Whenever I turn on my computer and open up IE, a bunch of popups open up as well as a separate page for my home page. If I try to google anything, popupsearches.com comes up and all of this is really starting to slow down my computer. Along with that, since all of this starting happening, random words on sites and in my email become hyperlinked and it is getting irritating. There are also times when icons just show up on my desktop and I don't know where from.
Thanks in advance. Here is the log from Hijackthis.
Logfile of HijackThis v1.99.1
Scan saved at 5:30:12 PM, on 3/29/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
File: ACS.exe
Status: MIGHT BE INFECTED/MALWARE (Sandbox emulation took a long time and/or runtime packers were found, this is suspicious. Normally programs aren't packed and don't force the sandbox into lengthy emulation. Do realize no scanner issued any warning, the file can very well be harmless. Caution is advised, however.)
Packers detected: -
AntiVir No viruses found
Avast No viruses found
AVG Antivirus No viruses found
BitDefender No viruses found
ClamAV No viruses found
Dr.Web No viruses found
F-Prot Antivirus No viruses found
Fortinet No viruses found
Kaspersky Anti-Virus No viruses found
mks_vir No viruses found
NOD32 No viruses found
Norman Virus Control No viruses found
And the second file...
Service load: 0% 100%
File: TCtrlIOHook.exe
Status: MIGHT BE INFECTED/MALWARE (Sandbox emulation took a long time and/or runtime packers were found, this is suspicious. Normally programs aren't packed and don't force the sandbox into lengthy emulation. Do realize no scanner issued any warning, the file can very well be harmless. Caution is advised, however.)
Packers detected: -
AntiVir No viruses found
Avast No viruses found
AVG Antivirus No viruses found
BitDefender No viruses found
ClamAV No viruses found
Dr.Web No viruses found
F-Prot Antivirus No viruses found
Fortinet No viruses found
Kaspersky Anti-Virus No viruses found
mks_vir No viruses found
NOD32 No viruses found
Norman Virus Control No viruses found
Third File...
Service load: 0% 100%
File: ZoomingHook.exe
Status: MIGHT BE INFECTED/MALWARE (Sandbox emulation took a long time and/or runtime packers were found, this is suspicious. Normally programs aren't packed and don't force the sandbox into lengthy emulation. Do realize no scanner issued any warning, the file can very well be harmless. Caution is advised, however.)
Packers detected: -
AntiVir No viruses found
Avast No viruses found
AVG Antivirus No viruses found
BitDefender No viruses found
ClamAV No viruses found
Dr.Web No viruses found
F-Prot Antivirus No viruses found
Fortinet No viruses found
Kaspersky Anti-Virus No viruses found
mks_vir No viruses found
NOD32 No viruses found
Norman Virus Control No viruses found
Fourth File...
Service load: 0% 100%
File: TPSMain.exe
Status: MIGHT BE INFECTED/MALWARE (Sandbox emulation took a long time and/or runtime packers were found, this is suspicious. Normally programs aren't packed and don't force the sandbox into lengthy emulation. Do realize no scanner issued any warning, the file can very well be harmless. Caution is advised, however.)
Packers detected: -
AntiVir No viruses found
Avast No viruses found
AVG Antivirus No viruses found
BitDefender No viruses found
ClamAV No viruses found
Dr.Web No viruses found
F-Prot Antivirus No viruses found
Fortinet No viruses found
Kaspersky Anti-Virus No viruses found
mks_vir No viruses found
NOD32 No viruses found
Norman Virus Control No viruses found
And the last file..
Service load: 0% 100%
File: TPSBattM.exe
Status: MIGHT BE INFECTED/MALWARE (Sandbox emulation took a long time and/or runtime packers were found, this is suspicious. Normally programs aren't packed and don't force the sandbox into lengthy emulation. Do realize no scanner issued any warning, the file can very well be harmless. Caution is advised, however.)
Packers detected: -
AntiVir No viruses found
Avast No viruses found
AVG Antivirus No viruses found
BitDefender No viruses found
ClamAV No viruses found
Dr.Web No viruses found
F-Prot Antivirus No viruses found
Fortinet No viruses found
Kaspersky Anti-Virus No viruses found
mks_vir No viruses found
NOD32 No viruses found
Norman Virus Control No viruses found
Thanks again for all of your help! I'm a complete idiot when it comes to computers.
Roshni
John L
03/28/05
Ok Roshni, not the results i thought would come back, but that's a good thing.
Here's what we have to do next.
fire up hijack this, hit scan only and place checks next to these.
O2 - BHO: CeresObj Class - {0049-8F91-4D9C-9573-F016E7626484} - C:\WINDOWS\ceres.dll (file missing)
O2 - BHO: ohb - {999A06FF-10EF-4A29-8640-69E99882C26B} - C:\WINDOWS\system32\rtneg2.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [ydxvoac] c:\windows\system32\ydxvoac.exe Unknown
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
Okay, I ran and clicked on the files you put up and then clicked fix. Except for the first one which for some reason was not showing up when I scanned. Also, when I went to delete the file you said, I couldn't find it. Should I do another scan before rebooting my computer? Or reboot and then do another scan?
John L
03/28/05
Reboot and send a new scan please
Roshni
03/28/05
Here is the new scan log.
Logfile of HijackThis v1.99.1
Scan saved at 8:01:32 PM, on 3/29/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Yes! Thanks John. The stupid popups didn't come up when I opened up IE and I tried a google search and popupsearch.com didn't come up. And those stupid hyperlinked words are gone as well.
Thank you so much. I'm so glad I found this place.
Thanks again :-)
John L
03/28/05
You're very welcome and we are glad you found this place as well. I'm just going to provide a little reading so that you can avoid reinfection. :-)
I'm having the same problem and I don't know what you guys are talking about! PLEASE HELP!
John L
03/30/05
Hi Julee:
I should have closes this thread when it was finished, but at this time I'm glad i did'nt. I will be posting some instructions below, please follow them and create a new thread.
This thread is now closed.
If anyone wishes to post, you simply need to click on the "Start new question thread" button below. Give your thread a title in the "Re:" box, and then write your message (filling in the other boxes is useful as well).