Solved

What is this program? Dog icon, 169k in size, random filenames, c:\windows\temp folder.

Posted on 2006-06-20
6
7,256 Views
Last Modified: 2011-08-18
Hi,

I have noticed on my computer now, every morning i start it up and check windows task manager, i can see a file with a random name .exe. For example toady i have TTA4A7.exe, other days i could have SL8669.exe, AAB4TY.exe, and so on. If i search for the file, it appears in the c:\windows\temp folder, has a dog icon (similar to the one on the old windows 'ski' game, if anyone remembers that!), and is 169k in size.

My computer has not been exhibiting any strange problems. We run Trend Micro OfficeScan which is kept up to date, and a scan is run at 1:30pm every day. I have run windows defender and detected no spyware.

If i end the task and delete the file, it seems to come back after about 20 minutes? Not sure on exact time, but when i come back to use my pc it is there again.

I suspect it could be a part of one of my programs, but i am suspicious because of the file name, and where it is kept.

I have googled this but returned no result.

Has anyone else seen this file? Please help!


Thank you,

Adam
0
Comment
Question by:stdcitunit
  • 3
  • 2
6 Comments
 
LVL 32

Expert Comment

by:r-k
ID: 16946576
That does seem very suspicious. Here is what I suggest:

Download and run HijackThis from http://www.hijackthis.de/
Copy-and-paste the resulting log back to that same web site (not here)
Click on "Analyze", and then click on "Save Analysis" at the bottom of the next page.
Finally post a link here to the saved analyzed page.


In addition to the above, submit the file TTA4A7.exe to this web site:

 http://www.virustotal.com/en/indexf.html

(use the browse button at the top-right of that page, followed by "Send")
They will analyze the file and tell you within a few minutes if it's a known virus.
0
 
LVL 47

Accepted Solution

by:
rpggamergirl earned 500 total points
ID: 16946992
Hi,
Don't worry about the file  in the "c:\windows\temp folder"
That file belongs to TrendMicro, it's their watchdog to evade detection from viruses they have to act like one.
Viruses which turns off antiviruses won't be able to detect TrendMicro's random file in the temp folder.
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 16947009
I'm sure if you contact TrendMicro they will be able to confirm that the random file in the temp folder with the dog icon belongs to their antivirus.
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 
LVL 32

Expert Comment

by:r-k
ID: 16947017
Good catch, rpggamergirl. I wasn't aware trendMicro was doing that!
0
 
LVL 2

Author Comment

by:stdcitunit
ID: 16947137
Thanks rpggamergirl! I have confimed this , it is even the same as the ofcscan file in the trend micro folder.

I was getting a little worried as i have found it on many of the workstations i administer. I feel much relieved!

Thank you again.
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 16947218
No problem stdcitunit,
TrendMicro is wise for creating a file that evade detection from viruses, but they should really let their customers know about their watchdog, and who would not be curious about a random file in the temp folder that changes names? Of course the first thing one would think is malware or viruses/trojans because of the way the file acts and also where it's located.


yes r-k, I've read same cases a few times and 2 users actually contacted TrendMicro and was confirmed that the file belongs to them.
0

Featured Post

Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

Join & Write a Comment

Suggested Solutions

PREFACE The purpose of this guide is to explain how to manually move a SEP client to a different client group by performing steps on the client-side. These steps may prove particularly useful because they allow the client to move after it has alrea…
HOW TO REMOTELY CLEAN MEROND.O WITH ESET SILENTLY PROBLEM       If you have the fortunate luck to contract the Merond.O virus on your network, it can be quite troublesome to remove as it propagates to network shares on your network. In my case, the …
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now