PDA

View Full Version : XP SP2 and upgrade.newdotnet.net


Wizard in Training
September 11th 04, 06:24 AM
Well SP2 is on my computer, has been since the pre
release, with little problem. I however disabled the
windows firewall as i run sygate.
Recently, last few days, i have been getting this attempt
to access the internet... see log below. After an adaware
scan, still this:

Newdotnet is adware/spyware right? So how does
rundll32.exe fit into the picture?


The following application has been blocked by user from
accessing the internet...

File Version : 5.1.2600.2180
(xpsp_sp2_rtm.040803-2158)
File Description : Run a DLL as an App (rundll32.exe)
File Path : C:\WINDOWS\SYSTEM32\rundll32.exe
Process ID : 0x5F4 (Heximal) 1524 (Decimal)

Connection origin : local initiated
Protocol : TCP
Local Address : 192.168.2.100
Local Port : 4926
Remote Name : upgrade.newdotnet.net
Remote Address : 66.151.57.231
Remote Port : 80 (HTTP - World Wide Web)

Ethernet packet details:
Ethernet II (Packet Length: 76)
Destination: 00-03-2f-09-c6-a5
Source: 00-4f-4e-09-1f-ba
Type: IP (0x0800)
Internet Protocol

hardhead
September 12th 04, 04:29 AM
your right it's malware big time. however i would check
your pc for other scumware, if it repetes you may have
something in your pc telling it to install. software
comes with a price tag these days.
>-----Original Message-----
>Well SP2 is on my computer, has been since the pre
>release, with little problem. I however disabled the
>windows firewall as i run sygate.
>Recently, last few days, i have been getting this
attempt
>to access the internet... see log below. After an
adaware
>scan, still this:
>
>Newdotnet is adware/spyware right? So how does
>rundll32.exe fit into the picture?
>
>
>The following application has been blocked by user from
>accessing the internet...
>
>File Version : 5.1.2600.2180
>(xpsp_sp2_rtm.040803-2158)
>File Description : Run a DLL as an App (rundll32.exe)
>File Path : C:\WINDOWS\SYSTEM32\rundll32.exe
>Process ID : 0x5F4 (Heximal) 1524 (Decimal)
>
>Connection origin : local initiated
>Protocol : TCP
>Local Address : 192.168.2.100
>Local Port : 4926
>Remote Name : upgrade.newdotnet.net
>Remote Address : 66.151.57.231
>Remote Port : 80 (HTTP - World Wide Web)
>
>Ethernet packet details:
>Ethernet II (Packet Length: 76)
> Destination: 00-03-2f-09-c6-a5
> Source: 00-4f-4e-09-1f-ba
>Type: IP (0x0800)
>Internet Protocol
>
>
>
>.
>

Google