NewDotNet.B

Description: Spyware
Risk Level: High
Date of First Occurence: Monday, April 14, 2008
Software Developer: New.net, Inc.
Brief Info: NewDotNet/B is an adware program that associates non-existent domain-names with sponsored content.
Removal: This threat can be removed using "Spyware Terminator"

RIMUOVI SPYWARE »

Geographical Distribution of Threat "NewDotNet.B"

Threat Info

View All

Detected Items

  1. Detected Files: %PROGRAMFILES%\NewDotNet\nnrun.exe MD5: 3AAC76340DEBB4D1069637E201C053D8 Size:5120 MD5: B696B1338A863E06BD2AE5CC9CB0812E Size:3072 MD5: 09B4AD2E039D3BFC64581ABE8B4DF0DE Size:5120 MD5: 27EC836812CEABAC6976ADCFC3124D2E Size:5120 MD5: 54840B8DE87F62ADB56BE8782C89812E Size:5120 MD5: EAAA61442F93DD7AE109ED348615F96F Size:5120 MD5: 7D7711F024B5A173D72551DC894FC964 Size:5120 MD5: 37DAD68F71198561E4B2F7A6F647E651 Size:3584 MD5: 0989872D89B7378385C0EDC284B69A3D Size:5120 MD5: C9B18F61A6FC0953856B548292AD6EAD Size:5120 MD5: 930309F952430A317FEC356FAAE5D8F4 Size:5120 MD5: 46F8C594C48FD12825EE4159F0ABC89A Size:5120 and more.... %PROGRAMFILES%\NewDotNet\nncore.dll MD5: DCBE82AEA2AA23B2FA192120E0B0A599 Size:536576 MD5: 36180EA9A843C6C9E95A30C6AF5E7973 Size:536576 MD5: 925AA5085CF8923BFE57051DEFBD879F Size:536576 MD5: D9937A948FE56BE52A019911C0D6EDCE Size:536576 MD5: F515D7BB6912DE7F38B989B070F6BC6C Size:536576 MD5: 9E801F49DE6ED8F9F21BD328F96F6B50 Size:536576 MD5: 0CC75BA7E5B320543B977165DCC55D9C Size:536576 MD5: 2D2B3BB3701F46B7868D167C34C6CB7E Size:536576 MD5: E11FA3898D4270E0617C544BDD69532F Size:536576 MD5: 4D069F09B516441BC1CA3839DC56B85E Size:536576 MD5: 376D81A637374273D12D286B24F175B6 Size:536576 MD5: 5690E88108DDA8DA0B84C75777FDF0DA Size:536576 and more.... %PROGRAMFILES%\NewDotNet\uninstall.exe MD5: 42C86E78725F723EE8C3B4B085425477 Size:61704 MD5: 143AAFA0CCEEAB090952E8F59C24244D Size:68192 MD5: A7DBDDA979E096CD4153D016171ACF08 Size:68192 MD5: 1735715FAE86250C63D1219DB70833E9 Size:68192 MD5: 8FF0376974E16EE340398E9B55DDB0A5 Size:68192 MD5: 4E601ED4D760C4ADCBCB4E314BD898E8 Size:68192 MD5: E6746DA57041A669EB1C7B316F101C76 Size:68192 %WINDIR%\NDNuninstall7_14.exe MD5: E11EC2ED9679F08CAE5244696C9D54BA Size:183296 %WINDIR%\NDNuninstall7_44.exe MD5: 1F944B48A3EF7BC7BC7936F194B6AAC0 Size:183808 %WINDIR%\NDNuninstall6_30.exe MD5: DF93A2942A60EDBF723E4B807C45DDE9 Size:50688 %WINDIR%\NDNuninstall6_22.exe MD5: E731F07025DD990E22C0A3F2C49A15FC Size:49664 MD5: 2409CC9477BE15378C93222237836671 Size:49664 %WINDIR%\NDNuninstall5_64.exe MD5: 048B68A2AF4AEBC56D80122134D70812 Size:49664 %WINDIR%\NDNuninstall5_20.exe