I have been having problems over the past few weeks with pop-ups showing up while my DSL is connected, regardless of whether I am browsing the Internet. My computer is overall very slow, which I've been remedying by just clearing the Task Manager of any unfamiliar programs. Finally, the desktop.exe bar started showing up on my desktop every time I started up my computer. I assume that it's due to spyware, but Ad-Aware and Spybot S&D never seem to fix this. Any help you could offer would be greatly appreciated!
Here's my HighjackThis log:
Logfile of HijackThis v1.99.1
Scan saved at 9:38:19 PM, on 3/24/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\oifvl\jgsgewy.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\arqsmuyn\aajyfc.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\program files\support.com\bin\tgcmd.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\PROGRA~1\Hardware\Keyboard\Ikeymain.exe
C:\PROGRA~1\Hardware\Mouse\Amoumain.exe
C:\WINDOWS\System32\soundcontrl.exe
C:\WINDOWS\aqadcup.exe
C:\WINDOWS\System32\Microsoft.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\DOCUME~1\FURIOU~1\LOCALS~1\Temp\32cx423.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\WINDOWS\System32\wintask.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\isrvs\desktop.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\secure.exe
C:\WINDOWS\System32\ykjrgve\jhmcml.exe
C:\windows\system32\vdxregvs.exe
C:\WINDOWS\System32\ffisysi6.exe
C:\WINDOWS\System32\pxabgq\armnrp.exe
C:\WINDOWS\System32\mfwjhuwc\pefkv.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\kkui\nwgctre.exe
C:\WINDOWS\System32\??chost.exe
C:\WINDOWS\System32\sysmonnt.exe
C:\WINDOWS\System32\hyfamjb\vghvqpgu.exe
C:\WINDOWS\System32\piokg\jpmryixe.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\WINDOWS\System32\taskmgr.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
C:\WINDOWS\System32\autodrop.exe
C:\HJT\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dellnet.comR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.dellnet.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://yahoo.sbc.com/dslR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://yahoo.sbc.com/dslR0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://red.clientapps.yahoo.com/customize/...//www.yahoo.comR3 - Default URLSearchHook is missing
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [sr1exe] "C:\Documents and Settings\All Users\Application Data\Dell\Alert\252\updtSup3.exe"
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [tgcmdprovidersbc] "c:\program files\support.com\bin\tgcmd.exe" /server /startmonitor /deaf /nosystray
O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\Hardware\Keyboard\Ikeymain.exe
O4 - HKLM\..\Run: [WheelMouse] C:\PROGRA~1\Hardware\Mouse\Amoumain.exe
O4 - HKLM\..\Run: [scvhost] scvhost.exe
O4 - HKLM\..\Run: [soundcontrl] soundcontrl.exe
O4 - HKLM\..\Run: [aqadcup] C:\WINDOWS\aqadcup.exe
O4 - HKLM\..\Run: [Microsoft Update] Microsoft.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [hcbyfsx] C:\WINDOWS\hcbyfsx.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Services] C:\DOCUME~1\FURIOU~1\LOCALS~1\Temp\32cx423.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdt.exe
O4 - HKLM\..\Run: [vidbbz] c:\windows\system32\vidbbz.exe
O4 - HKLM\..\Run: [8tyx6veo] C:\Program Files\8tyx6veo\8tyx6veo.exe
O4 - HKLM\..\Run: [mzwfgh] C:\WINDOWS\mzwfgh.exe
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
