SYSTEM process running in the Windows/Temp directory?

  • Thread starter Thread starter Crazy Horse
  • Start date Start date
C

Crazy Horse

1 At every startup a system process is running in the Windows/Tem dir.
2 It has a favicon showing a green running dog, but the filename is
different every time.
3 The filename always consists of 6 upper case chars and digits + .EXE
(NA54GR.EXE)
4 The filesize is normally app. 2720 bytes, but is occasionally smaller.
5. When the process is stopped manually, the file is deleted automatically.

No spyware/trojan/virus scanner report attack.

Anyone seen it before?
 
Do you have Trendmicro OfficeScan? It changes its name every startup so it
cannot be hijacked.

Chris
 
if you do not have the tremdmirco office scan, download superantispyware and
run it and see if it finds anything

robin
 
Thanks, Chris.

Yes, I have Trend Micro Client/Server Security Agent running. I'll look into
it and post back as soon as I can verify if this is the case.

CH
 
Reply from Trend Micro:
......
Yes, it is very likely the watchdog program that is taking care the realtime
scan is not stopped by a malware.

The name of the original file is:
C:\%path to location of Trend Micro OfficeScan Client folder%\OfcDog.exe

.....

Case closed.

Thanks, all.

CH
 
Back
Top