This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] adssite

26 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

…I hope this adssite thing disappears. ._. Just to tell you again, I went through the whole run and the regedit thing, and for some odd reason, it still pops back up after I did the merge thing.

We don't want to merge it again. Just export that key to the desktop and let it sit there until we see what happens.

Apparently, my results showed there are 25 examples of less dangerous malicious software.

I haven't used that scan myself. Did it give you a log or anything?
I saved it on my computer, but I'm not sure if its accurate. ;******************************************************************************* ********************************************************************************* ******************* ANALYSIS: 2007-12-23 14:54:06 PROTECTIONS: 1 MALWARE: 25 SUSPECTS: 0 ;******************************************************************************* ********************************************************************************* ******************* PROTECTIONS Description Version Active Updated ;=============================================================================== ================================================================================= =================== Norton AntiVirus 2004 Yes Yes ;=============================================================================== ================================================================================= =================== MALWARE Id Description Type Active Severity Disinfectable Disinfected Location ;=============================================================================== ================================================================================= =================== 00101555 Application/KillApp.B HackTools No 0 Yes No C:\hp\bin\KillIt.exe 00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.casalemedia.com/] 00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.casalemedia.com/] 00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.casalemedia.com/] 00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.casalemedia.com/] 00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.casalemedia.com/] 00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.casalemedia.com/] 00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.casalemedia.com/] 00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.casalemedia.com/] 00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.casalemedia.com/] 00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.doubleclick.net/] 00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.atdmt.com/] 00139535 Application/Processor HackTools No 0 Yes No C:\SDFix\apps\Process.exe 00139535 Application/Processor HackTools No 0 No No C:\Documents and Settings\Mai\Desktop\Anti stuff\VirtumundoBeGone.exe[²ƒÇ] 00139535 Application/Processor HackTools No 0 Yes No C:\Documents and Settings\Mai\Desktop\Anti stuff\SmitfraudFix\Process.exe 00139535 Application/Processor HackTools No 0 Yes No C:\RECYCLER\S-1-5-21-2287299698-3785260864-2669029396-1009\Dc391\SDFix\apps\Process.exe 00139535 Application/Processor HackTools No 0 Yes No C:\RECYCLER\S-1-5-21-2287299698-3785260864-2669029396-1009\Dc385\Process.exe 00139535 Application/Processor HackTools No 0 Yes No C:\Program Files\Mozilla Firefox\SmitfraudFix\Process.exe 00139535 Application/Processor HackTools No 0 No No C:\SDFix.exe[SDFix\apps\Process.exe] 00139535 Application/Processor HackTools No 0 No No C:\RECYCLER\S-1-5-21-2287299698-3785260864-2669029396-1009\Dc386.exe[SDFix\apps\Process.exe] 00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.fastclick.net/] 00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.fastclick.net/] 00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.fastclick.net/] 00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.fastclick.net/] 00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.fastclick.net/] 00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.fastclick.net/] 00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.fastclick.net/] 00168061 Cookie/Apmebf TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.apmebf.com/] 00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.advertising.com/] 00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.advertising.com/] 00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.advertising.com/] 00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.advertising.com/] 00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.advertising.com/] 00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.ads.pointroll.com/] 00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.ads.pointroll.com/] 00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.ads.pointroll.com/] 00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.ads.pointroll.com/] 00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.ads.pointroll.com/] 00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.ads.pointroll.com/] 00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.ads.pointroll.com/] 00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.questionmarket.com/] 