While looking into another problem, I found what appear to be bogus services listed. I found two services, XGGZVB and NRNTYDQZSLNU. They both showed a path to the windows temp folder. They were both stopped, but I disabled them and unchecked the 'allow service to interact with desktop' anyway. I find Registry Keys for them in several places under HKLM. I find them under HKLM/System/Controlset001(controlset003 and CurrentControSet)/Enum/ /Services and /Root I feel I can remove all these regestry entries to insure the services don't function - whatever there function might be. I couldn't find the files in the temp folder so I couldn't remove them. Is my solution valid is the first question. Anyone run in to this before? And how do you prevent it happening again?
Oh I'm running XP home SP2 , IE7, ZoneAlarm firewall, AVG antivirus, SPYBOT S&D, Adaware. I've recently run HJT, Panda free scan, and Pest Patrol free. All up to date and no problems found.
Thanks,
Pete.
Where were these listed? How long have they been there? Are you having problems?
Assuming all your security applications are kept up to date, and you practice safe computing - that is, you keep your system patched, updated, scanned, and blocked (and it looks like you do) then I would not be too concerned. Those could have been installed during an install of one of your other programs. The fact they point to a temp folder bares that out.
I think you have an adequate arsenal of anti-malware tools. You might try running CCleaner , a great disk cleaning program that is excellent at cleaning the system of 1000s of temporary files, including all history, old logs, and cache files. During installation, uncheck the option to install the Yahoo toolbar. Before first use, go to Options > Settings > Advanced and ensure Only delete files in Windows Temp folders older than 48 hours is unchecked. To delete all "tracking" cookies, (which I urge you do), you must delete all cookies, so ensure the Cookies setting remains checked. Ensure you know your site credentials (user name and password) for sites you frequent; you will have to login again at next visit. [TIP: Run CC before manual malware scans and defragging - no need to scan 1000s of temporary files!]
Note that CCleaner's "Issues" checker is a great Registry cleaner as well. As with any Registry change, ensure you follow the prompts to backup the Registry before making changes to it. It is often necessary to scan for issues 2 or 3 times until it reports, "No issues were found".
Thanks for the reply.
I use a product called Cleanup 4.0 to get rid of all temp junk. And yes, everything is as up to date as I can keep it.
I was digging into another problem relating to site hi-jacking and just checking for any potential culprits when I found the bogus entries. They show up in the list of services when you issue a services.msc command from Run, (other ways to list them but this is the quickest). You can see by the names, they stand out as potentially bogus. I really didn't notice them before so they could have been there for a while.
I've keep my cookies clean and only allow new cookies sparingly. However I'll check out CCleaner. I don't mind trying for better software.
CCleaner, under Tools, has a section called Startup. You can see and control there what is being started at start up (similar to MSCONFIG and other programs).
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI