nhd
Topic Starter
Please this is frustrating…. I am running McAfee security suite, all updated and correct but the computer keeps trying to send emails that are not mine. I can see this when I go to recent events and check the log. When this happens the computer slows down and acts erratic. I will attach a copy of my hijack this log….
Thank you for understanding this far better than I!
Comparison of your HijackThis log file items to others
The table below compares the items HijackThis found on your computer with those on other people's computers. The column "% of PCs with item" indicates what percent of other people's HijackThis log files contain the item in that row of the table. Additional information will be provided as more HijackThis log files are added to the AnalyzeThis database.
Each entry is coded to indicate the type of item it is on your computer. An explanation of these codes may be found at the bottom of this page.
Index % of PCs with item Code Data
1 0.9% O16 {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - [url="http://upload.facebook.com/controls/FacebookPhotoUploader.cab"]http://upload.facebook.com/controls/Facebo…otoUploader.cab[/url]
2 0.0% O16 {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - [url="http://amiuptodate.mcafee.com/vsc/bin/2,0,0,0/McUpdatePortal.cab"]http://amiuptodate.mcafee.com/vsc/bin/2,0,…pdatePortal.cab[/url]
3 0.0% O16 {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - [url="http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5044/mcfscan.cab"]http://download.mcafee.com/molbin/iss-loc/…044/mcfscan.cab[/url]
4 15.4% O2 (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
5 15.1% O2 Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
6 12.0% O2 (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
7 3.5% O2 DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
8 0.9% O2 scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
9 0.5% O2 (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
10 0.0% O2 Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.8.0\ViewBarBHO.dll (file missing)
11 0.0% O2 Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\WINDOWS\DOWNLO~1\vzbb.dll (file missing)
12 0.0% O2 ATLDistrib Object - {2353FCBC-012D-487B-8BF3-865C0929FBEB} - C:\WINDOWS\system32\pmkhg.dll (file missing)
13 0.0% O20 pmkhg - C:\WINDOWS\system32\pmkhg.dll (file missing)
14 41.5% O22 Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
15 40.1% O22 Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
16 4.8% O23 iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
17 3.9% O23 LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
18 1.7% O23 Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
19 1.5% O23 Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
20 1.4% O23 McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
21 1.4% O23 McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
22 1.3% O23 McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
23 1.3% O23 McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
24 1.3% O23 McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
25 1.3% O23 McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
26 1.2% O23 McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
27 1.2% O23 McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
28 1.2% O23 McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
29 1.2% O23 McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
30 1.1% O23 McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
31 0.9% O23 DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
32 0.8% O23 Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
33 0.7% O23 McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
34 0.6% O23 McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
35 0.6% O23 SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6066\SAService.exe
36 0.5% O23 McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
37 0.4% O23 DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
38 0.0% O23 Print Spooler Service (ca5yoauy8viy) - Unknown owner - C:\WINDOWS\system32\cofcotqpff.exe
39 0.0% O23 AOL Configuration Utility (Int-AOL_ConfSVC) - Unknown owner - C:\WINDOWS\Media\aolconfigs.exe
40 0.6% O3 McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
41 0.0% O3 Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\WINDOWS\DOWNLO~1\vzbb.dll (file missing)
42 0.0% O3 Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\IEViewBar.dll (file missing)
43 46.3% O4 [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
