDS::
uInternet Settings,ProxyOverride = 127.0.0.1:9421

File::
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCService.exe
c:\windows\system32\J8FNQN1.com

Folder::
c:\programdata\IObit
c:\program files (x86)\IObit

NetSvcs::
stunnel

Driver::
AdvancedSystemCareService5
aswSP
aswSnx
aswFsBlk
stunnel
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.



  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
----------

h4zmat

  • Guest
Re: Consrv.DLL Rootkit problems
« Reply #8 on: February 15, 2012, 07:51:23 AM »
Here you go. Still no Avast popups & no icons showing

-edit- Ok so now I can't get the Avast service to start, I tried reinstalling with no luck.
« Last Edit: February 15, 2012, 09:28:07 AM by h4zmat »

true indian

  • Guest
Re: Consrv.DLL Rootkit problems
« Reply #9 on: February 15, 2012, 09:43:00 AM »
Reinstall once again and if no luck

follow the instructions given here:
http://www.avast.com/uninstall-utility

Then do a install again that will be fixed. 8)
« Last Edit: February 15, 2012, 09:59:01 AM by true indian »

jeffce

  • Guest
Re: Consrv.DLL Rootkit problems
« Reply #10 on: February 15, 2012, 07:20:19 PM »
Hi,

Let's hit it again.  :)
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
Code: [Select]
NetSvc::
stunnel

Driver::
stunnel
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.



  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
----------

h4zmat

  • Guest
Re: Consrv.DLL Rootkit problems
« Reply #11 on: February 16, 2012, 12:58:40 AM »
Reinstall once again and if no luck

follow the instructions given here:
http://www.avast.com/uninstall-utility

Then do a install again that will be fixed. 8)

That did the trick, thanks!

My latest combofix log was too big to post, I had to upload it to another website.
http://www.sendspace.com/file/fikgzx

jeffce

  • Guest
Re: Consrv.DLL Rootkit problems
« Reply #12 on: February 16, 2012, 01:37:23 PM »
Hi,

Please run a new scan with OTL
Be sure to include in the Custom Scan section the following bolded text:
netsvcs
CREATERESTOREPOINT


Once the scan is complete please post the newly created log. 

h4zmat

  • Guest
Re: Consrv.DLL Rootkit problems
« Reply #13 on: February 16, 2012, 02:32:22 PM »
Done

jeffce

  • Guest
Re: Consrv.DLL Rootkit problems
« Reply #14 on: February 16, 2012, 04:32:00 PM »
Hi h4zmat,

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Right-click and Run as Administrator dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
---------------------------------------------------
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
----------