• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1204
  • Last Modified:

Possible Virus undetected by Trend & AVG

I have a client that is running Windows XP Pro and has an executable that shows up in the task manager that appears to have the characteristics of a virus.  The executalbe is in the c:\windows\temp directory and has the same icon (a little dog running) but changes names.  It has been running with the names gh5896.exe, xzf05.exe and ona32e.exe.  The properties of the file say that is was created on 5-16-2006 but the modified date is 7-6-2004.  When I right click on the desktop I get a window that says explorer has encounter a problem and then a Dr. Watson error window opens.  The only way to get back to the desktop is to kill the Dr. Watson process.  I have ran both Trend's Office Scan with the latest updates and AVG Network edition with the latest updates.  Neither one detect a virus on the computer, but I am still suspicious that there is a virus or worm that is placing these executables on the computer.  What should I try next to determine what keeps putting this executable file on the computer and running it?

  • 3
1 Solution
Don't worry they are legit.

Those files c:\windows\temp directory that has a dog icon and changes are legit and they belong to TrendMicro.
They are TrencMicro's watchdog in order to trick the viruses/trojans which wants to disable antivirus.

I think it's pretty clever for TrendMicro to think that way.
Unless I'm wrong of course! :)

BryanRSmithAuthor Commented:
You're welcome.

I was going to say contact TrendMicro I'm sure they can explain it better than I do.
In order for TrendMicro's watchdog to stay undetected by viruses/trojans it has to behave like one and look like one, hence the random files that changes.
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

How do you know if your security is working?

Protecting your business doesn’t have to mean sifting through endless alerts and notifications. With WatchGuard Total Security Suite, you can feel confident that your business is secure, meaning you can get back to the things that have been sitting on your to-do list.

  • 3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now