Solved

What is this program? Dog icon, 169k in size, random filenames, c:\windows\temp folder.

Posted on 2006-06-20
6
7,309 Views
Last Modified: 2011-08-18
Hi,

I have noticed on my computer now, every morning i start it up and check windows task manager, i can see a file with a random name .exe. For example toady i have TTA4A7.exe, other days i could have SL8669.exe, AAB4TY.exe, and so on. If i search for the file, it appears in the c:\windows\temp folder, has a dog icon (similar to the one on the old windows 'ski' game, if anyone remembers that!), and is 169k in size.

My computer has not been exhibiting any strange problems. We run Trend Micro OfficeScan which is kept up to date, and a scan is run at 1:30pm every day. I have run windows defender and detected no spyware.

If i end the task and delete the file, it seems to come back after about 20 minutes? Not sure on exact time, but when i come back to use my pc it is there again.

I suspect it could be a part of one of my programs, but i am suspicious because of the file name, and where it is kept.

I have googled this but returned no result.

Has anyone else seen this file? Please help!


Thank you,

Adam
0
Comment
Question by:stdcitunit
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
6 Comments
 
LVL 32

Expert Comment

by:r-k
ID: 16946576
That does seem very suspicious. Here is what I suggest:

Download and run HijackThis from http://www.hijackthis.de/
Copy-and-paste the resulting log back to that same web site (not here)
Click on "Analyze", and then click on "Save Analysis" at the bottom of the next page.
Finally post a link here to the saved analyzed page.


In addition to the above, submit the file TTA4A7.exe to this web site:

 http://www.virustotal.com/en/indexf.html

(use the browse button at the top-right of that page, followed by "Send")
They will analyze the file and tell you within a few minutes if it's a known virus.
0
 
LVL 47

Accepted Solution

by:
rpggamergirl earned 500 total points
ID: 16946992
Hi,
Don't worry about the file  in the "c:\windows\temp folder"
That file belongs to TrendMicro, it's their watchdog to evade detection from viruses they have to act like one.
Viruses which turns off antiviruses won't be able to detect TrendMicro's random file in the temp folder.
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 16947009
I'm sure if you contact TrendMicro they will be able to confirm that the random file in the temp folder with the dog icon belongs to their antivirus.
0
PeopleSoft Has Never Been Easier

PeopleSoft Adoption Made Smooth & Simple!

On-The-Job Training Is made Intuitive & Easy With WalkMe's On-Screen Guidance Tool.  Claim Your Free WalkMe Account Now

 
LVL 32

Expert Comment

by:r-k
ID: 16947017
Good catch, rpggamergirl. I wasn't aware trendMicro was doing that!
0
 
LVL 2

Author Comment

by:stdcitunit
ID: 16947137
Thanks rpggamergirl! I have confimed this , it is even the same as the ofcscan file in the trend micro folder.

I was getting a little worried as i have found it on many of the workstations i administer. I feel much relieved!

Thank you again.
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 16947218
No problem stdcitunit,
TrendMicro is wise for creating a file that evade detection from viruses, but they should really let their customers know about their watchdog, and who would not be curious about a random file in the temp folder that changes names? Of course the first thing one would think is malware or viruses/trojans because of the way the file acts and also where it's located.


yes r-k, I've read same cases a few times and 2 users actually contacted TrendMicro and was confirmed that the file belongs to them.
0

Featured Post

2017 Webroot Threat Report

MSPs: Get the facts you need to protect your clients.
The 2017 Webroot Threat Report provides a uniquely insightful global view into the analysis and discoveries made by the Webroot® Threat Intelligence Platform to provide insights on key trends and risks as seen by our users.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

12 Steps to a more secure Internet experience (http://tekblog.teksquisite.com/) Everyone who is a licensed driver initially had to pass a driving test that consisted of taking:    1. a written test    2. a road test    3. a vision test Le…
PREFACE The purpose of this guide is to explain what the SEPC Status Utility is and how it works. I have written the utility using AutoIt and have included the source code for your review. You are welcome to modify the code to your liking, but I wi…
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question