localsrv.net pop-up wont go away HELP!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by bashor56, Oct 12, 2006.

  1. bashor56

    bashor56 Private E-2

    My computer has been slowing down lately, and i have run spyware removal tools and virus removal tools, i continually get a pop-up for localsrv.net, and I can't get rid of it. I ran a Hijack This scan, and I need guidance on what to fix, because I have no idea. Please Help!

    EDIT: Removed inline Hijackthis log
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi and Welcome :)


    HijackThis does not come close to showing all malware that could be hiding on a PC. Anyone who has an infected computer and is relying on HijackThis without the benefit of running other scans such as Spybot, Windows Defender, BitDefender & Panda, CCleaner, etc. are more than likely still infected. In most cases, where there is one virus/trojan there are more. The goal of this forum is to remove all malware, and this cannot be done properly by just seeing a HijackThis log.


    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. bashor56

    bashor56 Private E-2

    Help! I have completed the read and run first

    I continually get a pop-up that says it is localsrv.net. I cannot seem to get rid of it. I have gone through all of the steps in the read and run first instructions. I will post my logs. Please help I dont want to delete the wrong thing.

    The rest will be in my next post
     

    Attached Files:

  4. bashor56

    bashor56 Private E-2

    Re: Help! I have completed the read and run first

    here are my other two logs
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Help! I have completed the read and run first

    Start by a two tool we will need- Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later.

    Is MarketResearch something that you installed? If not then goto Add/Remove Programs and uninstall it.

    While in Add/Remove programs also uninstall the below malware:
    Need2Find Bar

    Is your copy of Spyware Doctor a paid version of free trial version? If free, uninstall it too.

    Do you know what the below two programs are that show in your C:\Program Files folder?
    Code:
    C:\Program Files\
    ALARMC~1      Oct  8 2006              "Alarm Clock"
    INSANI~1      Sep 10 2006              "Insaniquarium Deluxe"
    I have a request of you. Can you put the below file into a ZIP file and upload it here as an attachment?
    C:\Documents and Settings\Owner\Application Data\wklnhst.dat

    Now Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - _{A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)
    R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)
    F2 - REG:system.ini: UserInit=userinit.exe,dnbidha.exe
    O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/installdrivecleanerstart.cab

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Documents and Settings\Owner\Application Data\Dxccwrd.dll
    C:\Documents and Settings\Owner\Application Data\Dxcknwrd.dll
    C:\Documents and Settings\Owner\Application Data\Dxcuknwrd.dll
    C:\803_104.exe
    C:\DXC1205b.exe
    C:\WINDOWS\b.exe
    C:\WINDOWS\hvvqsjdA.exe
    C:\WINDOWS\system32\taskkill.exe
    C:\WINDOWS\system32\dnbidha.exe
    C:\WINDOWS\bdjhj.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.
    After reboot locate the below folder and delete it if found:
    C:\Program Files\winupdates

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Owner\Local Settings\Temp

    Now uninstall the below old versions of Sun Java:
    Java 2 Runtime Environment, SE v1.4.2

    Now attach a the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. bashor56

    bashor56 Private E-2

    Thank you very much for the help so far.
    Marketresearch was not something that I installed, and it did not show up in remove programs. Also when I tried to get rid of Need2FindBar I got this error:
    Error loading C:pROGRA~1\NEED2F~1\bar\1.bin\Nd2fnBar.dll

    My SpyWare Doctor is a paid version

    Alarm Clock and INsaniquarium are programs i use

    I have attached that file as a zip file

    I fixed the four you pointed out in Hijack this

    everything went fine with the fixme.reg

    Pocket Killbox worked fine

    I did have a C:\Program Files\winupdates folder and I deleted it

    I had one file that was not dated todays date in the C:Documents and Settings\Owner\Local Settings\Temp folder that I deleted

    And I uninstalled the old sun java.

    My next post will have the last log that i need to show you.

    I have not gotten any pop-ups yet, so everything seems to be better.
     

    Attached Files:

  7. bashor56

    bashor56 Private E-2

    here is the other log
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

     
  9. bashor56

    bashor56 Private E-2

    I was able to remove look2find, i removed the AOL Spyware protection with Hijack this. I did the fixme.reg and that worked

    Here is my log

    Everything still seems to be working well.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean!

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    3. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and enable System Restore to create a new clean Restore Point.
    4. After doing the above, you should work thru the below link:
     
  11. bashor56

    bashor56 Private E-2

    Alright thanks for your help!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds