Author Topic: Sirefef.b, consrv.dll  (Read 6070 times)

0 Members and 1 Guest are viewing this topic.

glebidiah

  • Guest
Re: Sirefef.b, consrv.dll
« Reply #15 on: March 15, 2012, 03:30:55 PM »
Also, not sure if this is relevant or not, but trying to open any application on the machine produces an error, "Illegal operation on a registry key that has been marked for deletion."

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: Sirefef.b, consrv.dll
« Reply #16 on: March 15, 2012, 03:35:11 PM »
have you reboot twice after running Combofix ?

glebidiah

  • Guest
Re: Sirefef.b, consrv.dll
« Reply #17 on: March 15, 2012, 03:41:34 PM »
Just restarted again, all the applications work. MSE is disabled, won't turn it on again until told to, so I don't know offhand if anything is still there or not. A look in the registry shows that "HKLM\System\ControlSet001\Control\Session Manager\SubSystems\Windows" is pointing to winsrv.dll instead of consrv.dll so that hasn't been changed - looking good.
« Last Edit: March 15, 2012, 03:43:31 PM by glebidiah »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Sirefef.b, consrv.dll
« Reply #18 on: March 15, 2012, 03:56:12 PM »
Yep looks good just one or two more things to do on the repair side now.  The minor problem was Combofix failing to release the registry 

Exit all programs.
2. Click Start, and then click Control Panel.
3. Under System and Security, click Find and Fix Problems.
4. In the Task pane, click View All.
5. Click Internet Explorer Performance.
6.In the new window, click Next.
Note The troubleshooter runs and fixes all identified issues automatically.
7.Click Close.

That should reset the winsock

1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Open notepad and copy/paste the text in the quotebox below into it:
Quote
File::
C:\Windows\system32\int15.dll
C:\Windows\system32\NCPro.dll
C:\Windows\system32\NxSysMon.dll
C:\Windows\assembly\GAC_32\Desktop.ini
C:\Windows\assembly\GAC_64\Desktop.ini

NetSvc::
BVRPMPR5
AmdLLD
eeyeevnt

Driver::
BVRPMPR5
AmdLLD
eeyeevnt
Save this as CFScript.txt, in the same location as ComboFix.exe


Refering to the picture above, drag CFScript into ComboFix.exeWhen finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.


glebidiah

  • Guest
Re: Sirefef.b, consrv.dll
« Reply #19 on: March 15, 2012, 04:01:48 PM »
"Internet Explorer Performance" is not an option for me - please see the included screencap for the Troubleshoot options that are available.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Sirefef.b, consrv.dll
« Reply #20 on: March 15, 2012, 04:10:47 PM »
You are on 7 aren't you

glebidiah

  • Guest
Re: Sirefef.b, consrv.dll
« Reply #21 on: March 15, 2012, 04:11:39 PM »
Yup, Windows 7 Pro x64.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Sirefef.b, consrv.dll
« Reply #22 on: March 15, 2012, 04:18:42 PM »
OK we will do it manually  ;D

Go start > All Programs > Accessories
Right click the command prompt and select Run as Administrator

In the command window copy/paste the following commands hitting enter after each :

netsh winsock reset catalog

netsh int ip reset reset.log hit


Once done reboot

glebidiah

  • Guest
Re: Sirefef.b, consrv.dll
« Reply #23 on: March 15, 2012, 04:26:44 PM »
Done and rebooting, continue with the CFScript on startup?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Sirefef.b, consrv.dll
« Reply #24 on: March 15, 2012, 04:32:25 PM »
Yes please

Once complete can you let me know of any outstanding problems

glebidiah

  • Guest
Re: Sirefef.b, consrv.dll
« Reply #25 on: March 15, 2012, 04:50:47 PM »
Restarted after ComboFix and no issues to report. Please find the log attached. I'm going to run a Quick Scan with MSE and see if it picks up anything. Thank you very much for everything!

Quick question: I've been using a flash drive to swap the logs and scripts back and forth, should I been at all concerned about the infection transferring to it? I've been scanning it from a clean computer and nothing has cropped up, and the clean computer has no issues, so I'm not too concerned.

glebidiah

  • Guest
Re: Sirefef.b, consrv.dll
« Reply #26 on: March 15, 2012, 05:18:37 PM »
MSE reports Sirefef.AB and Sirefef.P, both in C:\Qoobox\Quarantine\... . I believe that's ComboFix's quarantine location - should I do anything to them or will trying to delete the files bring them back to life? Thanks!

glebidiah

  • Guest
Re: Sirefef.b, consrv.dll
« Reply #27 on: March 15, 2012, 05:28:50 PM »
Apparently MSE had its own ideas and while I was watching it automatically removed both items. Damnit Microsoft!

EDIT: looks like uninstalling ComboFix using Run "ComboFix /u" will get rid of them. I'd like to uninstall ComboFix before returning the computer just in case the user tries to run it. I'm thinking it should be safe to do so now, but I'll hold off in case. Thanks!

EDIT2: "ComboFix /Uninstall" did the trick. No issues to report!
« Last Edit: March 15, 2012, 06:15:59 PM by glebidiah »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Sirefef.b, consrv.dll
« Reply #28 on: March 15, 2012, 07:22:42 PM »
Yep it is uninstall  using u will just run it again   ;D

How is the computer running ?  Any further problems before I remove the tools and tidy up behind me
« Last Edit: March 15, 2012, 07:28:35 PM by essexboy »