10-06-2012 05:00 AM
Hello
One of my system been playing up last couple of days. Several Firefox crashes but with no obvious reason. Started looking around and came across this service in the Standard group:
Service Name: ZXOTMPA
Display Name: ZXOTMPA
Description:
Path to EXE: C:\Users\Martyn\AppData\Local\Temp\ZXOTMPA.exe
Startup: Manual
Status: Stopped
Logging on as the local system account and interacting with the desktop.
Type (from registry) 110 Hex (272 Dec)
Also found a second service, again in the Standard group
GWXJTLQQJO
May not be the cause of my Firefox issues but either way guessing that these services should not be there. Google search revealed nothing!
Any comments, hints or tips on what to do next greatly appreciated.
Cheers
Martyn
Solved! Go to Solution.
10-06-2012 10:11 AM - edited 10-06-2012 11:09 AM
Hi Bandolier,
Do you use RootkitRevealer? Each time you run RootkitRevealer it creates a randomly named copy of itself that runs as a Windows service. It does this because rootkits are able to avoid detection by tricking RootkitRevealer if they recognize it running. Your services look like the sorts of names that RootkitRevealer creates for itself.
10-11-2012 02:20 AM
Hi SendofJive
Sorry been away. Yes you are correct. I have used the RootKItRevealer and can confirm your hypothesis.
Thanks for the heads -up.
Cheers
Martyn
10-11-2012 01:13 PM
You're welcome. Yeah, I've seen so many of these on my PC, I can spot 'em a mile away - I was 99% sure that had to be your issue.
