Unknown Emails

Sorry for my English as it is my first Post.
My Computer is sending unknown emails even if I’m not doing anything.I hope someone can help me.Here is my Hijackthis log.

have you tried

Boot time Avast Antivirus Scanning
http://www.digitalred.com/avast-boot-time.php

Check your computer for Malware with

MBAM http://filehippo.com/download_malwarebytes_anti_malware/
update and run quick scan, click the button “remove selected” to quarantine anything found, and restart

SAS http://filehippo.com/download_superantispyware/

Are cookies really spyware and are they dangerous?
http://www.superantispyware.com/supportfaqdisplay.html?faq=26

If anything is found other than cookies you may post the scan logs here

When you get your XP SP2 system free of malware XP SP3 has been available for over a year and provides many Critical Updates plus performance improvements.

You need to start Internet Explorer then go to Tools then Windows Update and download all of the available updates.

Go to Control Panel then Automatic Updates then select Automatic (recommended) or at least Notify me but don’t automatically download or install them.

IE8 is more secure than IE6 and has a lot better performance:
http://www.microsoft.com/windows/Internet-explorer/default.aspx

You have a very down level of Java installed in JRE 1.3.1 so go to Add/Remove Programs and un-install it.

Version 6 Update 17 is the latest version:
http://java.com/en/download/manual.jsp

Go to Secunia Online Software Inspector then run it to see what other applications are vulnerable:
http://secunia.com/vulnerability_scanning/online


Welcome to the forums, ssswrd. :slight_smile:

In addition to the above replies, an analysis of your HJT log shows the following problems.

Platform: Windows XP SP2 (WinNT 5.01.2600)
A newer version of service pack is available. Service packs increase the safety of your system. Visit Microsoft’s windowsupdate site to download the newest version of the service pack.

It seems that you don’t use an anti-virus scanner or your scanner is not active. Only an anti-virus scanner can protect you against new viruses.

We couldn’t detect any active process of a firewall on your system. Possible reasons:
(1.) You are using the windows firewall or a hardware firewall.
(2.) You are using a firewall of an unknown vendor.
(3.) You are using a firewall, but for unknown reasons it is disabled
(4.) You don’t use any firewall at all.
We recommend you to use a firewall. Download and install one or activate windows xp´s own firewall.
A 2-way firewall would be better.

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
This entry should be fixed with HJT.

Overview of running tasks :

smss.exe
System task
Session Manager Subsystem

winlogon.exe
System task
Microsoft Windows Logon Process

services.exe
System task
Windows Service Controller

lsass.exe
System task
Local Security Authority Service

Ati2evxx.exe
Driver
ATI Display Adapter Assistant

svchost.exe
System task
Microsoft Service Host Process

svchost.exe
System task
Microsoft Service Host Process

Ati2evxx.exe
Driver
ATI Display Adapter Assistant

spoolsv.exe
System task
Microsoft Printer Spooler Service

Explorer.EXE
System task
Microsoft Windows Explorer

mDNSResponder.exe
Backgroundtask
Bonjour for Windows Component

EMLPROXY.EXE
Virusscan
EMLPROXY.EXE

jqs.exe
Backgroundtask
Java Quick Starter Service

opssvc.exe
Unknown task ( part of Quick Heal AntiVirus )
Unknown task http://www.tallemu.com/oasis2/file/quick_heal_technologies__pvt__ltd_/quick_heal_antivirus/opssvc_exe/2751436

quhlpsvc.exe
Virusscan
quhlpsvc.exe

EMLPROUI.EXE
Virusscan
EMLPROUI.EXE

SCANMSG.EXE
Virusscan
AntiVirus Quick Heal

RichVideo.exe
Backgroundtask
Cyberlink Power Director Video Module

RichVideo.exe
Backgroundtask
Cyberlink Power Director Video Module

scanwscs.exe
Virusscan
Quick Heal Helper Service

Acrotray.exe
Backgroundtask
Acrobat Traybar Assistant

OnlineNT.EXE
Unknown task ( part of Quick Heal AntiVirus )
Unknown task http://www.tallemu.com/oasis2/file/unspecified_vendor/quick_heal_antivirus/onlinent_exe/834277

jusched.exe
Backgroundtask
Sun Java Update Scheduler

realsched.exe
Application
RealNetworks Scheduler

StatusClient.exe
Backgroundtask
Hewlett-Packard Status Client

OrderReminder.exe
Backgroundtask
OrderReminder

GoogleUpdate.exe
Backgroundtask
GoogleUpdate.exe

GoogleUpdate.exe
Backgroundtask
Google Updater

ctfmon.exe
System task
Alternative User Input Services

uTorrent.exe
Backgroundtask
?Torrent

javaw.exe
Application
Sun Java

acrobat_sl.exe
Backgroundtask
Adobe Acrobat Speed Launcher

webshots.scr
Application
Webshots Desktop Image Downloader

wuauclt.exe
System task
AutoUpdate Client

Scanner.exe http://www.bleepingcomputer.com/startups/Scanner.exe-4759.html
Suspicious task
Retina Scanner Module http://www.backgroundtask.eu/Systeemtaken/Taakinfo.php?ID=5745

HiJackThis.exe
Application
Merijn Hijackthis


I just solved the problem.I removed some unused files using HijackThis and the problem was gone.


If you do not mind, would you please tell us what files you removed?


I removed opssvc and quhlpsvc as they were not there before the Problem.


Thanks for posting back.

Both those files are listed as being a part of Quick Heal anti-virus.


It seems that the Problem has returned again.My Internet Speed is low,performance is high.I found that siszyd32 was causing this.So I removed it with freefixer.But still My Internet Speed is low.

Have you checked your computer for malware?
Did you try the suggestions in reply #1

I have checked with MBAM and SAS.They show my computer is clean.

Hi,

If you need to make sure whether your system has secured, just please follow this instruction for using ComboFix

Here is my Combofix log.

Simple,

Try changing your password.

Maybe a keylogger got your password

I get the message C:\Windows\system32\services.exe is trying to send emails.


You may have match #2 at the link below. Be sure to compare the Hashmark numbers in order to be sure which services.exe is causing your problem.

http://www.pcpitstop.com/libraries/process/i/services.exe.html


I have checked the MD5 Hash of my services.exe with the ones provided in the link match #1.So should I allow it to send mails?