Remove consrv.dll file

So I’ve had a virus for about a week now.
The computer symptom is mainly that I’m getting redirected from
Searches and that just about any virus program I have running notifys me that there is something wrong with my browser.
I assume it’s all this consrv.dll file that replaced my winsrv.dll file.
I’ve run just about every virus an malware program I can get my hands on. And even the virus protection software I had before cant do a thing about it.
My current program lets me know that my browser is infected and when it try’s to remove the consrv.dll file it recommends either a startup repair or a normal boot. The normal boot is in loop that keeps me going back the the startup repair tha repairs the computer back to having the virus.

Can someone help me fix this and kill of this crappy virus.

I’m running windows 7

Follow the guide here and attach all log`s
http://forum.avast.com/index.php?topic=53253.0

Essexboy will then help you when he arrive here later today…

Ok Here is my MBAM log

OK now my OTL

aswmbr Log

ok here is my rogue killer report.

i think these are all the things needed let me know what else i can do to help figure this out. its killing me trying to figure this out.

Hi Gonzaba,

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

[*]Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs

[*]Right click on ComboFix.exe, click Run as Administrator & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix’s window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer’s settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
4. Please be patient, there may be times when it seems combofix may have stalled. If there is even the slightest hint of harddrive activity combofix is still runnning.

Please post back with the combofix log.

How’s the computer?

Thanks

I ran combofix and saved the log but now I keep getting an error

C:\program files (x86) \Mozilla\ Firefox.exe
Illegal operation attempted on a registry key that has been marked for deletion

And this is a similar problem for all programs and files.

ok here is the log

Hi Gonzaba,

Reboot your computer, that should take care of the eroor message.

You have this program installed, Malwarebytes’ Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

[*]Click the Update tab
[*]Click Check for Updates
[*]If an update is found, it will download and install the latest version.
[*]The program will close to update and reopen.
[*]Once the program has loaded, select “Perform Quick Scan”, then click Scan.
[*]The scan may take some time to finish,so please be patient.
[*]When the scan is complete, click OK, then Show Results to view the results.
[*]Make sure that everything is checked, and click Remove Selected.
[]When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
[
]The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
[*]Copy&Paste the entire report in your next reply.

Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Please post back with the MBAM log.

Any remaining issues?

OK i think im good. thanks for all the help.

Ill post the log anyways.

Hi Gonzaba,

Ok let’s do a little clean up and remove the tools and send you on your way.

Your java is out of date. Click your start button > Control Panel
[*]Use the drop down menu beside view by and change it to small icons
[*]locate java (32bit) in the list and click on it
[*]when the java console opens click the update tab
[*]Click update now
There should also be java (64bit), open it and please repeat the above steps to update it.

Next, Right click on OTL.exe and chose Run as Administrator to run it
[*]Under the Custom Scans/Fixes box at the bottom, paste in the following
[*]Do Not copy the word CODE
[*]please note the fix starts with the :

:Services

:Commands
[emptytemp]

Then click the Run Fix button at the top

[*]Let the program run unhindered

From your desktop, please delete, if present
[]any notepads/logs that we created
[
]TDSSKiller
[]RogueKiller.exe
[
]aswMBR.exe

Next

Click the Start button, click Run. [Vista and Win7 users, go Start>“Start search”] Copy and paste the following line into the run box and click OK

“%userprofile%\desktop\combofix.exe” /uninstall

(don’t miss the " mark at the begining)

Next

Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.

I suggest you keep MBAM. Keep it updated and use it regularly.

Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. Add a firewall to what you have.

  • If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for links and tutorials to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware)

You should also use Spyware Blaster to help immunize your computer.

  • SpywareBlaster will add a large list of programs and sites into your Internet Explorer
    settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.

-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
[*]Click once on the Security tab
[*]Click once on the Internet icon so it becomes highlighted.
[*]Click once on the Custom Level button.
[*]Change the Download signed ActiveX controls to Prompt
[*]Change the Download unsigned ActiveX controls to Disable
[*]Change the Initialize and script ActiveX controls not marked as safe to Disable
[*]Change the Installation of desktop items to Prompt
[*]Change the Launching programs and files in an IFRAME to Prompt
[*]Change the Navigate sub-frames across different domains to Prompt
[*]When all these settings have been made, click on the OK button.
[*]If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

  • Keeping your Windows up-to-date is crucial to your computer’s security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis

  • Make sure you have reset Automatic Updates to your chosen option. Click your start button > Control Panel > System > Automatic Updates tab

  • Keep your antivirus program updated, as well as any other security programs you have.

-More tips and programs can be found HERE

Please post back if you have any problems with these steps.

Thanks