MD5: C767E0B51B3CDD4429195A7FA1B4A7A9 Size:45056 %PROGRAMFILES%\NewDotNet\uninstall3_88.exe MD5: 61AB107F560024B8783E30D281DBA639 Size:36864 %PROGRAMFILES%\NEWDOTNET\NNRUN.EXE MD5: BED7638450DA6F5FD25211361C3021D9 Size:5120 MD5: 2741B256D97937BC77C567CADC42C9D0 Size:5120 MD5: FE8DE56A20BA3ACB70A48CDB97BB81AF Size:5120 MD5: B8747E39394593A6FF46E42C3D4D9AE6 Size:3584 MD5: DB24ADDBC8FA207A6514A33C874EAA74 Size:5120 MD5: 394C912312C1413B797B09D9527A7A37 Size:5120 MD5: AA0E6A693CCC935A9B33981C55F819CF Size:3584 %WINDIR%\NDNuninstall4_50.exe MD5: 96FF03F5E325328C2B34112EE0E25705 Size:54272 %WINDIR%\NDNuninstall4_95.exe MD5: F6206BA8058387CD7568232D39AA9D75 Size:44544 %WINDIR%\NDNuninstall4_34.exe MD5: E65D369BADCB17CBE82A5E61B58DA004 Size:53760 %PROGRAMFILES%\NewDotNet\newdotnet5_48.dll MD5: FBC129E2155F7D1E9550806BD7746289 Size:221184 %PROGRAMFILES%\NewDotNet\newdotnet4_80.dll MD5: D10FAC5747F0F129783935BBDF8C8BB9 Size:200704 %PROGRAMFILES%\NewDotNet\nncore.dll MD5: 30BAF468E254AC67F57593CDB74AA24B Size:536576 MD5: 4FEF6C619975D163410F4750A2CEC8DE Size:536576 MD5: A964BAAD204145CFE5311B1C484340DE Size:524288 MD5: 3461AC7B0352A9C4B2C894F4C7001FF2 Size:536576 MD5: 7307D5F0D3E4AD32F50718771F54DA9E Size:536576 MD5: C5235E299D295A7D3D10AD51670E9CCC Size:536576 MD5: 44EE57EF8536E8B9A20A0F8BBF90BA5D Size:536576 MD5: 6AD086F838C0A79F037C446C165747F6 Size:524288 MD5: 42057B168FBB69F4FE573DCE60928DAD Size:536576 MD5: B4F7E0A97908B8F530E7B3793A821E33 Size:536576 MD5: 271305CA42D92CAFFFD193E97410DC02 Size:536576 MD5: 79F531C8053CAB9AA4DBF85441DB90D3 Size:536576 and more.... %PROGRAMFILES%\NewDotNet\newdotnet7_48.dll MD5: CF618BA6DC9914D1DEA07BBFCF273FA4 Size:610304 %PROGRAMFILES%\NewDotNet\nnrun.exe MD5: 8516DD256D0DB06F78236DB205AD49D8 Size:5120 MD5: F81B7E4BD51E4E275CAC18D172DF58C3 Size:5120 MD5: 0CBA7130A8C6F8B93B90DDB6E458F1D4 Size:5120 MD5: BDA53B568D84940ACAFE6F090E10DEEC Size:5120 MD5: B7A04CF836A8E305668FCF7AE13D4C49 Size:5120 MD5: 832A4D3D4AF0E129BB2C32931DE94818 Size:5120 MD5: 984827FF7CFE29E857AC34018FADE769 Size:5120 MD5: 49F4180677D702208D5C3100948A72C6 Size:5120 MD5: 2C4D343620C3F66ABB71E60A9DEE4920 Size:5120 MD5: F4A8F5BA6D5697704CCB8A8C896C8CB6 Size:5120 MD5: 3A49F77C5B3425DF4C94557DF1500B75 Size:5120 MD5: 65F194958C28D07DB3BE681B7C6AA6A4 Size:5120 and more.... %WINDIR%\NDNuninstall6_34.exe MD5: AE896D910917D153B5D5B1272A01C82C Size:50688 %PROGRAMFILES%\NewDotNet\newdotnet6_98.dll MD5: 0857005BBE1B6C1176D7FA4878E404ED Size:593920 %PROGRAMFILES%\NewDotNet\nncore.dll MD5: 9A4FBE200E35E9BD8EEA8D20725772B0 