Virus Alert – GOOGLE.EXE

A file called google.exe found in your Windows\System or System32 folder may be trying to fool you into thinking that it has to do with the popular Google Search Engine. In reality, it installs with the W32/Rbot-AMW worm. This worm exploits the WKS, PNP and ASN.1 vulnerabilities, it sets itself to run on system startup, and it can allow a remote user to access your system. This user could download, install, run or delete files. You'll find more information at http://www.sophos.com/virusinfo/analyses/w32rbotamw.html.

We'd recommend removing this file using WinPatrol. First, kill it under Active Tasks then remove it from your Startup Programs. If running WinPatrol 8.x or later, right click the file then select "Delete file on Reboot". Finally, reboot your system.

  • Virus
  • Remove