00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.questionmarket.com/] 00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.questionmarket.com/] 00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.zedo.com/] 00173520 Cookie/Bluestreak TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.bluestreak.com/] 00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.adrevolver.com/] 00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.adrevolver.com/] 00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\84agba56.default\cookies.txt[.adrevolver.com/] 00252281 Adware/Trymedia Adware No 0 Yes No C:\RECYCLER\S-1-5-21-2287299698-3785260864-2669029396-1009\Dc371.part 00517584 Application/SuperFast HackTools No 0 Yes No C:\RECYCLER\S-1-5-21-2287299698-3785260864-2669029396-1009\Dc385\restart.exe 00517584 Application/SuperFast HackTools No 0 Yes No C:\Documents and Settings\Mai\Desktop\Anti stuff\SmitfraudFix\restart.exe 00517584 Application/SuperFast HackTools No 0 Yes No C:\Program Files\Mozilla Firefox\SmitfraudFix\restart.exe 00519333 Application/Processor HackTools No 0 Yes No C:\Documents and Settings\Mai\Desktop\Anti stuff\VirtumundoBeGone.exe 01262593 Application/NirCmd.A HackTools No 0 No No C:\RECYCLER\S-1-5-21-4266035414-202895112-2063273557-1010\Dc1.exe[nircmd.exe] 01262593 Application/NirCmd.A HackTools No 0 No No C:\RECYCLER\S-1-5-21-4266035414-202895112-2063273557-1010\Dc1.exe[nircmd.cfexe] 01262593 Application/NirCmd.A HackTools No 0 Yes No C:\WINDOWS\NirCmd.exe 02197130 Trj/Rebooter.J Virus/Trojan No 1 Yes No C:\Documents and Settings\Mai\Desktop\Anti stuff\SmitfraudFix\Reboot.exe 02197130 Trj/Rebooter.J Virus/Trojan No 1 Yes No C:\RECYCLER\S-1-5-21-2287299698-3785260864-2669029396-1009\Dc385\Reboot.exe 02402103 Adware/AdRotator Adware No 0 No No C:\RECYCLER\S-1-5-21-2287299698-3785260864-2669029396-1009\Dc395.zip[setup.exe][²ÜÇ\setup_rightonadz.exe][■%%\gzmrotate.dll] 02402103 Adware/AdRotator Adware No 0 No No C:\RECYCLER\S-1-5-21-2287299698-3785260864-2669029396-1009\Dc394.zip[setup.exe][²ÜÇ\setup_rightonadz.exe][■%%\gzmrotate.dll] 02402103 Adware/AdRotator Adware No 0 No No C:\RECYCLER\S-1-5-21-2287299698-3785260864-2669029396-1009\Dc396.zip[setup.exe][²ÜÇ\setup_rightonadz.exe][■%%\gzmrotate.dll] 02423299 Adware/AdRotator Adware No 0 No No C:\RECYCLER\S-1-5-21-2287299698-3785260864-2669029396-1009\Dc396.zip[setup.exe][²ÜÇ\setup_rightonadz.exe] 02423299 Adware/AdRotator Adware No 0 No No C:\RECYCLER\S-1-5-21-2287299698-3785260864-2669029396-1009\Dc395.zip[setup.exe][²ÜÇ\setup_rightonadz.exe] 02423299 Adware/AdRotator Adware No 0 No No C:\RECYCLER\S-1-5-21-2287299698-3785260864-2669029396-1009\Dc394.zip[setup.exe][²ÜÇ\setup_rightonadz.exe] 02427695 Adware/AdRotator Adware No 0 No No C:\RECYCLER\S-1-5-21-2287299698-3785260864-2669029396-1009\Dc394.zip[setup.exe][²ÜÇ\ads_3.5.exe][²ªÇ] 02427695 Adware/AdRotator Adware No 0 No No C:\RECYCLER\S-1-5-21-2287299698-3785260864-2669029396-1009\Dc395.zip[setup.exe][²ÜÇ\ads_3.5.exe][²ªÇ] 02427695 Adware/AdRotator Adware No 0 No No C:\RECYCLER\S-1-5-21-2287299698-3785260864-2669029396-1009\Dc396.zip[setup.exe][²ÜÇ\ads_3.5.exe][²ªÇ] 02427696 Adware/AdRotator Adware No 0 No No C:\RECYCLER\S-1-5-21-2287299698-3785260864-2669029396-1009\Dc396.zip[setup.exe][²ÜÇ\ads_3.5.exe][²ïÇ] 02427696 Adware/AdRotator Adware No 0 No No C:\RECYCLER\S-1-5-21-2287299698-3785260864-2669029396-1009\Dc394.zip[setup.exe][²ÜÇ\ads_3.5.exe][²ïÇ] 02427696 Adware/AdRotator Adware No 0 No No C:\RECYCLER\S-1-5-21-2287299698-3785260864-2669029396-1009\Dc395.zip[setup.exe][²ÜÇ\ads_3.5.exe][²ïÇ] 02427697 Adware/AdRotator Adware No 0 No No C:\RECYCLER\S-1-5-21-2287299698-3785260864-2669029396-1009\Dc396.zip[setup.exe][²ÜÇ\ads_3.5.exe] 02427697 Adware/AdRotator Adware No 0 No No C:\RECYCLER\S-1-5-21-2287299698-3785260864-2669029396-1009\Dc395.zip[setup.exe][²ÜÇ\ads_3.5.exe] 02427697 Adware/AdRotator Adware No 0 No No C:\RECYCLER\S-1-5-21-2287299698-3785260864-2669029396-1009\Dc394.zip[setup.exe][²ÜÇ\ads_3.5.exe] 02427701 Adware/WebHancer Adware No 0 Yes No C:\RECYCLER\S-1-5-21-2287299698-3785260864-2669029396-1009\Dc394.zip[setup.exe] 02427701 Adware/WebHancer Adware No 0 Yes No C:\RECYCLER\S-1-5-21-2287299698-3785260864-2669029396-1009\Dc395.zip[setup.exe] 02427701 Adware/WebHancer Adware No 0 Yes No C:\RECYCLER\S-1-5-21-2287299698-3785260864-2669029396-1009\Dc396.zip[setup.exe] 02634745 Application/Playmp3z HackTools No 0 Yes No C:\RECYCLER\S-1-5-21-2287299698-3785260864-2669029396-1009\Dc393.zip[Setup.exe] ;=============================================================================== ================================================================================= =================== SUSPECTS Location ;=============================================================================== ================================================================================= =================== ;=============================================================================== ================================================================================= ===================
We don't need to worry about those. We can kill those with ATF cleaner.

