Place a check against each of the following:R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://kingkongsearch.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssbR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.bearshare.com/sidebar.html?src=ssbR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssbO2 - BHO: Close all open programs and windows on your desktop. The bad guys use P2P filesharing as a major conduit to spread their wares. Each step discovered and helped me "supposedly" remove the malware, etc but these ads and voices keep popping up on my computer. Source

or read our Welcome Guide to learn how to use this site. C:\WINDOWS\system32\nsw35.dll unregistered successfully. It may be contributing to your current situation.

  1. rob kirstenishot, Feb 5, 2008 #13 sjpritch25 Malware Specialist Joined: Sep 8, 2005 Messages: 9,113 Check back with me in a couple of days.
  5. Close any programs you may have running - especially your web browser.
  6. Restart your computer.
  7. Important!After reboot, * Download Deljob.exe and save it on your desktop.Doubleclick Deljob.exe.A log, (logit.txt) should open afterwards.
  8. I just got one from Dcads, not sure why, but its the first one in a few days.

I ran AAW+ overnight and it found a malware object - of the Trojan.Win32 type! The page will refresh. Here is the uninstall_txt. Total Physical Memory: 503 MiB (512 MiB recommended). -- HijackThis (run as Alex.exe) ------------------------------------------------ Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 19:47:22, on 01/02/2008 Platform: Windows XP SP2 (WinNT

Hope this log is right from the latest scan I carried out- not done this before! Random, off-topic discussion. You will be sharing files from uncertified sources, and these are often infected. These can be found under the tools menu (top left toolbar one) on IE.

If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs. --------------------------------------------------------------------------------------------- Please visit this webpage for instructions for downloading and running ComboFix: Please re-enable javascript to access full functionality. Oh and in case pa4jj doesn't get back here , thanks for all your energy expended in helping. Once the update has finished, exit SUPERAntiSpyware.

Join 91147 other members! http://www.pchubs.com/blogs/dcads-toolbar-or-superiorads-removal-process and I only visit safe sites. C:\WINDOWS\system32\iebrowserc.dll moved successfully. sjpritch25, Feb 1, 2008 #8 kirstenishot Thread Starter Joined: Jan 24, 2008 Messages: 19 it's actually running quite well, the number of ads has been minimized to almost none..

I have installed all the updates I can. this contact form If there's anything that you do not understand, kindly ask your questions before proceeding. Stay Connected RSS YouTube Twitter LinkedIn Xing Weibo What We Do Software License Optimization Application Readiness Software Vulnerability Management Installation Software Monetization Company Contact Us About Flexera Software Website Feedback Site Go to Manage Add Ons.

All are TAI 10. References for the risk of these programs are here, here and here. Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quietO4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exeO4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -hO4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe have a peek here Click Exit on the Main menu to close the program.

Click the red Moveit! sjpritch25, Feb 4, 2008 #10 kirstenishot Thread Starter Joined: Jan 24, 2008 Messages: 19 Cool thanks for the response! The bad guys are not after you , but they will find you if you paint a target on your computer .

TiMow EDIT: All the above suggested settings, are what I have set on IE, and I never encountered this problem with these settings, when I did used to use IE.--Computing is

AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! Booting into safe mode may allow certain malicious files to be deleted. Find the Folder called HKEY_Current_User,open the folder up.-> Find another folder within the HKEY_Current_User called " Software " open it up.-> Open up a folder called " Microsoft "-> Find a Please help!!

Thread Tools Search this Thread 02-01-2008, 01:02 PM #1 awilson Registered Member Join Date: Jan 2008 Posts: 1 OS: xp Hi, I keep getting superior ads and DC ads Rerun Hijackthis (scan only) and place checks beside the following entriesR3 - URLSearchHook: (no name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)O2 - BHO: superiorads - {4AD44D3E-7316-4251-B754-9B10EC96AF92} - C:\WINNT\system32\sprt_ads.dllO2 - BHO: (no name)

Superiorads And Dcads Are A B%$ch! Terms and Conditions Privacy Policy Here's the real way to stop this scum-of-the-earth program: First search for any program with DCADS in it's name, and then delete it. Consistently helpful members with best answers are invited to staff.

All of a sudden I see windows from internet explorer opened by itself. Welcome! WE'RE SURE THAT YOU'LL LOVE US! Please note: Even if you are using a "safe" P2P program, it is only the program that is safe.

kirstenishot, Jan 31, 2008 #3 sjpritch25 Malware Specialist Joined: Sep 8, 2005 Messages: 9,113 Welcome to TSG Sorry for the delay Since its be awhile, please post a fresh Hijackthis log.