Solved

What is this program? Dog icon, 169k in size, random filenames, c:\windows\temp folder.

Posted on 2006-06-20
6
7,279 Views
Last Modified: 2011-08-18
Hi,

I have noticed on my computer now, every morning i start it up and check windows task manager, i can see a file with a random name .exe. For example toady i have TTA4A7.exe, other days i could have SL8669.exe, AAB4TY.exe, and so on. If i search for the file, it appears in the c:\windows\temp folder, has a dog icon (similar to the one on the old windows 'ski' game, if anyone remembers that!), and is 169k in size.

My computer has not been exhibiting any strange problems. We run Trend Micro OfficeScan which is kept up to date, and a scan is run at 1:30pm every day. I have run windows defender and detected no spyware.

If i end the task and delete the file, it seems to come back after about 20 minutes? Not sure on exact time, but when i come back to use my pc it is there again.

I suspect it could be a part of one of my programs, but i am suspicious because of the file name, and where it is kept.

I have googled this but returned no result.

Has anyone else seen this file? Please help!


Thank you,

Adam
0
Comment
Question by:stdcitunit
  • 3
  • 2
6 Comments
 
LVL 32

Expert Comment

by:r-k
ID: 16946576
That does seem very suspicious. Here is what I suggest:

Download and run HijackThis from http://www.hijackthis.de/
Copy-and-paste the resulting log back to that same web site (not here)
Click on "Analyze", and then click on "Save Analysis" at the bottom of the next page.
Finally post a link here to the saved analyzed page.


In addition to the above, submit the file TTA4A7.exe to this web site:

 http://www.virustotal.com/en/indexf.html

(use the browse button at the top-right of that page, followed by "Send")
They will analyze the file and tell you within a few minutes if it's a known virus.
0
 
LVL 47

Accepted Solution

by:
rpggamergirl earned 500 total points
ID: 16946992
Hi,
Don't worry about the file  in the "c:\windows\temp folder"
That file belongs to TrendMicro, it's their watchdog to evade detection from viruses they have to act like one.
Viruses which turns off antiviruses won't be able to detect TrendMicro's random file in the temp folder.
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 16947009
I'm sure if you contact TrendMicro they will be able to confirm that the random file in the temp folder with the dog icon belongs to their antivirus.
0
Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

 
LVL 32

Expert Comment

by:r-k
ID: 16947017
Good catch, rpggamergirl. I wasn't aware trendMicro was doing that!
0
 
LVL 2

Author Comment

by:stdcitunit
ID: 16947137
Thanks rpggamergirl! I have confimed this , it is even the same as the ofcscan file in the trend micro folder.

I was getting a little worried as i have found it on many of the workstations i administer. I feel much relieved!

Thank you again.
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 16947218
No problem stdcitunit,
TrendMicro is wise for creating a file that evade detection from viruses, but they should really let their customers know about their watchdog, and who would not be curious about a random file in the temp folder that changes names? Of course the first thing one would think is malware or viruses/trojans because of the way the file acts and also where it's located.


yes r-k, I've read same cases a few times and 2 users actually contacted TrendMicro and was confirmed that the file belongs to them.
0

Featured Post

ScreenConnect 6.0 Free Trial

Check out the updates in one game-changing release, ScreenConnect 6.0, based on partner feedback. New features include a redesigned UI that improves session organization and overall user experience. See the enhancements for yourself!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

For those of you actively in the Malware fightling business, we now have available an amazing new tool in the malware wars (first recommended to me by rpggamergirl (http://www.experts-exchange.com/M_3598771.html), the Zone Advisor for the Virus and …
By the time you finish reading this article, you may have already lost all your money because you don't know the simple steps to securing your BitCoin wallet. BitCoin is an incredible invention. It is a decentralized currency system, which is the…
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question