Solved

NewDotNet and HuntBar-how do I get rid of these unwanted programs?

Posted on 2004-03-27
7
343 Views
Last Modified: 2010-04-11
Sptbot S&D, Adaware 6.018 and McAfee Virus Scan have all pinpointed NeDotNet and HuntBar/BTIEIN as the unwanted programs that have taken control over IE and redirect it to unwanted and unsolicited web pages.  However, none of these spyware protection programs have been able to eliminate or disable these unwanted programs.  I have tried running both Adaware and Spybot S&D on startup (as recommended), disabling NewDotNet on the msconfig startup manager and using uninstall.  Nothing has worked so far.  Does anyone have a solution to this problem? Help!
0
Comment
Question by:rwrudd
7 Comments
 
LVL 49

Accepted Solution

by:
sunray_2003 earned 250 total points
ID: 10697156
Try these programs

CWShredder: http://www.softpedia.com/public/cat/10/17/10-17-150.shtml

HijackThis : http://www.webattack.com/download/dlhijackthis.shtml

Also check these registry entries and delete them if you find them there


HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Bar
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
HKCU\Software\Microsoft\Internet Explorer\SearchURL
HKCU\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
HKCU\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
HKCU\Software\Microsoft\Internet Explorer\Search\SearchAssistant
HKCU\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Bar
0
 
LVL 49

Expert Comment

by:sunray_2003
ID: 10697158
0
 
LVL 7

Expert Comment

by:hladamjr
ID: 10708571
You say you tryed ADaware but you need to be sure you have the latest refernce file installed also. If you downloaded Adaware and ran it it probably didn't catch 50 % of what you have installed. Be sure to use the latest refence file to get it go here:

http://www.lavasoft.de/update/refs/reflist.zip

Download the zip and extract the file in C:\ Program Files \Lavasoft \adaware and replace the file that currently resides there and then re-run the Adaware scan. Bet you find tons of stuff that can be removed

Hope this Helps

Hank
0
 
LVL 3

Expert Comment

by:zapthedingbat
ID: 10764660
NewDotNet.
litraly makes me want to vomit with loathing and contempt.

http://www.newdotnet.com/#remove

<rant>
whilst im on the subject of this vomit indusing crap
its intresting to note that having a poke about inside NewDotNet's guts with a hex editor you will see some of the following hard coded content...

RETR  
Return-Path:    
Bcc:
Cc:
To:
From:
POP3
EHLO
HELO
RSET
MAIL FROM:
DATA
RCPT TO:

netscape.com/webmail/br/compose.tmpl    
/webmail/br/compose.tmpl    

visto.com/mail/new.html /mail/mail=send.html
netaddress.com/tpl/Message
/tpl/Send

excite.com/ExciteMail/compose  
/ExciteMail/compose

www.mail.com/mailcom/writemail.jhtml
/mailcom/writemail.jhtml

mail.yahoo.com/ym/Compose?  
/ym/Compose?

hotmail.msn.com/cgi-bin/compose?
/cgi-bin/premail

now theres only one reason, i can think of that this evil scum might be hard coding the URLs and querystrings of popular web based email services and Chunks of POP3 Protocol into their widly distributed winsock layer...

and that would be that they are harvising the email addresses of everysingle person you send email to so they can hose them with showers of stinking spam.
and we wonder why the web is drowning in a sea of putrid, uncolidited, crap while new.net proudly bosts 174,661,619 users

oh unless anyone can think of a better explanation...of course

</rant>

grrr, arrg

ZapTheDingbat
http://www.zapthedingbat.com
0
 
LVL 12

Expert Comment

by:rossfingal
ID: 10792427
I agree with zapthedingbat.
Also, when you run Adaware, make sure you follow the directions posted on their website for running a "Custom" scan the
first time.
Make sure you get the latest version of CWShredder (ver 1.55, I think) - Cool Web Search has been rewritten to try and
block CWShredder.

Good luck!
0

Featured Post

Superior storage. Superior surveillance.

WD Purple drives are built for 24/7, always-on, high-definition security systems. With support for up to 8 hard drives and 32 cameras, WD Purple drives are optimized for surveillance.

Join & Write a Comment

This paper addresses the security of Sennheiser DECT Contact Center and Office (CC&O) headsets. It describes the DECT security chain comprised of “Pairing”, “Per Call Authentication” and “Encryption”, which are all part of the standard DECT protocol.
By this time the large percentage of day-to-day transactions have shifted to mobile banking; here are some overriding areas QAs must investigate while testing mobile banking apps.  
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now