I keep getting popups with these addresses:
http://bannerfarm.ace.advertising.com/bannerfarm/dealhelper.htmlhttp://media.fastclick.net/w/pop.cgi?sid=18667&m=2&CK=N&JS=N&c=1108374820I've updated and ran adaware, spybot, spy sweeper and xoft spy but i'm still having the problem. Also when i visit web pages part of the page shows "the page cannot be displayed" message.
here the hijack this log:
Logfile of HijackThis v1.91.2
Scan saved at 10:57:24, on 14/02/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page=
http://www.bbc.co.uk/comedy/tickets/R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page=
http://www.bbc.co.uk/comedy/tickets/R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant=
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH
elper.dll
O2 - BHO: (no name) - {9394EDE7-C8B5-483E-8773-4
74BF36AF6E
4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en
-xu\stmain
.dll
O2 - BHO: (no name) - {BDBD1DAD-C946-4A17-ADC1-6
4B5B4FF55D
0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en
-gb\msntb.
dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-F
ADC6B08487
2} - D:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-0
0D0B743919
D} - C:\WINDOWS\System32\Stopzi
llaBHO.dll
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "d:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [STOPzilla] "D:\Program Files\STOPzilla!\Stopzilla
.exe" /autorun
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.10
01\en-gb\m
snappau.ex
e"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMo
n.exe
O4 - HKLM\..\Run: [AcctMgr] D:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [Advanced Tools Check] C:\Documents and Settings\Steve\Local Settings\Temp\Norton AntiVirus 2003 Professional\AdvTools\AdvC
hk.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [GhostStartTrayApp] D:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.ex
e
O4 - HKLM\..\Run: [GuAb] C:\WINDOWS\xfynydf.exe
O4 - HKLM\..\Run: [jcn] C:\WINDOWS\jcn.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCh
eck.exe
O4 - HKLM\..\Run: [Printer Driver Helper Service] C:\WINDOWS\system32\crsrr.
exe
O4 - HKLM\..\Run: [ReleaseRAM] C:\Program Files\R-RAM\RRAM.exe
O4 - HKLM\..\RunServices: [Windows Update Process] wmiprvsc.exe
O4 - HKCU\..\Run: [SymKeepAlive] C:\Program Files\Symantec\Web Tools\CKA.exe
O4 - HKCU\..\Run: [Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID {DA9935BA-22F7-44ee-BD12-B
D8B87700BE
A}
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [WheresJames Startup Manager] C:\Program Files\WheresJames\StartupM
gr\Startup
Mgr.exe
O4 - HKCU\..\Run: [MemOptimizer] "E:\Steve\eMule\Incoming\T
o Move\memoptimizer.2.0.buil
d.30.crack
ed-tsrh\Me
mOptimizer
.exe"
O4 - Startup: Connection Keeper.lnk = C:\Program Files\Connection Keeper\ConKeepM.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1
\Office10\
EXCEL.EXE/
3000
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: {0000000A-0000-0010-8000-0
0AA00389B7
1} -
http://download.microsoft.com/download/d/4/4/d446e8a9-3a86-4b59-bb19-f5bd11b40367/wmavax.CABO16 - DPF: {39B0684F-D7BF-4743-B050-F
DC3F48F7E3
B} (FilePlanet Download Control Class) -
http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cabO16 - DPF: {9F1C11AA-197B-4942-BA54-4
7A8489BB47
F} -
http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38101.2416666667O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-0
0105AA9B6A
E} (Symantec RuFSI Registry Information Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab