Possible Virus undetected by Trend & AVG

Posted on 2006-05-17
Last Modified: 2008-02-01
I have a client that is running Windows XP Pro and has an executable that shows up in the task manager that appears to have the characteristics of a virus.  The executalbe is in the c:\windows\temp directory and has the same icon (a little dog running) but changes names.  It has been running with the names gh5896.exe, xzf05.exe and ona32e.exe.  The properties of the file say that is was created on 5-16-2006 but the modified date is 7-6-2004.  When I right click on the desktop I get a window that says explorer has encounter a problem and then a Dr. Watson error window opens.  The only way to get back to the desktop is to kill the Dr. Watson process.  I have ran both Trend's Office Scan with the latest updates and AVG Network edition with the latest updates.  Neither one detect a virus on the computer, but I am still suspicious that there is a virus or worm that is placing these executables on the computer.  What should I try next to determine what keeps putting this executable file on the computer and running it?

Question by:BryanRSmith
    LVL 47

    Expert Comment

    Don't worry they are legit.

    Those files c:\windows\temp directory that has a dog icon and changes are legit and they belong to TrendMicro.
    They are TrencMicro's watchdog in order to trick the viruses/trojans which wants to disable antivirus.

    I think it's pretty clever for TrendMicro to think that way.
    LVL 47

    Accepted Solution

    Unless I'm wrong of course! :)


    Author Comment

    LVL 47

    Expert Comment

    You're welcome.

    I was going to say contact TrendMicro I'm sure they can explain it better than I do.
    In order for TrendMicro's watchdog to stay undetected by viruses/trojans it has to behave like one and look like one, hence the random files that changes.

    Featured Post

    How to run any project with ease

    Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
    - Combine task lists, docs, spreadsheets, and chat in one
    - View and edit from mobile/offline
    - Cut down on emails

    Join & Write a Comment

    Suggested Solutions

    Cybersecurity has become the buzzword of recent years and years to come. The inventions of cloud infrastructure and the Internet of Things has made us question our online safety. Let us explore how cloud- enabled cybersecurity can help us with our b…
    Transferring data across the virtual world became simpler but protecting it is becoming a real security challenge.  How to approach cyber security  in today's business world!
    Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…
    Here's a very brief overview of the methods PRTG Network Monitor ( offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

    732 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    22 Experts available now in Live!

    Get 1:1 Help Now