newdotnet

Discussion in 'Malware Help (A Specialist Will Reply)' started by Joeyly, Oct 12, 2005.

  1. Joeyly

    Joeyly Private E-2

    Hello,

    newdotnet has cost me this evening. Here in Germany it is close to midnight.
    Enclosed is my log file. Any recommendation welcome. Tell me your country.
    Regards
    Joeyly
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I do not see visible signs of newdotnet but I do see Superbar:

    O2 - BHO: SuperBar - {136A9D1D-1F4B-43D4-8359-6F2382449255} - C:\Programme\SUPERBAR\SUPERBAR.dll
    O3 - Toolbar: SuperBar - {69E69E31-FBFC-4656-9EDE-A3E9E3006B27} - C:\Programme\SUPERBAR\SUPERBAR.dll

    I also see:
    O4 - HKLM\..\Run: [eDonkey2000] "C:\Programme\eDonkey2000\edonkey2000.exe" -t

    which is probably the cause of your newdotnet problems and more. See the below link for reference:

    http://www.bleepingcomputer.com/startups/eDonkey2000.exe-7149.html


    Please follow require standard cleaning procedures and only post HJT logs afterwards.

    I would suggest you look for Superbar and Edonkey200 in Add/Remove programs first and uninstall if found.

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:

    Downloading, Installing, and Running HijackThis

    .
     
  3. Joeyly

    Joeyly Private E-2

    Hello

    all as described in READ AND RUN until step 7 was done. Viruses were found and deleted. One log is enclosed from Bitdefender but with suffix change to log instead html to upload it. It is still installed edonkes2000. Do I have to uninstall really? A lot of started files would be deleted.

    Still Antivir is signing up with:
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{FC971C2B-34CB-4A94-8495-9227AD108828}\RP109\A0011594.EXE
    Contains code of the ADSPY/NewDotNet.A.11 virus
    I still saw
    O3 - Toolbar: SuperBar - {69E69E31-FBFC-4656-9EDE-A3E9E3006B27} - C:\Programme\SUPERBAR\SUPERBAR.dll (file missing).

    So I scanned again with HJT and deleted O3-Toolbar: SuperBar….

    Enclosed is the latest log file. Advice is welcom.
    Regards
    Joeyly
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Unless you enjoy being infected, the answer is Yes! Read this: http://www.bleepingcomputer.com/startups/eDonkey2000.exe-7149.html

    Are you sure you disabled System Restore? Double check to make sure. If it is disabled, boot in safe mode and use Windows Explorer to locate the C:\SYSTEM VOLUME INFORMATION\_RESTORE{FC971C2B-34CB-4A94-8495-9227AD108828}\RP109\A0011594.EXE file and delete it.

    Per the READ & RUN ME directions you need to disable Spybot's Teatimer.

    To disable TeaTimer, run Spybot and click Mode and select Advanced Mode. Then click Tools and select Resident. Now in the right window pane, uncheck TeaTimer.
    Also while this is open, in the left column now select IE Tweaks and then in the right pane make sure all the Miscellaneous locks are unchecked.
    Now quit Spybot!

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O3 - Toolbar: SuperBar - {69E69E31-FBFC-4656-9EDE-A3E9E3006B27} - C:\Programme\SUPERBAR\SUPERBAR.dll (file missing)
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    5 A082DDA76BB72327F7FAD47BE472ECC4)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete (if found):

    C:\Programme\SUPERBAR <-- the whole folder

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds