Koozali.org: home of the SME Server

shellxp.exe

Ed Form

shellxp.exe
« on: October 05, 2003, 04:21:09 PM »
Not strictly an SME problem, but I hope someone here knows something at least about the problem outlined below.

I run SME 6 with every update.

I've been getting an odd event at boot time on one of my Windows XP workstations, in which a command line window briefly opens and runs something called shellXP. Then at random, while surfing, a message box pops up on the screen telling me the path of the files representing the current page in my Temporary internet folder [IE6.1], and giving me an OK button to press.

When I investigate the task manager, there is a process running called shellxp.exe and if I terminate this process the pop-up messages cease.

I have completely up-to-date virus protection on all my workstations with EZAntivirus and it doesn't say anything about these events. None of the standard Adware/Malware products raise any objection either.

The only objects to be found on my workstation which are related to this event are a couple of files called shellxp.c, in the temporary internet store, in a sub-folder called after a Dutch website - something like internet-security.nl, but I delated the objects before I noted the name down.

The [rather tenuous] connection with SME is this...

I use a dial-up connection and the modem is shared with a hylafax installation on the SME server. At about the same time as the shellxp events began occurring, I ceased to be able to send or receive faxes, apparently because the modem was connected to my ISP all the time. At first I didn't connect the two things and I reset my connection times to short, which restored the fax system, but I now realise that something to do with this shellxp thing was keeping my internet connection alive, presumably phoning home?????

I clear my IE temp regularly so are these things in the Squid cache????

Anyone have any ideas or experience of such a thing?

I've also sent this message to bugs at mitel, although it seems highly unlikely that it's an SME problem.

Ed Form

Guck Puppy

Re: shellxp.exe
« Reply #1 on: October 05, 2003, 11:28:24 PM »
Sounds very suspicious... how about downloading and running adaware with the latest updates - just in case...

http://www.lavasoft.de/

G

Ed Form

Re: shellxp.exe
« Reply #2 on: October 06, 2003, 04:24:16 AM »
It would help if I gave the correct info! It's shellExp.exe, not shellxp.exe.

A quick search turned up the fact that its the BackExp trojan and 2 minutes work pulled it. I've just sent off a complaint to the EZAntivirus people asking why their product completley failed to stop it.

Sorry for creating noise like this.

Ed Form

Tom Keiser

Re: shellxp.exe
« Reply #3 on: October 06, 2003, 04:57:01 AM »
Before you get too excited about your AV vendor, be aware that most  of them are not doing a very good job with virii.

Have a look at this site, rating RH linux AV products as of 5/2003. This is something of the industry gold-standard for rating AV software:
http://www.virusbtn.com/vb100/archives/tests.xml?200305

Then go to this page, and check the quality of all tested AV products by vendor or by platform.
http://www.virusbtn.com/vb100/about/index.xml

Bottom line is that most of them are truly substandard. There are only two for RH linux that passed the tests; nine failed, and another number weren't even well-known enough to have been tested.

Regards,

Tom