unknown service installed in "temp"

Discussion in 'other security issues & news' started by CreepyKangaroo, Jan 13, 2010.

Thread Status:
Not open for further replies.
  1. CreepyKangaroo

    CreepyKangaroo Registered Member

    Joined:
    Mar 18, 2009
    Posts:
    31
    I'm running XP sp3 nd recently I found a service installed in
    [ C:\Documents and Settings\My Playground\Local Settings\Temp ].
    The name is "BSZVOGHEDKM.EXE" (googled it, no hits!)

    The service is set to manual startup and I never see it running. About the service, winpatrol says "local file not found"...

    Is this a malware related issue? If so, how do I uninstall this service?
     
  2. Keyboard_Commando

    Keyboard_Commando Registered Member

    Joined:
    Mar 6, 2009
    Posts:
    690
  3. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    I would advise the following

    a) Check with services.msc whether is still not running and set to manual when your PC is operational (when still running, check location and upload to virus total or simular multi AV check )

    b) creat a system restore point
    c) download autoruns & hitman Pro & sanity check anti rootkit
    d) disable and remove the file with autoruns
    e) reboot
    f) run Hitman Pro
    g) run sanity check
    h) check whether something suspicious is reported
    i) when everything is normal create another restore point
     
  4. andyman35

    andyman35 Registered Member

    Joined:
    Nov 2, 2007
    Posts:
    2,336
    You aren't running Prevx by any chance are you?
     
Loading...
Thread Status:
Not open for further replies.