HijackThis - sxe.tmp

Discussion in 'adware, spyware & hijack cleaning' started by vladkernst, Jul 8, 2004.

Thread Status:
Not open for further replies.
  1. vladkernst

    vladkernst Registered Member

    Joined:
    Jul 8, 2004
    Posts:
    1
    I've run Ad-Aware, Spybot, Agent Ransack and have been running AVG Professional 7 to try and remove an "sxe.tmp" virus file installed on my XP Home Edition PC but to no avail. AVG scans, recognises that the sxe.tmp is infected and cleans/removes the files but they reappear each time the PC boots up. AVG classes the files as "Trojan horse BackDoor.Iroffer.V".

    Each time I reboot and log into an account with admin rights Zone Alarm tells me that sxe*.tmp wants to access the internet. The * refers to an ever increasing number or letter which goes up one each time I log in the the admin account, e.g. sxe1.tmp, sxe2.tmp or sxeA.tmp, sxeB.tmp etc.

    However, if I log in to an account on the PC with restricted rights an error message appears saying:

    "Error
    An error has occurred while executing this program. Free up harddrive space and try again."

    Please see my Hijack This log as follows:

    Logfile of HijackThis v1.97.7
    Scan saved at 22:40:40, on 07/07/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\iexplore.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\GSICON.EXE
    C:\WINDOWS\System32\dslagent.exe
    C:\WINDOWS\System32\RUNDLL32.EXE
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\WINDOWS\System32\iexplorer.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\WINDOWS\Mixer.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\QUICKENW\QWDLLS.EXE
    C:\WINDOWS\System32\cmd.exe
    C:\WINDOWS\system32\mui\0009\iexplore.exe
    C:\WINDOWS\system32\mui\0009\sxe3.tmp
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Downloads\Hijack This\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.btyahoo.com/welcome2
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
    O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [QAGENT] C:\QUICKENW\QAGENT.EXE
    O4 - HKLM\..\Run: [EPSON Stylus C44 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C44 Series" /O6 "USB001" /M "Stylus C44"
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O4 - HKLM\..\Run: [Microsoft Update Machine] iexplorer.exe
    O4 - HKLM\..\Run: [Microsoft Kernel32] kernel32.exe
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
    O4 - HKLM\..\RunServices: [Microsoft Update Machine] iexplorer.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [Microsoft Update Machine] iexplorer.exe
    O4 - Startup: Billminder.lnk = ?
    O4 - Startup: Quicken Startup.lnk = ?
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38175.4197222222
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{F39A7670-7432-41B5-86DF-DFD246AB0663}: NameServer = 194.72.9.44 194.74.65.86
     
    Last edited: Jul 8, 2004
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.