I also uploaded c:\windows\system32\consrv.dll to Virus Total. Here are the results:
|MD5 : 1812577ddfa736694a8dbad896d329d7|
|SHA1 : a6831421aa2c04b93078df35d4bd2eed62985060|
I have removed ZeroAccess manually without help of Mcafee or big security society finally , this "consrv.dl" is the body of the threat but he can't do deleted without cleaned before the windows's registry key associate with him. This key is protected by the infection and must be modified with a Boot Live CD. It's not easy or secure for everyone...
Or simply use a restoration point create before the infection if you have the luck to have one and delete after the "consrv.dll"
Be carefull if you delete the file 'consrv.dll" without have a registry safe and cleaned, the windows don't start anymore and you will have a BSOD with a reboot of the computer.
on 11/10/11 12:13:55 CDT
Thanks Beagle123, you've been very positive and helpful in your posts. I've gathered several samples from posters, and research has added them to the dats. They should show up today/tomorrow. The challenge is to get a scan going. If the product is still up and running, I'd do a full system scan, and see what it picks up. If the product is down, we can use the daily Stinger, as I've ensured the signatures are included into that as well.
I'll be trying to test it out today as well.
I ran a full scan last night. In c:\Program Files\McAfee\VirusScan\dat I have a 6497.0 folder. I'm guessing that is the version of the data files. In c:\Program Files\McAfee\VirusScan\Engine I have 5400.1158.
The scan may have been interrupted by a reboot caused by a Windows update.
The scan removed the following:
10/12/2011 08:44:41 PM Real Time Artemis!56C9EF26F88B(Trojan) Repaired(removed) File: C:\windows\assembly\tmp\U\80000032.$ Process: c:\windows\system32\svchost.exe
10/12/2011 09:07:56 PM Real Time DNSChanger!fa(Trojan) Repaired(removed) File: C:\windows\assembly\tmp\U\80000032.@ Process c:\Program Files(x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
The scan quarantined the following:
10/12/2011 10:09:29 PM Full DNSChanger!fa(Trojan) Quarantined File: C:\Temp\80000032.@ (this is a copy that I made earlier to send the files to this discussion)
10/12/2011 10:09:39 PM Full Generic.dx!bbbg(Trojan) Quarantined File: C:\windows\assembly\tmp\kwrd.dll
10/12/2011 10:09:39 PM Full DNSChanger!fa(Trojan) Quarantined File: C:\Temp\Windows_assembly_tmp_U.zip (this was also used to send the files to this discussion)
10/13/2011 0553:12 AM Scheduled Generic.dx!bbbg(Trojan) Quarantined File: C:\windows\assembly\tmp\kwrd.dll
Conspicuously absent from these lists is the contaminated c:\windows\system32\consrv.dll that I submitted to Virus Total. It looks like the scan missed it.
just ran the scan. Files found:
freqdpcobn in ...\appdata\Local\temp\
nrv.dll in ...\appdata\Local\temp\
kwrd.dll in \windows\assembly\tmp\
However, the Firewall still is having the same issues, so I don't believe the computer is clean.
I ran another full scan on Friday using the automatically downloaded updates. Zeroaccess.e and two other viruses were reported to be detected and quarantined (whatever that means). The next time that I rebooted the machine, Windows failed to start. It tried to repair itself, but it was unsuccessful. This led me to do what I knew was inevitable anyway. I wiped out everything and reloaded Windows. At least I KNOW that it's gone now.
Just an FYI for the Engineers: Without the FIREWALL the virus came back with a vengenance. McAfee still DID NOT detect it , my other programs gave off warnings in an attempt to clean...my laptop finally crashed. The only thing left for me to do was to reformat the hard drive and reinstall all the programs. At least the firewall is back up.
I am currently looking for more powerful security programs, because McAfee isn't even recognizing there is a problem. Right now, McAfee is running - and I am not sure what type of protection I am receiving from it. I'm counting my losses and going back to freeware - which I know works.
Oh and by-the-way I lost everything!!! Thanks McAfee!!!
This virus is very malicious, Virus="consrv.dll" He work like a Dropper virus, he try to invit bad friends to live in your computer.
On 32bits operating system he can disable all antivirus and protections, redirected the web search on publicity and expand quickly.. a special removal has been create by an other security company...
On 64Bits operating system the virus processing isn't the same, the removal tool don't work on 64 bits operating system. The virus try infinitely to invit friends on your computer, the firewall block them but if you disable the firewall there are others virus who come on your computer and the infection expand and become more dangerous.
One of antivirus tested have detected the file "consrv.dll" and delete her but after that the computer crash at the starting because this virus have infected the Windows's registry too!
The infection is hide under a primary key in the registry, you must restore this key or modify her out of the Windows with a live operating system with a Boot live CD fo recover a clean registry before delete the file 'consrv.dll".
Or use a restoration point of Windows created before the infection for recover a clean registry and finally delete the file "consrv.dll" after.
The registry key modified by this threat is:
%SystemRoot%system32csrss.exe ObjectDirectory=Windows SharedSection=1024,20480,768 Windows=On