44 20.8% O4 [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
45 11.9% O4 [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
46 11.1% O4 Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
47 10.2% O4 [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
48 10.2% O4 [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
49 4.2% O4 [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
50 4.2% O4 [igfxpers] C:\WINDOWS\system32\igfxpers.exe
51 3.7% O4 [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
52 3.1% O4 [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
53 2.4% O4 [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
54 1.9% O4 [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
55 1.7% O4 [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
56 1.0% O4 [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
57 0.9% O4 QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
58 0.8% O4 [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
59 0.8% O4 Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
60 0.7% O4 [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
61 0.5% O4 [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
62 0.5% O4 [SiteAdvisor] C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
63 0.5% O4 [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
64 0.4% O4 [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
65 0.4% O4 [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
66 0.3% O4 America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
67 0.1% O4 [Motive SmartBridge] C:\PROGRA~1\VERIZON\SMARTB~1\MotiveSB.exe
68 0.1% O4 [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
69 0.1% O4 [VerizonServicepoint.exe] C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
70 0.1% O4 dlbcserv.lnk = C:\Program Files\Dell Photo Printer 720\dlbcserv.exe
71 0.0% O4 [ngaxxuyjppwy] C:\WINDOWS\system32\ngaxxuyjppwy.exe
72 0.0% O4 [tmosnxxki] C:\WINDOWS\system32\tmosnxxki.exe
73 0.0% O4 [yhqvtifvzcum] C:\WINDOWS\system32\yhqvtifvzcum.exe
74 0.0% O4 [agr] C:\WINDOWS\system32\agr.exe
75 0.0% O4 [gnfkj] C:\WINDOWS\system32\gnfkj.exe
76 0.0% O4 [jzfvoefkyttz] C:\WINDOWS\system32\jzfvoefkyttz.exe
77 0.0% O4 [wyu] C:\WINDOWS\system32\wyu.exe
78 0.0% O4 [xndzbyrmxxir] C:\WINDOWS\system32\xndzbyrmxxir.exe
79 0.0% O4 [dpzcedve] C:\WINDOWS\system32\dpzcedve.exe
80 37.2% O9 Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
81 36.7% O9 Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
82 24.9% O9 @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
83 24.9% O9 (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
84 5.8% O9 Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
85 1.2% O9 (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
86 1.1% O9 Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
87 72.2% P01 C:\WINDOWS\Explorer.EXE
88 70.5% P01 C:\WINDOWS\system32\svchost.exe
89 70.5% P01 C:\WINDOWS\system32\lsass.exe
90 70.4% P01 C:\WINDOWS\system32\winlogon.exe
91 70.4% P01 C:\WINDOWS\system32\services.exe
92 70.3% P01 C:\WINDOWS\System32\smss.exe
93 67.7% P01 C:\WINDOWS\system32\spoolsv.exe
94 49.0% P01 C:\WINDOWS\system32\ctfmon.exe
95 28.0% P01 C:\Program Files\Internet Explorer\iexplore.exe
96 13.1% P01 C:\Program Files\QuickTime\qttask.exe
97 10.9% P01 C:\Program Files\iPod\bin\iPodService.exe
98 10.3% P01 C:\Program Files\iTunes\iTunesHelper.exe
99 9.4% P01 C:\WINDOWS\System32\hkcmd.exe
100 5.0% P01 C:\WINDOWS\system32\igfxpers.exe
101 4.0% P01 C:\WINDOWS\system32\LEXBCES.EXE
102 3.7% P01 C:\WINDOWS\system32\lexpps.exe
103 3.3% P01 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
104 3.1% P01 C:\WINDOWS\system32\dla\tfswctrl.exe
105 2.2% P01 C:\PROGRA~1\mcafee.com\agent\mcagent.exe
106 1.9% P01 C:\Program Files\Analog Devices\Core\smax4pnp.exe
107 1.8% P01 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
108 1.7% P01 C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
109 1.6% P01 C:\Program Files\Viewpoint\Common\ViewpointService.exe
110 1.3% P01 C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
111 1.3% P01 C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
112 1.3% P01 C:\Program Files\Real\RealPlayer\RealPlay.exe
113 1.3% P01 C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
114 1.2% P01 C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
115 1.2% P01 c:\program files\common files\mcafee\mna\mcnasvc.exe
116 1.2% P01 C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
117 1.2% P01 C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