Size:536576 MD5: FD803B4C8D5723A495893984758EC966 Size:536576 MD5: CE7B26E4E5CFEF90312A19C62BBEFFAA Size:536576 MD5: 013A58A991513DB8DA4ADA25B1E237E4 Size:536576 MD5: E3AF90C981883FF6B81C0E1E2F16A366 Size:536576 MD5: 85BB5E635787E454F85A70F74DFE8B1F Size:507904 MD5: AF048BCAE79B6DD8642EFD6CC387D887 Size:536576 MD5: E39E2959A22FB3B7CCD9816EBBDEA77C Size:536576 MD5: A5BD692DDC7DBFF6A497DF90B61D6269 Size:536576 MD5: C9492E437C4453177DB353D445EED329 Size:536576 MD5: 90774C0A607305DB5A6DA0934A92C60D Size:536576 MD5: CB2F0170F95BD1531E8C628E874E7B18 Size:536576 and more.... %PROGRAMFILES%\NewDotNet\nnrun.exe MD5: 6E9661D77D7F3721807970DD30611A98 Size:3072 MD5: 1FFB289A7CBCFA87C743DF111667032D Size:5120 MD5: 7B400228E7E7347F9D633BE6432967C8 Size:5120 MD5: F2FE16948D5F26ACDAB725AD17D845D7 Size:5120 MD5: F1EEE35FE673E602E6CBA3C21317CFBD Size:5120 MD5: 7EFB10A282B704A109CD46613A36D4D3 Size:5120 MD5: 5D4DE0106F4A7254AB8DFA8B6DC50C26 Size:5120 MD5: 1184FB3C8843BB77CE39B54A3223D170 Size:5120 MD5: 6BBB28613EF394791EF218321A8FEA77 Size:5120 MD5: 3052C1804CA5A12761437DEDA9B3AB17 Size:5120 MD5: AB8B3ABE2067EBA1948A2BD4AB51697E Size:5120 MD5: 0718C752BC6B086F11118AED512EFE6A Size:5120 and more.... %PROGRAMFILES%\NewDotNet\nncore.dll MD5: 1692D74D4DDB4530E2CE4B19B06511F2 Size:536576 MD5: 964FDC1DD524D27507AE524EBC2B7150 Size:536576 MD5: ED4949B17DD9EA6C86D82F77A84D162D Size:536576 MD5: 1CC45487FEC59DA554F8C4DFD6242D58 Size:536576 MD5: CAA6770436C7FD913C9FA3E10FF5160A Size:536576 MD5: FA765D320643BAC6737A93AE8A58CBAD Size:536576 MD5: B13757DE26C1291EF9AE25B98CA4DC5C Size:536576 MD5: CD875C00BD4A8461B428D77B51FB2A4D Size:536576 MD5: 554E60A125B1AA3415789C3836B8BCBA Size:524288 %PROGRAMFILES%\NewDotNet\nnrun.exe MD5: BABB79E42EC900864FF5B78DC57B8183 Size:5120 MD5: 26026D6304DD7845A6426F9830C4A93F Size:5120 %WINDIR%\NDNuninstall6_84.exe MD5: BEB2285334329B85E6A3F5DB692DAE9B Size:113664 %PROGRAMFILES%\NewDotNet\newdotnet4_94.dll MD5: E24C8187E1EB7BF165EF41F9BA8AC50B Size:204800 %WINDIR%\NDNuninstall6_72.exe MD5: F061AA37C652F08ECE6734E4CB967626 Size:83456
  2. Detected Files with variable Filenames: MD5: 5B29B82B4FC8FF22472366727FB2F178 Size: 182272 %WINDIR%\NDNuninstall6_98.exe %PROGRAMFILES%\NewDotNet\uninstall6_98.exe MD5: 9D2745366D090F3D70B23FB06D538ED1 Size: 183296 %WINDIR%\NDNuninstall7_22.exe %PROGRAMFILES%\NewDotNet\uninstall7_22.exe %WINDIR%\NDNuninstall7_22-1.exe %PROGRAMFILES%\NewDotNet\uninstall7_22-1.exe MD5: 546C546164B0C71D2A68F67E7FE6488A Size: 182272 %WINDIR%\NDNuninstall6_90.exe %WINDIR%\NDNuninstall6_90-1.exe %PROGRAMFILES%\NewDotNet\uninstall6_90-1.exe MD5: E261FD676834CCD3E5499C472DD4D1A0 Size: 49664 %WINDIR%\NDNuninstall6_10.exe %WINDIR%\NDNuninstall6_10-1.exe %PROGRAMFILES%\NewDotNet\uninstall6_10-1.exe MD5: DC1C3F1B51C6EB35954CED59094DBDF5 Size: 49664 %WINDIR%\NDNuninstall5_48.exe %PROGRAMFILES%\NewDotNet\uninstall5_48.exe MD5: 1DE4F09FA138BDEE91CC7E8429AB1F85 Size: 49664 %WINDIR%\NDNuninstall5_40.exe %PROGRAMFILES%\NewDotNet\uninstall5_40.exe MD5: CA3DDCFFE3403F9C599E3AB4F184B8D6 Size: 44544 %WINDIR%\NDNuninstall4_94.exe %PROGRAMFILES%\NewDotNet\uninstall4_94.exe MD5: 6CA5C622A3CA138EF16D82E9F9567C62 Size: 44544 %WINDIR%\NDNuninstall4_88.exe %PROGRAMFILES%\NewDotNet\uninstall4_88.exe MD5: DC30E4B55CACE4F84B752055A33F5AA5 Size: 45056 %WINDIR%\NDNuninstall4_85.exe %PROGRAMFILES%\NewDotNet\uninstall4_85.exe MD5: 143AAFA0CCEEAB090952E8F59C24244D Size: 68192 %PROGRAMFILES%\NewDotNet\uninstall.exe %PROGRAMFILES%\NewDotNet\NewDotNet-old_\uninstall.exe %PROGRAMFILES%\NewDotNet\NewDotNet-old_\uninstall.exe.ren MD5: B696B1338A863E06BD2AE5CC9CB0812E Size: 3072 %PROGRAMFILES%\NewDotNet\nnrun.exe %PROGRAMFILES%\NewDotNet\NewDotNet-old_\nnrun.exe %PROGRAMFILES%\NewDotNet\NewDotNet-old_\nnrun.exe.ren %PROGRAMFILES%\NewDotNet\nnrun.exe.ren MD5: A7DBDDA979E096CD4153D016171ACF08 Size: 68192 %PROGRAMFILES%\NewDotNet\uninstall.exe %PROGRAMFILES%\NewDotNet\NewDotNet-old_\uninstall.exe %PROGRAMFILES%\NewDotNet\uninstall.exe.ren MD5: F643766BDE04B246CAEE5F22909FC6A4 Size: 68192 %PROGRAMFILES%\NewDotNet\NewDotNet-old_\uninstall.exe %PROGRAMFILES%\NewDotNet\uninstall.exe MD5: 12AD5E7706D35CA00B8F3737065FB25B Size: 507904 %PROGRAMFILES%\NewDotNet\NewDotNet-old_\nncore.dll %PROGRAMFILES%\NewDotNet\nncore.dll MD5: 37DAD68F71198561E4B2F7A6F647E651 Size: 3584 %PROGRAMFILES%\NewDotNet\nnrun.exe %PROGRAMFILES%\NewDotNet\nnrun.exe.ren %PROGRAMFILES%\NewDotNet\NewDotNet-old_\nnrun.exe MD5: 1735715FAE86250C63D1219DB70833E9 Size: 68192 %PROGRAMFILES%\NewDotNet\uninstall.exe %PROGRAMFILES%\NewDotNet\uninstall.exe.ren %PROGRAMFILES%\NewDotNet\NewDotNet-old_\uninstall.exe MD5: 8FF0376974E16EE340398E9B55DDB0A5 Size: 68192 %PROGRAMFILES%\NewDotNet\uninstall.exe %PROGRAMFILES%\NewDotNet\NewDotNet-old_\uninstall.exe MD5: B8747E39394593A6FF46E42C3D4D9AE6 Size: 3584 %PROGRAMFILES%\NEWDOTNET\NNRUN.EXE %PROGRAMFILES%\NewDotNet\nnrun.exe.ren %PROGRAMFILES%\NewDotNet\NewDotNet-old_\nnrun.exe.ren %PROGRAMFILES%\NewDotNet\NewDotNet-old_\nnrun.exe MD5: 0C33E084D41146189C53ADE3A472C21C Size: 208896 %PROGRAMFILES%\NewDotNet\newdotnet4_85.dll %PROGRAMFILES%\NewDotNet\newdotnet4_85.dll.ren %PROGRAMFILES%\NewDotNet\newdotnet4_85.VIR MD5: A964BAAD204145CFE5311B1C484340DE Size: 524288 %PROGRAMFILES%\NewDotNet\nncore.dll %PROGRAMFILES%\NewDotNet\NewDotNet-old_\nncore.dll.ren %PROGRAMFILES%\NewDotNet\nncore.dll.ren MD5: 01B7176890D94CD4E4FDA77754AE029C Size: 66408 %PROGRAMFILES%\NewDotNet\NewDotNet-old_\uninstall.exe %PROGRAMFILES%\NewDotNet\uninstall.exe MD5: 5344E9A2DE08E1C137CAB57774452EA8 Size: 3072 %PROGRAMFILES%\NewDotNet\NewDotNet-old_\nnrun.exe %PROGRAMFILES%\NewDotNet\nnrun.exe MD5: 72E9CD1B434627B6A3A961C05C563AF5 Size: 266240 %PROGRAMFILES%\Ares Galaxy FasterDownload\NNGLZA638.EXE %PROGRAMFILES%\Emule Speed Booster\NNGLZA638.EXE %PROGRAMFILES%\MegaSoundRecorder\NNGLZA638.EXE MD5: FB75CC573D91162CA8D4746B6C57C1E8 Size: 614400 %PROGRAMFILES%\NewDotNet\newdotnet7_22.dll %PROGRAMFILES%\NewDotNet\newdotnet7_22-1.dll.ren %PROGRAMFILES%\NewDotNet\newdotnet7_22-1.dll MD5: AA0E6A693CCC935A9B33981C55F819CF Size: 3584 %PROGRAMFILES%\NEWDOTNET\NNRUN.EXE %PROGRAMFILES%\NewDotNet\NewDotNet-old_\nnrun.exe MD5: 554E60A125B1AA3415789C3836B8BCBA Size: 524288 %PROGRAMFILES%\NewDotNet\nncore.dll %PROGRAMFILES%\NewDotNet\nncore.dll.ren MD5: 031DA553B01B63E28646955382942A32 Size: 524288 %PROGRAMFILES%\NewDotNet\NewDotNet-old_\nncore.dll %PROGRAMFILES%\NewDotNet\nncore.dll %PROGRAMFILES%\NewDotNet\NewDotNet-old0\NewDotNet-old_\nncore.dll MD5: 3722EE6EDD6EC01427050CBD5916FA1C Size: 196608 %PROGRAMFILES%\FileSubmit\Scarface\NNEZTA388.exe %PROGRAMFILES%\screensandthemes\16308.exe\NNEZTA388.exe %PROGRAMFILES%\themexp\ThemeXP.org File\NNEZTA388.exe

Detecting items list:

  1. Files by Name %PROGRAMFILES%\NewDotNet\uninstall*.exe %PROGRAMFILES%\NewDotNet\NewDotNet*.dll %windir%\ndnuninstall*.exe %windir%\NDNuninstall?_??.exe %PROGRAMFILES%\NewDotNet\newdotnet7_22.dll %TEMP%\NNEZTA388.exe %TEMP%\NNGLZA638.EXE %PROGRAMFILES%\themexp\ThemeXP.org File\NNEZTA388.exe %PROGRAMFILES%\themexp\ThemeXP.org File\NNGLZA638.EXE
  2. Files by MD5 MD5: 5D5C7768899D1553C2529DE91A4236A3 Size: 596550 MD5: 33894EDF829958C471E03C2CD2CEFF93 Size: 596550
  3. Files by Directories %PROGRAMFILES%\NewDotNet
  4. Files by CLSID or Name CLSID=4A2AACF3-ADF6-11D5-98A9-00E018981B9E
  5. Registry Keys HKLM\SOFTWARE\New.net HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\New.net HKCU\Software\New.net
  6. Registry Values HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ValueName=New.net Startup Value=rundll32 %SystemDiskRoot%\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s

« Go to Software Database