10-06-2012 05:00 AM
One of my system been playing up last couple of days. Several Firefox crashes but with no obvious reason. Started looking around and came across this service in the Standard group:
Service Name: ZXOTMPA
Display Name: ZXOTMPA
Path to EXE: C:\Users\Martyn\AppData\Local\Temp\ZXOTMPA.exe
Logging on as the local system account and interacting with the desktop.
Type (from registry) 110 Hex (272 Dec)
Also found a second service, again in the Standard group
May not be the cause of my Firefox issues but either way guessing that these services should not be there. Google search revealed nothing!
Any comments, hints or tips on what to do next greatly appreciated.
Solved! Go to Solution.
10-06-2012 10:11 AM - edited 10-06-2012 11:09 AM
Do you use RootkitRevealer? Each time you run RootkitRevealer it creates a randomly named copy of itself that runs as a Windows service. It does this because rootkits are able to avoid detection by tricking RootkitRevealer if they recognize it running. Your services look like the sorts of names that RootkitRevealer creates for itself.
10-11-2012 02:20 AM
Sorry been away. Yes you are correct. I have used the RootKItRevealer and can confirm your hypothesis.
Thanks for the heads -up.