consrv.dll

Picked up a virus somewhere… System was redirecting on google searches… then installing via javascript isecurity.exe. I’ve mashed it with several virus removal programs and have my system currently working. Microsoft security essentials keeps detecting win64/sirefef.b in system32/consrv.dll file.
Removing it constantly only to have the consrv.dll file return. The odd scan from microsoft essentials shows win32/unruy.h. Log from essentials shows
I’ve attached the Unruy.h report from essentials and other logs.

Running combofix will put my system into blue screen next boot. with a %hs missing error. I have to repair the system by using a windows 7 boot disk to edit the registry. Load the system hive and edit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\SubSystems
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Session Manager\SubSystems

%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=consrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16

Changing consrv.dll to winsrv.dll fixes…

Can’t seem to shake this one… Please help…

Attached logs…

Thanks in advance.

Thank you for attaching the logs.

essexboy has been notified. As there is a bit of a time zone difference (7 hours USA) might be a little bit before he comes online.

Suggest not running additional programs without his supervision, as you have seen, this one can prevent your system from booting normally. Please be patient.

Hi I see you have run combofix, can you delete that copy from your desktop please

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

If you have Malwarebytes 1.6 or better installed please disable it for the duration of this run

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

:OTL DRV - [2012/02/24 14:27:34 | 000,061,440 | ---- | M] () [Kernel | Boot | Stopped] -- C:\Windows\system32\drivers\ueffjs.sys -- (tsux) DRV - [2012/02/24 14:09:46 | 000,061,440 | ---- | M] () [Kernel | Boot | Stopped] -- C:\Windows\system32\drivers\vsagl.sys -- (zasqciz) DRV - [2012/02/24 14:04:00 | 000,061,440 | ---- | M] () [Kernel | Boot | Stopped] -- C:\Windows\system32\drivers\gdghbwfs.sys -- (ukdzjk) @Alternate Data Stream - 989 bytes -> C:\ProgramData\Microsoft:7Xj2BkEybxYHipFPnL @Alternate Data Stream - 1074 bytes -> C:\ProgramData\Microsoft:rnI683qrV8W8AXhNLZXC8mW

:Files
ipconfig /flushdns /c

:Commands
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]


[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

THEN

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  1. Close any open browsers.
  2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  3. Open notepad and copy/paste the text in the quotebox below into it:
File:: C:\Windows\SysNative\rkhdrv31.dll C:\Windows\SysNative\dds_trash_log.cmd

NetSvc::
ftpds

ATJob::

Driver::
ftpds

Save this as CFScript.txt, in the same location as ComboFix.exe

http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

Refering to the picture above, drag CFScript into ComboFix.exeWhen finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

So far so good… Essentials is not detecting the consrv.dll file recurring.
See attached logs as per request.

Thank You.

UBH

Could you now run the MSFixit on this page http://support.microsoft.com/kb/811259

Once done let me know of any remaining problems