Got a co-worker’s computer with a sirefef.b infection. Very similar to a few other posts here, every time it restarts MSE finds C:\Windows\system32\consrv.dll and removes it, but the registry is already altered to look for that file. I can get the computer to restart by altering the registry using a recovery CD but consrv.dll returns and re-edits the registry. Running a scan from the recovery CD finds the C:\Windows\assembly\GAC_32\Desktop.ini (and …\GAC_64.…) but deleting them makes no difference. In Safe Mode, RKill stops the rundll32.exe process and a Malwarebytes scan finds various registry key agents which all seem to be related to C:\Windows\system32\grpconv.exe through HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce|GrpConv. Also tried renaming grpconv.exe to GARBAGEgrpconv.exe from the recovery CD - didn’t delete it though.
An IT guy ran ComboFix at some point before I got the computer but I don’t know if it solved anything. I have attached the logs but they may not be relevant anymore. MSE was installed after these logs were created, and Sophos was disabled (but the folder is still there and can’t be deleted).
Refering to the picture above, drag CFScript into ComboFix.exeWhen finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
Notes:
Do not mouse-click Combofix’s window while it is running. That may cause it to stall.
Do not “re-run” Combofix. If you have a problem, reply back for further instructions.
If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.
Might be Sophos, which doesn’t appear in the installed programs list, but its folder is still there and can’t be deleted, or MSE, but I thought I disabled that before running anything.
Is it usual for ComboFix to hang the computer with a black screen and a mouse cursor on it after the reboot? Been like that for about 5 minutes.
If necessary I can delete the Sophos folder from the recovery disk.
I’ll be leaving the office within the hour and returning to this problem tomorrow. ComboFix ran and the computer is still restarting, still showing disk activity. If that completes and the log is available before the end of the day today I’ll post it immediately. Unfortunately I’m working at a mine site so staying late isn’t an option right now unless I want to stay the night
Twelve hours later, no change to the computer’s status. Still a black screen with a cursor. Looks like the only thing to do is try to turn it off and on again and see what’s there.
ComboFix has generated a log, please find it attached. It is quite heartening that the computer actually started without giving the “%hs missing” error!
Also, not sure if this is relevant or not, but trying to open any application on the machine produces an error, “Illegal operation on a registry key that has been marked for deletion.”
Just restarted again, all the applications work. MSE is disabled, won’t turn it on again until told to, so I don’t know offhand if anything is still there or not. A look in the registry shows that “HKLM\System\ControlSet001\Control\Session Manager\SubSystems\Windows” is pointing to winsrv.dll instead of consrv.dll so that hasn’t been changed - looking good.
Yep looks good just one or two more things to do on the repair side now. The minor problem was Combofix failing to release the registry
Exit all programs.
2. Click Start, and then click Control Panel.
3. Under System and Security, click Find and Fix Problems.
4. In the Task pane, click View All.
5. Click Internet Explorer Performance.
6.In the new window, click Next.
Note The troubleshooter runs and fixes all identified issues automatically.
7.Click Close.
That should reset the winsock
Close any open browsers.
Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
Open notepad and copy/paste the text in the quotebox below into it:
Refering to the picture above, drag CFScript into ComboFix.exeWhen finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
Notes:
Do not mouse-click Combofix’s window while it is running. That may cause it to stall.
Do not “re-run” Combofix. If you have a problem, reply back for further instructions.
If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.