xseacc.xse and xsecva folder?

Discussion in 'Malware Help (A Specialist Will Reply)' started by punchup, Jul 29, 2012.

  1. punchup

    punchup Private E-2

    hello there,

    yesterday afternoon, i saw xsecva.exe in my task manager and it took up 100% of my cpu. there was also a pop up message which was about something like the cookie cannot be deleted... coz window system.. ?? (sorry, i cannot recall the exact lines). it was weird message so, i closed it; i did not click ok button. i do not know how xsecva happened as i was away from my pc for a few mins to eat ice-cream. there was no video or downloading activity on my pc.

    anyway, i ran Malwarebytes Anti-Malware which found many malicious items and then cleaned them out.

    1. C:\Documents and Settings\user\Application Data\xsecva\xsecva.exe (Trojan.Agent) -> Quarantined and deleted successfully.
    2. C:\Documents and Settings\user\Application Data\nmrliz.dll (Trojan.Midhos) -> Quarantined and deleted successfully.
    3. C:\Documents and Settings\user\Local Settings\Temp\censxrwoam.exe (Trojan.Agent.BVXGen) -> Quarantined and deleted successfully.
    4. C:\WINDOWS\assembly\GAC\Desktop.ini (Trojan.0access) -> Delete on reboot.
    5. the rest - Registry Values and Registry Keys

    the reboot was ok and i did not see anything funny in my task manager.

    i checked my application data folder and to my horror, there is a xsecva folder which has xseacc.xse(1.15kb) inside.

    i am thinking to delete them but i do not know whether it is proper way... can you please advise me what to do? and what is xsecva and xseacc.xse? can they affect the files on my pc? more importantly, is my cookies(storing login details) compromised? i went to my local forum(i am auto logged in) to post my problem. I did not visit the rest of the sites to play it safe.
    also, i did not register here on that affected pc. i do not know whether it is really alright to log in to the site/s on that pc so i am unable to provide you with my logs of RogueKiller, Malwarebytes Anti-Malware, HitmanPro and MGtools. please let me know if it is alright or not to do that.
    i would like to know whether RogueKiller, HitmanPro and MGtools require any disk space as i have low disk space - currently 100mb. :-o i think i might have no (earlier) system restore point due to that.

    oh yeah, i googled for xsecva here and found 2 similar links to my problem.
    1. http://forums.majorgeeks.com/showthread.php?t=261989 - The Avenger by Swandog469/OTM by Old Timer (post #8 and #11)
    2. http://forums.majorgeeks.com/showthread.php?t=262364 - delete manually (post #6)

    i do not dare follow 1. as i never do the cleaning procedures before; i only used Malwarebytes Anti-Malware.
    i wonder why The Avenger by Swandog469/OTM by Old Timer was not mentioned in 2. -> according to Kestrel13!, "Does this folder still exist? If so are you able to delete it, reboot and then see if it is still gone?"

    :confused so, can i just delete xsecva folder, using the "delete" option in windows explorer?

    i checked that pc for similar file name - xsecva, censxrwoam and etc and got the results - prefetch files.

    1. XSECVA.exe-00A4AFB8.pf 12kb
    2. CENSXRWOAM.exe - 1BBAEB97.pf 7kb
    3.MSHTA.exe - 331DF029.pf 40kb
    in C:\Windows\Prefetch

    are they dangerous? i checked online and found out that pf files are harmless. so, do i just leave them alone?

    ah, about mshta.exe, i checked my norton's log and saw the suspicious events which caused xsecva problem. mshta.exe -> censxrwoam.exe -> xsecva.exe in order ( occured every few mins)

    i checked my internet history for that affected time of the sites i went to. i did not find anything wrong.. they are regular forums/sites/google i go. :confused

    that's all.

    many many thanks and my deepest apologies for not following this forum requirement before posting.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  3. punchup

    punchup Private E-2

    hi Kestrel13!,

    you seem like you never read my post? please read it below and answer my questions. :-o



    should i back up my files first before doing the cleaning procedures? i do not know whether RogueKiller, HitmanPro and MGtools will affect anything or my files?
    my pc's usb ports are not working properly so, please feel free to tell me whether it is really necessary to back up my files ( it might take long.. but will a longer delay be dangerous for pc? )..

    more info on my pc, i am on XP, 32 bit... my pc is old and its cd-rom is spoilt.

    thanks again!
     
    Last edited by a moderator: Jul 29, 2012
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes back up if you really want to but I would say it is not necessary.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds