I’m afraid i got the “consrv.dll” virus thing somehow and though Avast found it in both system32/64 folders and deleted it, i am afraid to make a restart, as i fear it may not re-boot, as others have mention in various similar threads here…
I also, tried to alter the registry entry, back to “winsrv”, as suggested in this forum, but it just doesn’t change; as soon as i click OK, i can see it reverts back to the dreaded “consrv”, probably cause the virus is still active on memory?..
And this is the reason i’m afraid to restart the PC now…
U shouldnt have deleted the file anyway i know how to fix this problem though but i dont want to take the chance of making your computer unbootable i would request u to wait until our malware removal expert essexboy arrives at night till then follow the link to guide below and attach the logs here on next reply: http://forum.avast.com/index.php?topic=53253.0
Well…
I’m not sure i can restore it, but i’ll give it a try…
In the mean time, running the Anti-Malware found no malicious items.
So at the end there were no “Show Results” option to choose.
Here’s a copy-paste of the log it generated…
If you cannot do that then we will take the bull by the horns and run Combofix
Download and Install Combofix
Download ComboFix from one of the following locations: Link 1 Link 2
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
[*]Double click on ComboFix.exe & follow the prompts.
[*]Accept the disclaimer and allow to update if it asks
Well…
Running the ComboFix, though it all started correctly, at some point screen went black and only mouse cursor could be seen, but it was frozen and couldn’t be moved…
Only option was to push the reset button unfortunately and “what a surprise” i couldn’t log into Windows anymore…
In the next reset/restart it invoke the build in System Repair bootup and it went and restore the Windows to some point, probably before the virus attack, cause the system boot up correctly with next restart…
I’m not sure what’s going on now, what’s affected, what is not, or what files i may be missing due to the restore point, but i did boot in Windows correctly…
But, since i was forced to reset, i don’t think i have a log file from what OTL did…
What should i do next?
Edit: Sorry, said it was OTL, but in fact i was running ComboFix…
Double Click mbam-setup.exe to install the application.
[*]Make sure a checkmark is placed next to Update Malwarebytes’ Anti-Malware and Launch Malwarebytes’ Anti-Malware, then click Finish.
[*]If an update is found, it will download and install the latest version.
[*]Once the program has loaded, select “Perform Quick Scan”, then click Scan.
[*]The scan may take some time to finish, so please be patient.
[*]When the scan is complete, click OK, then Show Results to view the results.
[*]Make sure that everything is checked, and click Remove Selected.
[]When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
[]The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
[*]Copy&Paste the entire report in your next reply.
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.
Well…
I haven’t checked everything, but most of the apps and the system seem to work okay, with one exception. There are a couple of small programs/utilities that don’t run, even when i re-install them. I got a popup saying: “A device attached to the system is not functioning”.
There are a couple of small programs/utilities that don't run, even when i re-install them. I got a popup saying: "A device attached to the system is not functioning".
Windows Update works and i’m currently downloading 20 updates (177MB)…
The programs that didn’t start were Java related, but after a Windows restart everything was running fine. Weird behavior, if you ask me…
Anyways, i haven’t found anything else problematic so far, except of course a couple of apps that were removed from the system due to going back to that restored point, but that’s okay; i can re-install them anytime…
Everything seem fine now, but i still have a bitter taste that everything is so fragile with Windows…