Hi, I’ve a laptop with windows 7 and i think i’ve trojan MAX++ (zeroAccess)
I’ve tried with various tools and antivirus but it is impossible clean consrv.dll
I can not modify the registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Sub Systems\ and HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems
If i delete consrv.dll, windows7 not boot and i´ve to restore it.
That would suggest that it is not replacing the registry key so I will need to have a look at that
[*]Run OTL.
[*]Select All Users
[*]Under the Custom Scan box paste this in netsvcs
%SYSTEMDRIVE%*.exe
/md5start
consrv.dll
/md5stop
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystem /s
hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs
CREATERESTOREPOINT
[*]Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
[*]When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
[*]Post both logs
When i’ve started the laptop, the redirection of google’s search has come back again
I’ve run OTL, but it does not found consrv.dll (log attach), but actually, consrv.dll is still in windows/system32
The registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems has consrv instead of winsrv.
I think that i’ve the same Driverx’s variant (consrv.dll+95p).
Attach the new Malwarebytes’s log.
[list]So far you two are the only ones I have come across
Do the following:
[*]Click on the Start button and then choose Control Panel.
[*]Click on the System and Security link.
Note: If you’re viewing the Large icons or Small icons view of Control Panel, you won’t see this link so just click on the Administrative Tools icon and skip to Step 4.
[*]In the System and Security window, click on the Administrative Tools heading located near the bottom of the window.
[*]In the Administrative Tools window, double-click on the Computer Management icon.
[*]When Computer Management opens, click on Disk Management on the left side of the window, located under Storage.
After a brief loading period, Disk Management should now appear on the right side of the Computer Management window.
Note: If you don’t see Disk Management listed, you may need to click on the |> icon to the left of the Storage icon.
Take a screen Shot of the Disk Management Window and attach the screen shot to your reply.