Boot into safe mode. See how HERE.
http://www.bleepingcomputer.com/forums/tutorial61.html
Turn off system restore.(XP/ME only) See how HERE.
http://www.bleepingcomputer.com/forums/tutorial56.html
In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how HERE.
http://www.bleepingcomputer.com/forums/tutorial62.html
Go to add remove programmes in your control panel and uninstall anything to do with(if there).
NewDotNet
NEWDOT~1
New.net Application or New.net Domains
Close control panel.
If none are listed, download and run this:
www.new.net/support/uninstall6_38.exe
Open your task manager and click on the processes tab. End process for(if there).
2005810205444_mcinfo.exe
mcinfo.exe
ShowWnd.exe
Close task manager.
Run HJT with no other programmes open. Have HJT fix the following(if there).
O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet7_22.dll
O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
O4 - HKLM\..\Run: [msci] C:\DOCUME~1\Owner\LOCALS~1\Temp\2005810205444_mcinfo.exe /insfin
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O10 - Hijacked Internet access by New.Net
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) -
http://www.miniclip.com/supergerball/miniclipGameLoader.dll
Click on the fix checked button.
Close HJT.
Locate and delete the following
bold files(if there).
C:\PROGRA~1\
NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
C:\DOCUME~1\Owner\LOCALS~1\Temp\
2005810205444_mcinfo.exe /insfin
ShowWnd.exe
C:\Program Files\
NewDotNet\newdotnet7_22.dll
Reboot into normal mode and turn system restore back on.
Post a fresh HJT log.
Regards Howard