Any popups from Adssite?


Delete these folders:
C:\SDFix
C:\Documents and Settings\Mai\Desktop\Anti stuff\SmitfraudFix

Delete this file:
C:\Documents and Settings\Mai\Desktop\Anti stuff\VirtumundoBeGone.exe


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

So far none, but this morning, I got an adssite pop up.

Was that before we exported the reg key?

Please go here:

http://www.billsway.com/vbspage/

Scroll to the bottom third of the page where you will find the download link.

Input adssite and it should produce a log of EVERY instance of adssite in you regitry.

Please post that log here.
Is it the startup list? Nevermind. Here you go. I hope this is right. REGEDIT4 ; RegSrch.vbs © Bill James ; Registry search results for string "adssite" 12/23/2007 5:04:12 PM ; NOTE: This file will be deleted when you close WordPad. ; You must manually save this file to a new location if you want to refer to it again later. ; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.) [HKEY_USERS\S-1-5-21-1547285-3713172090-2628342386-1009\Software\Microsoft\adssite] [HKEY_USERS\S-1-5-21-1547285-3713172090-2628342386-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*] "b"="C:\\Documents and Settings\\HP_Owner\\Desktop\\Adssite.reg" [HKEY_USERS\S-1-5-21-1547285-3713172090-2628342386-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\reg] "d"="C:\\Documents and Settings\\HP_Owner\\Desktop\\Adssite.reg"
Registry Search Tool
Click the little down arrow> over to the right see the icon that has like 29974.
Click that and select Open. It should show a file regsrch.vbs file.
Open that file (double click) select open then in the open window type in adssite
Just in case if you didn't see the above. :) REGEDIT4 ; RegSrch.vbs © Bill James ; Registry search results for string "adssite" 12/23/2007 5:04:12 PM ; NOTE: This file will be deleted when you close WordPad. ; You must manually save this file to a new location if you want to refer to it again later. ; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.) [HKEY_USERS\S-1-5-21-1547285-3713172090-2628342386-1009\Software\Microsoft\adssite] [HKEY_USERS\S-1-5-21-1547285-3713172090-2628342386-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*] "b"="C:\\Documents and Settings\\HP_Owner\\Desktop\\Adssite.reg" [HKEY_USERS\S-1-5-21-1547285-3713172090-2628342386-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\reg] "d"="C:\\Documents and Settings\\HP_Owner\\Desktop\\Adssite.reg"
Launch Notepad (Start>All Programs>Accessories), and copy/paste all the Quoted REGEDIT below to it. Don't forget to include REGEDIT4.
Save in: Desktop
File Name: fixme.reg
Save as Type: * files
Click: Save

REGEDIT4

[-HKEY_USERS\S-1-5-21-1547285-3713172090-2628342386-1009\Software\Microsoft\adssite]

[HKEY_USERS\S-1-5-21-1547285-3713172090-2628342386-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*]
"b"=-
[HKEY_USERS\S-1-5-21-1547285-3713172090-2628342386-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\reg]
"d"=-


Save this as fix.reg Choose to save as *all files and place it on your desktop.
It should look like this: [external image: Posted Image]
Doubleclick on it and when it asks you if you want to merge the contents to the registry, click yes/ok.
(In case you are unsure how to create a reg file, take a look here with screenshots.)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI