What is this program running on my PC ?

spideyontheweb

Junior Member
Aug 24, 2011
23
0
66
Hi

I was checking the Services tab on my Task Manager and I find this program (zdfchhpxzuugca) which I cannot stop even with administrator control. Its the first program in the image.

Its a Dell 501x laptop (64bit) with windows 10 and Kaspersky. I have never seen this in the past.

Can anyone help me find out what it is and how to disable it.

Many Thanks

[/IMG]
 

pcgeek11

Lifer
Jun 12, 2005
21,514
4,608
136
Malwarebytes
Bitdefender

Run these and allow them to clean whatever they find.
 

Seba

Golden Member
Sep 17, 2000
1,497
144
106
Search your computer and also the Registry for that string and see what comes up.
 

spideyontheweb

Junior Member
Aug 24, 2011
23
0
66
Search your computer and also the Registry for that string and see what comes up.

Thanks. Nothing on search. But regedit search gives this info !
Location is in SysWOW64 and properties says it is a Sver file - kepfzqq
What do I do next?
[/IMG]
 
Last edited:

Seba

Golden Member
Sep 17, 2000
1,497
144
106
Now look at the properties of that file kepfzqq.exe, located in C: \Windows\SysWOW64 to see what info can you gather. Maybe you can identify some program that you installed. If not, it could be some unwanted program.
 

spideyontheweb

Junior Member
Aug 24, 2011
23
0
66
Now look at the properties of that file kepfzqq.exe, located in C: \Windows\SysWOW64 to see what info can you gather. Maybe you can identify some program that you installed. If not, it could be some unwanted program.

The original location of the file is kepfzqq.exe and properties says its a Sver file. I cannot open the file or get anything else or even disable it.Strange :thumbsdown:
 

sbpromania

Senior member
Mar 3, 2015
265
1
16
www.sbp-romania.com
It's highly likeable that it is a 3rd party program, that was installed in the background of another installation process ( this happens a lot for software downloaded from free websites).

The best course of action you can take is to make a backup of your registry and delete all the entries of the specified program. If it breaks something on your computer u have the backup. Also delete all the cache from your browsers
 

Majorrabbid

Junior Member
Dec 6, 2015
1
0
66
Crypto locker? Or a variant? Do you have any files that you cannot open or come up saying corrupt?
 

redzo

Senior member
Nov 21, 2007
547
5
81
Malwarebytes
Bitdefender

Run these and allow them to clean whatever they find.

This.

Run a full scan using malwarebytes! If it's spyware or a virus, MB will certainly detect it.
It could be anything from a bitcoin miner or crypto virus to some harmless crapware.
 
Last edited:

LPCTech

Senior member
Dec 11, 2013
680
93
86
run in this order:

rkill
jrt
Malwarebytes
adwcleaner

Thats not normal. You have malware. Malware commonly has gibberish names like that. If this fails run combofix and hope for the best, back up all your files before doing any of this.
 

xgsound

Golden Member
Jan 22, 2002
1,374
8
81
If you have the nerve you can stop the service as follows after you see what info is available on it.
To get info you can run services program. Go search/ type services/ click on services/ go to zdfchhpxzuugca and single left click. You should get info on the service shown on the left and options to stop start and so on. A right click lets you look at properties. If computer works after you stop or disable it, the next step is to delete the registry item.
Jim
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |