File names:
dap.exe
dapiebar.exe
dapie.dll
dapns.dll
dapop.dll
dapbho.dll
When Adware.DAP runs, it does the following:
- Creates the following files:
- %ProgramFiles%\DAP\Ads\*.* (stored ads)
- %ProgramFiles%\DAP\Icons\dapgames.ico
- %ProgramFiles%\DAP\Locales\*.* (language files)
- %ProgramFiles%\DAP\Log\*.* (log files)
- %ProgramFiles%\DAP\Skins\Dap\*.bmp (files for
GUI skins)
- %ProgramFiles%\DAP\Temp\*.* (temporary files)
- %ProgramFiles%\DAP\Updates\*.* (update files)
- %ProgramFiles%\DAP\cabex.dll
- %ProgramFiles%\DAP\dap.exe (executable, runs at
boot, detected as Adware.DAP)
- %ProgramFiles%\DAP\dap.gif
- %ProgramFiles%\DAP\dapbho.dll (Internet Explorer
BHO, detected as Adware.DAP)
- %ProgramFiles%\DAP\dapextie.htm
- %ProgramFiles%\DAP\dapextie2.htm
- %ProgramFiles%\DAP\dapie.dll (Internet Explorer
DAP download interceptor)
- %ProgramFiles%\DAP\dapiebar.dll (the toolbar in
Internet Explorer, detected as Adware.DAP)
- %ProgramFiles%\DAP\dapmm.dll (multimedia
library)
- %ProgramFiles%\DAP\dapm_amdc.dll (multimedia
library)
- %ProgramFiles%\DAP\dapm_context_games.dll (games
library)
- %ProgramFiles%\DAP\dapm_ftp.dll (ftp client)
- %ProgramFiles%\DAP\dapns.dll (Netscape DAP
download interceptor)
- %ProgramFiles%\DAP\dapop.dll (Opera DAP download
interceptor)
- %ProgramFiles%\DAP\dapres.dll (DAP resource
library)
- %ProgramFiles%\DAP\dapres32.dll (DAP resource
library)
- %ProgramFiles%\DAP\dapupd.exe (DAP updater)
- %ProgramFiles%\DAP\install.log
- %ProgramFiles%\DAP\license.txt
- %ProgramFiles%\DAP\mfc42.dll (Microsoft library)
- %ProgramFiles%\DAP\mmc.xml
- %ProgramFiles%\DAP\msvcrt.dll (Microsoft
library)
- %ProgramFiles%\DAP\restartApp.exe
- %ProgramFiles%\DAP\screen.dat
- %ProgramFiles%\DAP\unwise.exe
- %ProgramFiles%\DAP\zlib.dll (data compression
library)
- %ProgramFiles%\DAP\*.gif (images)
- %System%\anigif.ocx (gif animation control)
- %System%\wbhelp2.dll (WindowBlinds helper DLL)
- %System%\wbocx (WindowBlinds helper
control)
Notes:
- %System% is a variable that refers to the
System folder. By default, this is
C:\Windows\System (Windows 95/98/Me),
C:\Winnt\System32 (Windows NT/2000), or
C:\Windows\System32 (Windows XP).
- %ProgramFiles% is a variable that refers to
the program files folder. By default, this is
C:\Program Files.
- Creates the following registry entries:
- HKEY_CLASSES_ROOT\CLSID\{8110AEA1-AD5B-4B90-883F-04A9A33B106E}
- HKEY_LOCAL_MACHINE\Software\Speedbit
- HKEY_CLASSES_ROOT\daffile
- HKEY_LOCAL_MACHINE\Microsoft\Internet
Explorer\Extensions\{669695BC-A811-4A9D-8CDF-BA8C795F261C}
- HKEY_CURRENT_USER\Software\Microsoft\Internet
Explorer\MenuExt\Download &all with DAP
- HKEY_USER\.DEFAULT\Software\Microsoft\Internet
Explorer\MenuExt\Download &all with DAP
- HKEY_CLASSES_ROOT\.das
- HKEY_CLASSES_ROOT\.dzs
- HKEY_CLASSES_ROOT\dzsfile
- HKEY_CLASSES_ROOT\dasfile
- HKEY_CURRENT_USER\Software\Netscape\Netscape
Navigator\Suffixes\application\x-speedbit-daf
- HKEY_CURRENT_USER\Software\Netscape\Netscape
Navigator\Suffixes\application\x-speedbit-dal
- HKEY_CURRENT_USER\Software\Netscape\Netscape
Navigator\Suffixes\application\x-speedbit-das
- HKEY_CURRENT_USER\Software\Netscape\Netscape
Navigator\Suffixes\application\x-speedbit-skin
- HKEY_CURRENT_USER\Software\Netscape\Netscape
Navigator\Viewers\application\x-speedbit-daf
- HKEY_CURRENT_USER\Software\Netscape\Netscape
Navigator\Viewers\application\x-speedbit-dal
- HKEY_CURRENT_USER\Software\Netscape\Netscape
Navigator\Viewers\application\x-speedbit-das
- HKEY_CURRENT_USER\Software\Netscape\Netscape
Navigator\Viewers\application\x-speedbit-skin
- HKEY_CLASSES_ROOT\DAPBHO.DAPHelper.1
- HKEY_CLASSES_ROOT\DAPBHO.DAPHelper
- HKEY_CLASSES_ROOT\CLSID\{F852086B-10E6-4743-9A3F-D8257A0A59E3}
- HKEY_CLASSES_ROOT\CLSID\{62999427-33FC-4BAF-9C9C-BCE6BD127F08}
- HKEY_CLASSES_ROOT\CLSID\{235D7A27-DE65-49F0-BFCF-D5C3BC3B2E67}
- Adds the
value:
"DownloadAccelerator"="%ProgramFiles%\DAP\DAP.EXE
/STARTUP"
to the registry
key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so
that the Adware runs when you start
Windows.
The following instructions pertain to
all Symantec antivirus products that support Security
Risk detection.
- Update the definitions.
- Uninstall Download Accelerator Plus using the
Add/Remove Programs utility.
- Run a full system scan.
- Delete the value that was added to the registry.
- Delete any remaining files.
For
specific details on each of these steps, read the
following instructions.
1. To update the
definitions
To obtain the most recent
definitions, start your Symantec program and run
LiveUpdate.
2. To uninstall the Adware
- Do one of the following:
- On the Windows 98 taskbar:
- Click Start > Settings > Control
Panel.
- In the Control Panel window, double-click
Add/Remove Programs.
- On the Windows Me taskbar:
- Click Start > Settings > Control
Panel.
- In the Control Panel window, double-click
Add/Remove Programs.
If you do not see
the Add/Remove Programs icon, click "...view
all Control Panel options."
- On the Windows 2000 taskbar:
By default,
Windows 2000 is set up the same as Windows 98, so
follow the instructions for Windows 98. If
otherwise, click Start, point to Settings
> Control Panel, and then click Add/Remove
Programs.
- On the Windows XP taskbar:
- Click Start > Control Panel.
- In the Control Panel window, double-click
Add or Remove
Programs.
- Click Download Accelerator
Plus.
Note: You may need to use
the scroll bar to view the whole list.
- Click Add/Remove, Change/Remove, or
Remove (this varies with the operating system).
Follow the prompts.
3. To run the
scan
- Start your Symantec antivirus program, and then
run a full system scan.
Note: If you ran
the Add/Remove programs applet as described in the
previous section, all the files may have been removed,
and thus none of them will be detected.
- If any files are detected as Adware.DAP and
depending on which software version you are using, you
may see one or more of the following
options:
Note: This applies only to
versions of Norton AntiVirus that support Security
Risk detection. If you are running a version of
Symantec AntiVirus Corporate Edition that supports
Security Risk detection, and Security Risk detection
has been enabled, you will only see a message box that
gives the results of the scan. If you have questions
in this situation, contact your network
administrator.
- Exclude (Not recommended): If you click this
button, it will set the threat so that it is no
longer detectable. That is, the antivirus program
will keep the security risk on your computer and
will no longer detect it to remove from your
computer.
- Ignore or Skip: This option tells the scanner to
ignore the threat for this scan only. It will be
detected again the next time that you run a
scan.
- Cancel: This option is new to Norton Antivirus
2005. It is used when Norton Antivirus 2005 has
determined that it cannot delete a security risk.
This Cancel option tells the scanner to ignore the
threat for this scan only, and thus, the threat will
be detected again the next time that you run a
scan.
To actually delete the security risk:
- Click its file name (under the Filename
column).
- In the Item Information box that displays,
write down the full path and file name.
- Then use Windows Explorer to locate and delete
the file.
If Windows reports that it
cannot delete the file, this indicates that the
file is in use. In this situation, complete the
rest of the instructions on this page, restart
the computer in Safe mode, and then delete the
file using Windows Explorer.
- Delete: This option will attempt to delete the
detected files. In some cases, the scanner will not
be able to do this.
- If you see a message, "Delete Failed" (or
similar message), manually delete the file.
- Click the file name of the threat that is
under the Filename column.
- In the Item Information box that displays,
write down the full path and file name.
- Then use Windows Explorer to locate and delete
the file.
If Windows reports that it
cannot delete the file, this indicates that the
file is in use. In this situation, complete the
rest of the instructions on this page, restart
the computer in Safe mode, and then delete the
file using Windows
Explorer.
4. To delete the value from the
registry
Important:
Symantec strongly recommends that you back up
the registry before making any changes to it.
Incorrect changes to the registry can result in
permanent data loss or corrupted files. Modify the
specified keys only. Read the document, "How to make a backup of the Windows
registry," for instructions.
- Click Start > Run.
- Type regedit
Then click OK.
- Navigate to the
key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- In the right pane, delete the
value:
"DownloadAccelerator"="%ProgramFiles%\DAP\DAP.EXE
/STARTUP"
- Exit the Registry Editor
5. To
delete any remaining files
Navigate to the
%ProgramFiles%\DAP folder. Delete the folder and any
files contained within it.