Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

What is this program? Dog icon, 169k in size, random filenames, c:\windows\temp folder.

Posted on 2006-06-20
6
Medium Priority
?
7,370 Views
Last Modified: 2011-08-18
Hi,

I have noticed on my computer now, every morning i start it up and check windows task manager, i can see a file with a random name .exe. For example toady i have TTA4A7.exe, other days i could have SL8669.exe, AAB4TY.exe, and so on. If i search for the file, it appears in the c:\windows\temp folder, has a dog icon (similar to the one on the old windows 'ski' game, if anyone remembers that!), and is 169k in size.

My computer has not been exhibiting any strange problems. We run Trend Micro OfficeScan which is kept up to date, and a scan is run at 1:30pm every day. I have run windows defender and detected no spyware.

If i end the task and delete the file, it seems to come back after about 20 minutes? Not sure on exact time, but when i come back to use my pc it is there again.

I suspect it could be a part of one of my programs, but i am suspicious because of the file name, and where it is kept.

I have googled this but returned no result.

Has anyone else seen this file? Please help!


Thank you,

Adam
0
Comment
Question by:stdcitunit
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
6 Comments
 
LVL 32

Expert Comment

by:r-k
ID: 16946576
That does seem very suspicious. Here is what I suggest:

Download and run HijackThis from http://www.hijackthis.de/
Copy-and-paste the resulting log back to that same web site (not here)
Click on "Analyze", and then click on "Save Analysis" at the bottom of the next page.
Finally post a link here to the saved analyzed page.


In addition to the above, submit the file TTA4A7.exe to this web site:

 http://www.virustotal.com/en/indexf.html

(use the browse button at the top-right of that page, followed by "Send")
They will analyze the file and tell you within a few minutes if it's a known virus.
0
 
LVL 47

Accepted Solution

by:
rpggamergirl earned 2000 total points
ID: 16946992
Hi,
Don't worry about the file  in the "c:\windows\temp folder"
That file belongs to TrendMicro, it's their watchdog to evade detection from viruses they have to act like one.
Viruses which turns off antiviruses won't be able to detect TrendMicro's random file in the temp folder.
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 16947009
I'm sure if you contact TrendMicro they will be able to confirm that the random file in the temp folder with the dog icon belongs to their antivirus.
0
2017 Webroot Threat Report

MSPs: Get the facts you need to protect your clients.
The 2017 Webroot Threat Report provides a uniquely insightful global view into the analysis and discoveries made by the Webroot® Threat Intelligence Platform to provide insights on key trends and risks as seen by our users.

 
LVL 32

Expert Comment

by:r-k
ID: 16947017
Good catch, rpggamergirl. I wasn't aware trendMicro was doing that!
0
 
LVL 2

Author Comment

by:stdcitunit
ID: 16947137
Thanks rpggamergirl! I have confimed this , it is even the same as the ofcscan file in the trend micro folder.

I was getting a little worried as i have found it on many of the workstations i administer. I feel much relieved!

Thank you again.
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 16947218
No problem stdcitunit,
TrendMicro is wise for creating a file that evade detection from viruses, but they should really let their customers know about their watchdog, and who would not be curious about a random file in the temp folder that changes names? Of course the first thing one would think is malware or viruses/trojans because of the way the file acts and also where it's located.


yes r-k, I've read same cases a few times and 2 users actually contacted TrendMicro and was confirmed that the file belongs to them.
0

Featured Post

Looking for the Wi-Fi vendor that's right for you?

We know how difficult it can be to evaluate Wi-Fi vendors, so we created this helpful Wi-Fi Buyer's Guide to help you find the Wi-Fi vendor that's right for your business! Download the guide and get started on our checklist today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Change your password...do it now!. Probably the easiest point of access to your account is through guessing your password. If your password is guessable, do change it now. If not for your sake but for everyone else in your friends list. Remember …
Ransomware continues to be a growing problem for both personal and business users alike and Antivirus companies are still struggling to find a reliable way to protect you from this dangerous threat.
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

670 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question