Symantec United States














© 1995-2005 Symantec Corporation.
All rights reserved.
Legal Notices
Privacy Policy

Adware.DAP

Last Updated on: May 11, 2005 12:05:30 PM

Type: Adware
Name: Download Accelerator Plus
Version: 7.2
Publisher: Speedbit
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Risk Impact: Low

  • Intelligent Updater Definitions*
  • October 13, 2004

  • LiveUpdate™ Definitions **
  • October 13, 2004

    *

    Intelligent Updater definitions are released daily, but require manual download and installation.
    Click here to download manually.

    **

    LiveUpdate definitions are usually released every Wednesday.
    Click here for instructions on using LiveUpdate.

    This risk can be detected only by Symantec products that support security risks. For more information on security risks, please go here.



    Behavior
    Adware.DAP is:


    Note: Registering the application will stop the ads from displaying.

    Symptoms
    One or more files are detected as Adware.DAP.

    Transmission
    The Download Accelerator Plus program must be manually installed.


    File names:
    dap.exe
    dapiebar.exe
    dapie.dll
    dapns.dll
    dapop.dll
    dapbho.dll

    When Adware.DAP runs, it does the following:

    1. Creates the following files:
      • %ProgramFiles%\DAP\Ads\*.* (stored ads)
      • %ProgramFiles%\DAP\Icons\dapgames.ico
      • %ProgramFiles%\DAP\Locales\*.* (language files)
      • %ProgramFiles%\DAP\Log\*.* (log files)
      • %ProgramFiles%\DAP\Skins\Dap\*.bmp (files for GUI skins)
      • %ProgramFiles%\DAP\Temp\*.* (temporary files)
      • %ProgramFiles%\DAP\Updates\*.* (update files)
      • %ProgramFiles%\DAP\cabex.dll
      • %ProgramFiles%\DAP\dap.exe (executable, runs at boot, detected as Adware.DAP)
      • %ProgramFiles%\DAP\dap.gif
      • %ProgramFiles%\DAP\dapbho.dll (Internet Explorer BHO, detected as Adware.DAP)
      • %ProgramFiles%\DAP\dapextie.htm
      • %ProgramFiles%\DAP\dapextie2.htm
      • %ProgramFiles%\DAP\dapie.dll (Internet Explorer DAP download interceptor)
      • %ProgramFiles%\DAP\dapiebar.dll (the toolbar in Internet Explorer, detected as Adware.DAP)
      • %ProgramFiles%\DAP\dapmm.dll (multimedia library)
      • %ProgramFiles%\DAP\dapm_amdc.dll (multimedia library)
      • %ProgramFiles%\DAP\dapm_context_games.dll (games library)
      • %ProgramFiles%\DAP\dapm_ftp.dll (ftp client)
      • %ProgramFiles%\DAP\dapns.dll (Netscape DAP download interceptor)
      • %ProgramFiles%\DAP\dapop.dll (Opera DAP download interceptor)
      • %ProgramFiles%\DAP\dapres.dll (DAP resource library)
      • %ProgramFiles%\DAP\dapres32.dll (DAP resource library)
      • %ProgramFiles%\DAP\dapupd.exe (DAP updater)
      • %ProgramFiles%\DAP\install.log
      • %ProgramFiles%\DAP\license.txt
      • %ProgramFiles%\DAP\mfc42.dll (Microsoft library)
      • %ProgramFiles%\DAP\mmc.xml
      • %ProgramFiles%\DAP\msvcrt.dll (Microsoft library)
      • %ProgramFiles%\DAP\restartApp.exe
      • %ProgramFiles%\DAP\screen.dat
      • %ProgramFiles%\DAP\unwise.exe
      • %ProgramFiles%\DAP\zlib.dll (data compression library)
      • %ProgramFiles%\DAP\*.gif (images)
      • %System%\anigif.ocx (gif animation control)
      • %System%\wbhelp2.dll (WindowBlinds helper DLL)
      • %System%\wbocx (WindowBlinds helper control)

        Notes:
        • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
        • %ProgramFiles% is a variable that refers to the program files folder. By default, this is C:\Program Files.

    2. Creates the following registry entries:
      • HKEY_CLASSES_ROOT\CLSID\{8110AEA1-AD5B-4B90-883F-04A9A33B106E}
      • HKEY_LOCAL_MACHINE\Software\Speedbit
      • HKEY_CLASSES_ROOT\daffile
      • HKEY_LOCAL_MACHINE\Microsoft\Internet Explorer\Extensions\{669695BC-A811-4A9D-8CDF-BA8C795F261C}
      • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Download &all with DAP
      • HKEY_USER\.DEFAULT\Software\Microsoft\Internet Explorer\MenuExt\Download &all with DAP
      • HKEY_CLASSES_ROOT\.das
      • HKEY_CLASSES_ROOT\.dzs
      • HKEY_CLASSES_ROOT\dzsfile
      • HKEY_CLASSES_ROOT\dasfile
      • HKEY_CURRENT_USER\Software\Netscape\Netscape Navigator\Suffixes\application\x-speedbit-daf
      • HKEY_CURRENT_USER\Software\Netscape\Netscape Navigator\Suffixes\application\x-speedbit-dal
      • HKEY_CURRENT_USER\Software\Netscape\Netscape Navigator\Suffixes\application\x-speedbit-das
      • HKEY_CURRENT_USER\Software\Netscape\Netscape Navigator\Suffixes\application\x-speedbit-skin
      • HKEY_CURRENT_USER\Software\Netscape\Netscape Navigator\Viewers\application\x-speedbit-daf
      • HKEY_CURRENT_USER\Software\Netscape\Netscape Navigator\Viewers\application\x-speedbit-dal
      • HKEY_CURRENT_USER\Software\Netscape\Netscape Navigator\Viewers\application\x-speedbit-das
      • HKEY_CURRENT_USER\Software\Netscape\Netscape Navigator\Viewers\application\x-speedbit-skin
      • HKEY_CLASSES_ROOT\DAPBHO.DAPHelper.1
      • HKEY_CLASSES_ROOT\DAPBHO.DAPHelper
      • HKEY_CLASSES_ROOT\CLSID\{F852086B-10E6-4743-9A3F-D8257A0A59E3}
      • HKEY_CLASSES_ROOT\CLSID\{62999427-33FC-4BAF-9C9C-BCE6BD127F08}
      • HKEY_CLASSES_ROOT\CLSID\{235D7A27-DE65-49F0-BFCF-D5C3BC3B2E67}

    3. Adds the value:

      "DownloadAccelerator"="%ProgramFiles%\DAP\DAP.EXE /STARTUP"

      to the registry key:

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

      so that the Adware runs when you start Windows.



    The following instructions pertain to all Symantec antivirus products that support Security Risk detection.

    1. Update the definitions.
    2. Uninstall Download Accelerator Plus using the Add/Remove Programs utility.
    3. Run a full system scan.
    4. Delete the value that was added to the registry.
    5. Delete any remaining files.
    For specific details on each of these steps, read the following instructions.

    1. To update the definitions
    To obtain the most recent definitions, start your Symantec program and run LiveUpdate.

    2. To uninstall the Adware
    1. Do one of the following:
      • On the Windows 98 taskbar:
        1. Click Start > Settings > Control Panel.
        2. In the Control Panel window, double-click Add/Remove Programs.

      • On the Windows Me taskbar:
        1. Click Start > Settings > Control Panel.
        2. In the Control Panel window, double-click Add/Remove Programs.
          If you do not see the Add/Remove Programs icon, click "...view all Control Panel options."

      • On the Windows 2000 taskbar:
        By default, Windows 2000 is set up the same as Windows 98, so follow the instructions for Windows 98. If otherwise, click Start, point to Settings > Control Panel, and then click Add/Remove Programs.

      • On the Windows XP taskbar:
        1. Click Start > Control Panel.
        2. In the Control Panel window, double-click Add or Remove Programs.

    2. Click Download Accelerator Plus.


      Note:
      You may need to use the scroll bar to view the whole list.

    3. Click Add/Remove, Change/Remove, or Remove (this varies with the operating system). Follow the prompts.


    3. To run the scan
    1. Start your Symantec antivirus program, and then run a full system scan.

      Note: If you ran the Add/Remove programs applet as described in the previous section, all the files may have been removed, and thus none of them will be detected.
    2. If any files are detected as Adware.DAP and depending on which software version you are using, you may see one or more of the following options:

      Note: This applies only to versions of Norton AntiVirus that support Security Risk detection. If you are running a version of Symantec AntiVirus Corporate Edition that supports Security Risk detection, and Security Risk detection has been enabled, you will only see a message box that gives the results of the scan. If you have questions in this situation, contact your network administrator.
      4. To delete the value from the registry

      Important:
      Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
      1. Click Start > Run.
      2. Type regedit

        Then click OK.

      3. Navigate to the key:

        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

      4. In the right pane, delete the value:

        "DownloadAccelerator"="%ProgramFiles%\DAP\DAP.EXE /STARTUP"

      5. Exit the Registry Editor

      5. To delete any remaining files

      Navigate to the %ProgramFiles%\DAP folder. Delete the folder and any files contained within it.