NEWNETGAR.DLL - Dangerous
NEWNETGAR.DLL
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
NEWNETGAR.DLL is known as: Trojan.Win32.Agent.ezap [Kaspersky Lab] Mal/Emogen-Y [Sophos] TrojanClicker:Win32/Agent.FB!dll [Microsoft] Trojan-Clicker.Win32.Agent [Ikarus] Win-Trojan/Goriadu.Gen [AhnLab].
MD5 of NEWNETGAR.DLL = 629087A34F33979A5CF8D11677C18D9F
NEWNETGAR.DLL size is 354304 bytes.
Full path on a computer: %PROGRAMFILES%\BAIDU\NEWNETGAR.DLL
Related Files:
%APPDATA%\MYIEDATA\MAIN.INI
%APPDATA%\NETHOME\MAIN.INI
%APPDATA%\PIERROR.LOG
%TEMP%\IS-2QOV5.TMP\SPASS.DLL
%TEMP%\IS-2QOV5.TMP\_ISETUP\_REGDLL.TMP
%TEMP%\IS-2QOV5.TMP\_ISETUP\_SHFOLDR.DLL
%TEMP%\IS-LHPB3.TMP\SETUP162770.TMP
%TEMP%\NSS2.TMP\ACCESSCONTROL.DLL
%TEMP%\NSS2.TMP\INETLOAD.DLL
%TEMP%\NSS2.TMP\INTERNET.DLL
%TEMP%\NSS2.TMP\MATH.DLL
%TEMP%\NSS2.TMP\NSEXEC.DLL
%TEMP%\NSS2.TMP\NSRANDOM.DLL
%TEMP%\NSS2.TMP\SYSTEM.DLL
C:\IPCONFIG.TXT
%PROGRAMFILES%\BAIDU\DSETUP.EXE
%PROGRAMFILES%\BAIDU\GO6002.EXE
%WINDIR%\INF\OEM9.INF
%WINDIR%\INF\OEM8.INF
%PROGRAMFILES%\BAIDU\MSFSG.EXE
%PROGRAMFILES%\BAIDU\NEW.EXE
%PROGRAMFILES%\BAIDU\NEWNETGAR.DLL
%PROGRAMFILES%\BAIDU\RONOWN.DLL
%SYSTEM%\DRIVERS\RONOWN.SYS
%PROGRAMFILES%\BAIDU\SETUP162770.EXE
%PROGRAMFILES%\BAIDU\SPASS.DLL
%SYSTEM%\MICROINFO\MYIEDATA\SYSDAT.BIN
%PROGRAMFILES%\BAIDU\TEMPNETHOME18.INI
%PROGRAMFILES%\BAIDU\UNINST18.EXE
%PROGRAMFILES%\INTERNET EXPLORER.LNK
%WINDIR%\INF\OEM8.PNF
%WINDIR%\INF\OEM9.PNF
%SYSTEM%\COOPEN_SETUP_100207.EXE
%SYSTEM%\DRIVERS\RONOWN.DLL
%SYSTEM%\MICROINFO\MICROINFO.DLL
%SYSTEM%\MICROINFO\MYIEDATA\MAIN.INI
%SYSTEM%\NETHOME32.DLL