O4 - HKLM\..\Run: [AutoLoader3suo1PKfLZXK] "C:\WINDOWS\System32\eqngnt.exe" /HideDir /HideUninstall /PC="CP.BIG" /ShowLegalNote="nonbranded"
O4 - HKLM\..\Run: [3F5U35X] eqngnt.exe
O4 - HKLM\..\Run: [wwyem] C:\WINDOWS\System32\eygpy\wwyem.exe
O4 - HKLM\..\Run: [mlpxb] C:\WINDOWS\System32\edvg\mlpxb.exe
O4 - HKLM\..\Run: [jlhlatk] C:\WINDOWS\System32\gdgvmc\jlhlatk.exe
O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
O4 - HKLM\..\Run: [SystemCheck] C:\WINDOWS\SysCheckBop32
O4 - HKLM\..\Run: [uousam] C:\WINDOWS\System32\amion\uousam.exe
O4 - HKLM\..\Run: [krfbp] C:\WINDOWS\System32\uqvqrys\krfbp.exe
O4 - HKLM\..\Run: [nvif] C:\WINDOWS\System32\nxbhexbu\nvif.exe
O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
O4 - HKLM\..\Run: [BPT] "C:\Program Files\Bpt\bpt.exe"
O4 - HKLM\..\Run: [DI2] "C:\DOCUME~1\JD_ONL~1\LOCALS~1\Temp\27.exe\27.exe"
O4 - HKLM\..\Run: [secure] C:\WINDOWS\System32\secure.exe
O4 - HKLM\..\Run: [nsvcin] C:\WINDOWS\system32\n20050308.exe
O4 - HKLM\..\Run: [hgvqv] C:\WINDOWS\System32\foaw\hgvqv.exe
O4 - HKLM\..\Run: [ZStart] C:\windows\system32\vdxregvs.exe lee0105
O4 - HKLM\..\Run: [SysStart] C:\WINDOWS\System32\ffisysi6.exe lee0105
O4 - HKLM\..\Run: [txyisl] C:\WINDOWS\System32\nbls\txyisl.exe
O4 - HKLM\..\Run: [mvcmxhv] C:\WINDOWS\System32\yrmf\mvcmxhv.exe
O4 - HKLM\..\Run: [hsndkgd] C:\WINDOWS\System32\emam\hsndkgd.exe
O4 - HKLM\..\Run: [qxqal] C:\WINDOWS\System32\vefvkdts\qxqal.exe
O4 - HKLM\..\Run: [kpquywbg] C:\WINDOWS\System32\pkrwmxa\kpquywbg.exe
O4 - HKLM\..\Run: [ygld] C:\WINDOWS\System32\ajlbx\ygld.exe
O4 - HKLM\..\Run: [sgwds] C:\WINDOWS\System32\ihiifnuy\sgwds.exe
O4 - HKLM\..\Run: [bvmil] C:\WINDOWS\System32\istr\bvmil.exe
O4 - HKLM\..\Run: [gkfdv] C:\WINDOWS\System32\auchrdfi\gkfdv.exe
O4 - HKLM\..\Run: [onthbc] C:\WINDOWS\System32\hfrkqfcd\onthbc.exe
O4 - HKLM\..\Run: [hmdh] C:\WINDOWS\System32\oyqtqnwh\hmdh.exe
O4 - HKLM\..\Run: [krmoa] C:\WINDOWS\System32\srusxbp\krmoa.exe
O4 - HKLM\..\Run: [ogacxs] C:\WINDOWS\System32\edfsp\ogacxs.exe
O4 - HKLM\..\Run: [mvahkx] C:\WINDOWS\System32\bcem\mvahkx.exe
O4 - HKLM\..\Run: [fawufouy] C:\WINDOWS\System32\gdorcrug\fawufouy.exe
O4 - HKLM\..\Run: [bvklcmq] C:\WINDOWS\System32\wdmseywf\bvklcmq.exe
O4 - HKLM\..\Run: [etbrun] C:\windows\system32\elitexdh32.exe
O4 - HKLM\..\Run: [pxedminw] C:\WINDOWS\System32\nqsedq\pxedminw.exe
O4 - HKLM\..\Run: [rwbet] C:\WINDOWS\System32\xrtnt\rwbet.exe
O4 - HKLM\..\Run: [oatfrtt] C:\WINDOWS\System32\quwb\oatfrtt.exe
O4 - HKLM\..\Run: [tgsf] C:\WINDOWS\System32\igylk\tgsf.exe
O4 - HKLM\..\Run: [fhix] C:\WINDOWS\System32\axmacsig\fhix.exe
O4 - HKLM\..\Run: [fxlgifl] C:\WINDOWS\System32\sjhkp\fxlgifl.exe
O4 - HKLM\..\Run: [rxcqcvf] C:\WINDOWS\System32\yoihssy\rxcqcvf.exe
O4 - HKLM\..\Run: [qllxy] C:\WINDOWS\System32\oyiqjkg\qllxy.exe
O4 - HKLM\..\Run: [armnrp] C:\WINDOWS\System32\pxabgq\armnrp.exe
O4 - HKLM\..\Run: [cdsu] C:\WINDOWS\System32\peqnna\cdsu.exe
O4 - HKLM\..\Run: [mmkoru] C:\WINDOWS\System32\okyqnid\mmkoru.exe
O4 - HKLM\..\Run: [mwua] C:\WINDOWS\System32\mcaifdr\mwua.exe
O4 - HKLM\..\Run: [TrayComm] TrayComm.exe
O4 - HKLM\..\Run: [aajyfc] C:\WINDOWS\System32\arqsmuyn\aajyfc.exe
O4 - HKLM\..\Run: [jgsgewy] C:\WINDOWS\System32\oifvl\jgsgewy.exe
O4 - HKLM\..\Run: [pefkv] C:\WINDOWS\System32\mfwjhuwc\pefkv.exe
O4 - HKLM\..\Run: [hdky] C:\WINDOWS\System32\ydskoo\hdky.exe
O4 - HKLM\..\Run: [fcabn] C:\WINDOWS\System32\gwbfjup\fcabn.exe
O4 - HKLM\..\Run: [jhmcml] C:\WINDOWS\System32\ykjrgve\jhmcml.exe
O4 - HKLM\..\Run: [vghvqpgu] C:\WINDOWS\System32\hyfamjb\vghvqpgu.exe
O4 - HKLM\..\Run: [jpmryixe] C:\WINDOWS\System32\piokg\jpmryixe.exe
O4 - HKLM\..\Run: [nwgctre] C:\WINDOWS\System32\kkui\nwgctre.exe
O4 - HKLM\..\RunServices: [scvhost] scvhost.exe
O4 - HKLM\..\RunServices: [soundtasks] soundtasks.exe
O4 - HKLM\..\RunServices: [soundcontrl] soundcontrl.exe
O4 - HKLM\..\RunServices: [Microsoft Update] Microsoft.exe
O4 - HKCU\..\Run: [Yahoo! Pager] 1
O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\furious_d\Application Data\ttuh.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Dycku] C:\WINDOWS\System32\mzsuo.exe
O4 - HKCU\..\Run: [Vodojv] C:\WINDOWS\System32\??chost.exe
O4 - HKCU\..\Run: [ESPN BottomLine] C:\Program Files\ESPN\BottomLine\bline.exe
O4 - HKCU\..\Run: [Iou8RRbtQ] rasfldr.exe
O4 - HKCU\..\Run: [sysmonnt] C:\WINDOWS\System32\sysmonnt
O4 - Startup: DSL Connection.lnk = C:\WINDOWS\SYSTEM32\rasphone.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cabO16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary/MineSweeper.cabO16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
http://207.188.7.150/0693bf3230200b469302/...ip/RdxIE601.cabO16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} -
http://a1540.g.akamai.net/7/1540/52/200404...meInstaller.exeO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/Messe...StatsClient.cabO16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} -
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) -
http://photos.yahoo.com/ocx/us/yexplorer1_9us.cabO16 - DPF: {EB623776-492A-42CA-9571-3AA39F58530B} -
http://www.alwaysupdatednews.com/install/aun_0010.exeO17 - HKLM\System\CCS\Services\Tcpip\..\{AE96FB46-15EF-4AAD-823A-EF3053CBEC06}: NameServer = 65.43.19.26 206.141.192.60
O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - C:\WINDOWS\isrvs\mfiltis.dll
O20 - Winlogon Notify: ThemeManager - C:\WINDOWS\system32\mvp2l97o1.dll
O23 - Service: bvklcmqwdmseywf - Unknown owner - C:\WINDOWS\System32\wdmseywf\bvklcmq.exe
O23 - Service: bvmilistr - Unknown owner - C:\WINDOWS\System32\istr\bvmil.exe
O23 - Service: fhixaxmacsig - Unknown owner - C:\WINDOWS\System32\axmacsig\fhix.exe
O23 - Service: gkfdvauchrdfi - Unknown owner - C:\WINDOWS\System32\auchrdfi\gkfdv.exe
O23 - Service: jgsgewyoifvl - Unknown owner - C:\WINDOWS\System32\oifvl\jgsgewy.exe
O23 - Service: jhmcmlykjrgve - Unknown owner - C:\WINDOWS\System32\ykjrgve\jhmcml.exe
O23 - Service: krfbpuqvqrys - Unknown owner - C:\WINDOWS\System32\uqvqrys\krfbp.exe
O23 - Service: krmoasrusxbp - Unknown owner - C:\WINDOWS\System32\srusxbp\krmoa.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: mvahkxbcem - Unknown owner - C:\WINDOWS\System32\bcem\mvahkx.exe
O23 - Service: mvcmxhvyrmf - Unknown owner - C:\WINDOWS\System32\yrmf\mvcmxhv.exe
O23 - Service: nvifnxbhexbu - Unknown owner - C:\WINDOWS\System32\nxbhexbu\nvif.exe
O23 - Service: nwgctrekkui - Unknown owner - C:\WINDOWS\System32\kkui\nwgctre.exe
O23 - Service: oatfrttquwb - Unknown owner - C:\WINDOWS\System32\quwb\oatfrtt.exe
O23 - Service: pxedminwnqsedq - Unknown owner - C:\WINDOWS\System32\nqsedq\pxedminw.exe
O23 - Service: qllxyoyiqjkg - Unknown owner - C:\WINDOWS\System32\oyiqjkg\qllxy.exe
O23 - Service: rxcqcvfyoihssy - Unknown owner - C:\WINDOWS\System32\yoihssy\rxcqcvf.exe
O23 - Service: txyislnbls - Unknown owner - C:\WINDOWS\System32\nbls\txyisl.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE