Cannot start computer after removing viruses with Avast

After installing avast, it found a virus called consrv.dll Avast removed the virus, but my computer wouldn’t start even in safe mode. i had to rollback to a point before avast was installed:[

My computer has been reeeeally slow lately, i keep getting weird redirects (i think thats something else though), and i cant open things like windows firewall and defender. i have run many scans with malwarebytes, but it didn’t find anything. i have no idea what im doing and i dont want to break my computer.

Useful information:

Windows 7 Home
Malwarebytes is installed
TDSSkiller is installed
[TDSSkiller is not an antivirus, its just an antirootkit utility]
Secunia PSI is installed
There is a folder called System64 In C:windows. i dont think that was always there…

Any help would be greatly appreciated.

Thanks!
-Sam

follow this guide and attach (not copy and paste) Logs from malwarebytes / OTL / aswMBR
http://forum.avast.com/index.php?topic=53253.0

when done, essexboy will be notified…

Ok here are the logs…

OK this will need a minimum of two runs, as it is an old variant

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

https://dl.dropbox.com/u/73555776/OTL_Fix.GIF

:OTL [2012/06/19 18:26:06 | 000,525,301 | ---- | M] () (No name found) -- C:\USERS\SAM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XTON9W5O.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI O4 - HKU\.DEFAULT..\Run: [dplaysvr] C:\Windows\system32\config\systemprofile\AppData\Local\dplaysvr.exe File not found O4 - HKU\S-1-5-18..\Run: [dplaysvr] C:\Windows\system32\config\systemprofile\AppData\Local\dplaysvr.exe File not found O4 - HKLM..\Run: [cpQeUCMUEXwA.exe] C:\ProgramData\cpQeUCMUEXwA.exe File not found [2012/04/11 20:52:43 | 000,000,160 | ---- | C] () -- C:\ProgramData\-xaTBmMNLGfOwB9r [2012/04/11 20:52:43 | 000,000,000 | ---- | C] () -- C:\ProgramData\-xaTBmMNLGfOwB9 [2012/04/11 20:52:39 | 000,000,256 | ---- | C] () -- C:\ProgramData\xaTBmMNLGfOwB9 [2012/04/11 20:42:23 | 000,000,160 | ---- | C] () -- C:\ProgramData\-AefGmHo9FZhif5r [2012/04/11 20:42:23 | 000,000,000 | ---- | C] () -- C:\ProgramData\-AefGmHo9FZhif5 [2012/04/11 20:42:20 | 000,000,256 | ---- | C] () -- C:\ProgramData\AefGmHo9FZhif5

:Files
ipconfig /flushdns /c

:Commands
[purity]
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]


[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

THEN

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

[*]Double click on ComboFix.exe & follow the prompts.
[*]Accept the disclaimer and allow to update if it asks

http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png

http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png

[*]When finished, it shall produce a log for you.
[*]Please include the C:\ComboFix.txt in your next reply.

Notes:

  1. Do not mouse-click Combofix’s window while it is running. That may cause it to stall.
  2. Do not “re-run” Combofix. If you have a problem, reply back for further instructions.
  3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

This is all that i see when trying to disable the firewall.
Does this mean that its disabled and is it safe to continue with OTL and Combofix?
[the picture was too big to upload]

http://www.facebook.com/photo.php?fbid=449634978388105&set=a.118943851457221.17433.100000248193081&type=1&theater

Yes continue with both the OTL followed by Combofix, do not allow Avast to sandbox or quarantine anything

I did OTL and then combofix. it seemed fine but i tried opening firefox and it said something along the lines of “this has been marked for deletion.” i tried to restart, but now windows will not start:[
the only options i have are start windows normally or launch startup repair
what should i do?

First try start windows normally please

same thing happened. it still shows those two as the only options.

How did you shut the computer down ?

Select startup repair
If it does not work
Does your safe mode have this option ?

http://i1224.photobucket.com/albums/ee362/Essexboy3/RepairVista_7277.jpg

If not then do the following please

Download the following three programmes to your desktop :

  1. WiNTobootic
  2. Windows 7 64bit RC
  3. Farbar Recovery Scan Tool x64

Extract wintoboot to your desktop
Insert a USB drive of at least 4GB
Run Wintoboot

http://dl.dropbox.com/u/73555776/wintoboot.JPG

Drag and drop the Windows 7 ISO to the programme in the space indicated
Tick the Format box and accept the warnings
Press Do It

You will see it progressing

http://dl.dropbox.com/u/73555776/usb%20progress.JPG

It will let you know when it is done
Then copy FRST to the same USB

http://dl.dropbox.com/u/73555776/frstwintoboot.JPG

Insert the USB into the sick computer and start the computer. First ensuring that the system is set to boot from USB
Note: If you are not sure how to do that follow the instructions Here

When you reboot you will see this although yours will say windows 7. Click repair my computer

http://i1224.photobucket.com/albums/ee362/Essexboy3/RepairVista_7275.jpg

Select your operating system

http://i1224.photobucket.com/albums/ee362/Essexboy3/RepairVista_7277202.jpg

Select Command prompt

http://i1224.photobucket.com/albums/ee362/Essexboy3/RepairVista_7277.jpg

At the command prompt type the following :

notepad and press Enter.
The notepad opens. Under File menu select Open.
Select “Computer” and find your flash drive letter and close the notepad.
In the command window type e:\frst64.exe and press Enter
Note: Replace letter e with the drive letter of your flash drive.
The tool will start to run.
When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

Here is the log for the Farbar scan

Sorry i cant copy and paste the log. Its too big…

Download the attached fixlist.txt to the same USB as FRST
Start FRST as before
Press the Fix button

Reboot to normal windows

it booted up as normal :smiley:
it seemed to boot much faster this time.

here are the logs for the OTL fix, Combofix, and Fixlog for FRST.
im not totally sure what the 06242012_145119.log is, but it had yesterdays date on it so i assume it was some combofix or otl related…

Does everything look ok?

I see what happened there, combofix failed to stop/delete the protection driver. Once this run is complete can you let me know how the computer is behaving

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

https://dl.dropbox.com/u/73555776/OTL_Fix.GIF

:OTL [2012/04/05 10:26:28 | 000,002,048 | -HS- | C] () -- C:\Windows\assembly\temp\@

:Files
ipconfig /flushdns /c
C:\Windows\assembly\temp\U

:Commands
[purity]
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]


[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

It seems fine:]
Here is the log.

Is everything ok?
Can i install the windows updates? [there are 37. i guess the virus stopped the updates]

Thank you for all of your help. You’re a lifesaver!!!

The log

Yep get them there updates ;D

Subject to no further problems :slight_smile:

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems

Now the best part of the day ----- Your log now appears clean :thumbsup:

A good workman always cleans up after himself so…The following will implement some cleanup procedures as well as reset System Restore points:

Run OTL
[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

:Commands [resethosts] [emptytemp] [Reboot]

[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done

Remove ComboFix

[*]Hold down the Windows key + R on your keyboard. This will display the Run dialogue box
[*]In the Run box, type in ComboFix /Uninstall (Notice the space between the “x” and “/”) then click OK

http://i1224.photobucket.com/albums/ee362/Essexboy3/Misc%20screen%20shots/CF_Uninstall-1.jpg

[]Follow the prompts on the screen
[
]A message should appear confirming that ComboFix was uninstalled

Run OTL and hit the cleanup button. It will remove all the programmes we have used plus itself.

We will now confirm that your hidden files are set to that, as some of the tools I use will change that

[*]Go to control panel
[*]Select folder options (Appearance > Folder options in category view)
[*]Select the View Tab.
[*]Under the Hidden files and folders heading select Do not show hidden files and folders.
[]Click Yes to confirm.
[
]Click OK.

http://users.telenet.be/bluepatchy/miekiemoes/images/javaicon.gif

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version of Java components and upgrade the application.

Upgrading Java:

[] Go to this site and click Do I have Java
[
] It will check your current version and then offer to update to the latest version

SPRING CLEAN

To manually create a new Restore Point

[*]Go to Control Panel and select System
[*]Select System
[*]On the left select System Protection and accept the warning if you get one
[*]Select System Protection Tab
[*]Select Create at the bottom
[*]Type in a name i.e. Clean
[*]Select Create

Now we can purge the infected ones

[*]GoStart > All programs > Accessories > system tools
[*]Right click Disc cleanup and select run as administrator
[*]Select Your main drive and accept the warning if you get one
[*]For a few moments the system will make some calculations
[*]Select the More Options tab
[*]In the System Restore and Shadow Backups select Clean up
[*]Select Delete on the pop up
[]Select OK
[
]Select Delete

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

http://img233.imageshack.us/img233/7729/mbamicontw5.gif

Malwarebytes. Update and run weekly to keep your system clean

Download and install FileHippo update checker and run it monthly it will show you which programmes on your system need updating and give a download link

It is critical to have both a firewall and anti virus to protect your system and to keep them updated. To keep your operating system up to date visit

[*]Microsoft Windows Update

To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?

Keep safe :wave:

Umm…combofix is “Scanning for infected files”

i ran Combofix /Unistall

is this normal?

Combofix /Unistall
You missed out the second [b]n[/b] in uni[b]n[/b]stall so combofix ignored the switch and ran a scan instead

Try again when it has finished