Sorry for my English as it is my first Post.
My Computer is sending unknown emails even if I’m not doing anything.I hope someone can help me.Here is my Hijackthis log.
have you tried
Boot time Avast Antivirus Scanning
http://www.digitalred.com/avast-boot-time.php
Check your computer for Malware with
MBAM http://filehippo.com/download_malwarebytes_anti_malware/
update and run quick scan, click the button “remove selected” to quarantine anything found, and restart
SAS http://filehippo.com/download_superantispyware/
Are cookies really spyware and are they dangerous?
http://www.superantispyware.com/supportfaqdisplay.html?faq=26
If anything is found other than cookies you may post the scan logs here
When you get your XP SP2 system free of malware XP SP3 has been available for over a year and provides many Critical Updates plus performance improvements.
You need to start Internet Explorer then go to Tools then Windows Update and download all of the available updates.
Go to Control Panel then Automatic Updates then select Automatic (recommended) or at least Notify me but don’t automatically download or install them.
IE8 is more secure than IE6 and has a lot better performance:
http://www.microsoft.com/windows/Internet-explorer/default.aspx
You have a very down level of Java installed in JRE 1.3.1 so go to Add/Remove Programs and un-install it.
Version 6 Update 17 is the latest version:
http://java.com/en/download/manual.jsp
Go to Secunia Online Software Inspector then run it to see what other applications are vulnerable:
http://secunia.com/vulnerability_scanning/online
Welcome to the forums, ssswrd. ![]()
In addition to the above replies, an analysis of your HJT log shows the following problems.
Platform: Windows XP SP2 (WinNT 5.01.2600)
A newer version of service pack is available. Service packs increase the safety of your system. Visit Microsoft’s windowsupdate site to download the newest version of the service pack.
It seems that you don’t use an anti-virus scanner or your scanner is not active. Only an anti-virus scanner can protect you against new viruses.
We couldn’t detect any active process of a firewall on your system. Possible reasons:
(1.) You are using the windows firewall or a hardware firewall.
(2.) You are using a firewall of an unknown vendor.
(3.) You are using a firewall, but for unknown reasons it is disabled
(4.) You don’t use any firewall at all.
We recommend you to use a firewall. Download and install one or activate windows xp´s own firewall.
A 2-way firewall would be better.
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
This entry should be fixed with HJT.
Overview of running tasks :
smss.exe
System task
Session Manager Subsystem
winlogon.exe
System task
Microsoft Windows Logon Process
services.exe
System task
Windows Service Controller
lsass.exe
System task
Local Security Authority Service
Ati2evxx.exe
Driver
ATI Display Adapter Assistant
svchost.exe
System task
Microsoft Service Host Process
svchost.exe
System task
Microsoft Service Host Process
Ati2evxx.exe
Driver
ATI Display Adapter Assistant
spoolsv.exe
System task
Microsoft Printer Spooler Service
Explorer.EXE
System task
Microsoft Windows Explorer
mDNSResponder.exe
Backgroundtask
Bonjour for Windows Component
EMLPROXY.EXE
Virusscan
EMLPROXY.EXE
jqs.exe
Backgroundtask
Java Quick Starter Service
opssvc.exe
Unknown task ( part of Quick Heal AntiVirus )
Unknown task http://www.tallemu.com/oasis2/file/quick_heal_technologies__pvt__ltd_/quick_heal_antivirus/opssvc_exe/2751436
quhlpsvc.exe
Virusscan
quhlpsvc.exe
EMLPROUI.EXE
Virusscan
EMLPROUI.EXE
SCANMSG.EXE
Virusscan
AntiVirus Quick Heal
RichVideo.exe
Backgroundtask
Cyberlink Power Director Video Module
RichVideo.exe
Backgroundtask
Cyberlink Power Director Video Module
scanwscs.exe
Virusscan
Quick Heal Helper Service
Acrotray.exe
Backgroundtask
Acrobat Traybar Assistant
OnlineNT.EXE
Unknown task ( part of Quick Heal AntiVirus )
Unknown task http://www.tallemu.com/oasis2/file/unspecified_vendor/quick_heal_antivirus/onlinent_exe/834277
jusched.exe
Backgroundtask
Sun Java Update Scheduler
realsched.exe
Application
RealNetworks Scheduler
StatusClient.exe
Backgroundtask
Hewlett-Packard Status Client
OrderReminder.exe
Backgroundtask
OrderReminder
GoogleUpdate.exe
Backgroundtask
GoogleUpdate.exe
GoogleUpdate.exe
Backgroundtask
Google Updater
ctfmon.exe
System task
Alternative User Input Services
uTorrent.exe
Backgroundtask
?Torrent
javaw.exe
Application
Sun Java
acrobat_sl.exe
Backgroundtask
Adobe Acrobat Speed Launcher
webshots.scr
Application
Webshots Desktop Image Downloader
wuauclt.exe
System task
AutoUpdate Client
Scanner.exe http://www.bleepingcomputer.com/startups/Scanner.exe-4759.html
Suspicious task
Retina Scanner Module http://www.backgroundtask.eu/Systeemtaken/Taakinfo.php?ID=5745
HiJackThis.exe
Application
Merijn Hijackthis
I just solved the problem.I removed some unused files using HijackThis and the problem was gone.
If you do not mind, would you please tell us what files you removed?
I removed opssvc and quhlpsvc as they were not there before the Problem.
Thanks for posting back.
Both those files are listed as being a part of Quick Heal anti-virus.
It seems that the Problem has returned again.My Internet Speed is low,performance is high.I found that siszyd32 was causing this.So I removed it with freefixer.But still My Internet Speed is low.
Have you checked your computer for malware?
Did you try the suggestions in reply #1
I have checked with MBAM and SAS.They show my computer is clean.
Hi,
If you need to make sure whether your system has secured, just please follow this instruction for using ComboFix
Here is my Combofix log.
Simple,
Try changing your password.
Maybe a keylogger got your password
I get the message C:\Windows\system32\services.exe is trying to send emails.
You may have match #2 at the link below. Be sure to compare the Hashmark numbers in order to be sure which services.exe is causing your problem.
http://www.pcpitstop.com/libraries/process/i/services.exe.html
I have checked the MD5 Hash of my services.exe with the ones provided in the link match #1.So should I allow it to send mails?