Link to home
Start Free TrialLog in
Avatar of BryanRSmith
BryanRSmith

asked on

Possible Virus undetected by Trend & AVG

I have a client that is running Windows XP Pro and has an executable that shows up in the task manager that appears to have the characteristics of a virus.  The executalbe is in the c:\windows\temp directory and has the same icon (a little dog running) but changes names.  It has been running with the names gh5896.exe, xzf05.exe and ona32e.exe.  The properties of the file say that is was created on 5-16-2006 but the modified date is 7-6-2004.  When I right click on the desktop I get a window that says explorer has encounter a problem and then a Dr. Watson error window opens.  The only way to get back to the desktop is to kill the Dr. Watson process.  I have ran both Trend's Office Scan with the latest updates and AVG Network edition with the latest updates.  Neither one detect a virus on the computer, but I am still suspicious that there is a virus or worm that is placing these executables on the computer.  What should I try next to determine what keeps putting this executable file on the computer and running it?

Thanks
Avatar of rpggamergirl
rpggamergirl
Flag of Australia image

Don't worry they are legit.

Those files c:\windows\temp directory that has a dog icon and changes are legit and they belong to TrendMicro.
They are TrencMicro's watchdog in order to trick the viruses/trojans which wants to disable antivirus.

I think it's pretty clever for TrendMicro to think that way.
ASKER CERTIFIED SOLUTION
Avatar of rpggamergirl
rpggamergirl
Flag of Australia image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of BryanRSmith
BryanRSmith

ASKER

thanks
You're welcome.

I was going to say contact TrendMicro I'm sure they can explain it better than I do.
In order for TrendMicro's watchdog to stay undetected by viruses/trojans it has to behave like one and look like one, hence the random files that changes.