118 1.1% P01 c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
119 1.1% P01 C:\Program Files\McAfee\MPF\MPFSrv.exe
120 0.9% P01 C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
121 0.8% P01 C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
122 0.8% P01 C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
123 0.7% P01 C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
124 0.7% P01 C:\Program Files\McAfee\MPS\mpsevh.exe
125 0.7% P01 C:\Program Files\DellSupport\DSAgnt.exe
126 0.6% P01 C:\PROGRA~1\McAfee\MPS\mps.exe
127 0.6% P01 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
128 0.6% P01 C:\Program Files\SiteAdvisor\6066\SAService.exe
129 0.5% P01 C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
130 0.5% P01 C:\Program Files\McAfee\MSK\MskAgent.exe
131 0.5% P01 C:\Program Files\Common Files\Command Software\dvpapi.exe
132 0.5% P01 C:\Program Files\McAfee\MSK\MskSrver.exe
133 0.4% P01 C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
134 0.3% P01 C:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
135 0.3% P01 C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
136 0.1% P01 C:\PROGRA~1\VERIZON\SMARTB~1\MotiveSB.exe
137 0.1% P01 C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
138 0.1% P01 C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
139 0.0% P01 C:\WINDOWS\Media\aolconfigs.exe
140 0.0% P01 C:\WINDOWS\system32\tmosnxxki.exe
141 0.0% P01 C:\Documents and Settings\Nancy\Local Settings\Temporary Internet Files\Content.IE5\NDZYT3L3\startuplist[1]\StartupList.exe
142 0.0% P01 C:\Documents and Settings\Nancy\Local Settings\Temporary Internet Files\Content.IE5\VL7PX27S\HiJackThis_v2[1].exe
143 23.1% R0 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [url="http://go.microsoft.com/fwlink/?LinkId=69157"]http://go.microsoft.com/fwlink/?LinkId=69157[/url]
144 6.9% R0 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
145 27.0% R1 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [url="http://go.microsoft.com/fwlink/?LinkId=54896"]http://go.microsoft.com/fwlink/?LinkId=54896[/url]
146 25.9% R1 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [url="http://go.microsoft.com/fwlink/?LinkId=54896"]http://go.microsoft.com/fwlink/?LinkId=54896[/url]
147 25.1% R1 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url="http://go.microsoft.com/fwlink/?LinkId=69157"]http://go.microsoft.com/fwlink/?LinkId=69157[/url]
148 0.8% R1 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url="http://www.dell4me.com/myway"]http://www.dell4me.com/myway[/url]
149 0.1% R1 HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url="http://bfc.myway.com/search/de_srchlft.html"]http://bfc.myway.com/search/de_srchlft.html[/url]
150 0.1% R3 (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
Explanation of the codes
R - Registry, StartPage/SearchPage changes
R0 - Changed registry value
R1 - Created registry value
R2 - Created registry key
R3 - Created extra registry value where only one should be
F - IniFiles, autoloading entries
F0 - Changed inifile value
F1 - Created inifile value
F2 - Changed inifile value, mapped to Registry
F3 - Created inifile value, mapped to Registry
N - Netscape/Mozilla StartPage/SearchPage changes
N1 - Change in prefs.js of Netscape 4.x
N2 - Change in prefs.js of Netscape 6
N3 - Change in prefs.js of Netscape 7
N4 - Change in prefs.js of Mozilla
O - Other, several sections which represent:
O1 - Hijack of auto.search.msn.com with Hosts file
O2 - Enumeration of existing MSIE BHO's
O3 - Enumeration of existing MSIE toolbars
O4 - Enumeration of suspicious autoloading Registry entries
O5 - Blocking of loading Internet Options in Control Panel
O6 - Disabling of 'Internet Options' Main tab with Policies
O7 - Disabling of Regedit with Policies
O8 - Extra MSIE context menu items
O9 - Extra 'Tools' menuitems and buttons
O10 - Breaking of Internet access by New.Net or WebHancer
O11 - Extra options in MSIE 'Advanced' settings tab
O12 - MSIE plugins for file extensions or MIME types
O13 - Hijack of default URL prefixes
O14 - Changing of IERESET.INF
O15 - Trusted Zone Autoadd
O16 - Download Program Files item
O17 - Domain hijack
O18 - Enumeration of existing protocols and filters
O19 - User stylesheet hijack
O20 - AppInit_DLLs autorun Registry value, Winlogon Notify Registry keys
O21 - ShellServiceObjectDelayLoad (SSODL) autorun Registry key
O22 - SharedTaskScheduler autorun Registry key
O23 - Enumeration of NT Services
O24 - Enumeration of ActiveX Desktop Components
Thank you for understanding this far better than I!