Detection found in installation exe file

Problem #1:
I recently had a recurring popup suggesting that AVG had discovered spyware in taskeng exe and windows has a partial explanation:

taskeng.exe is a legitimate Windows Task Scheduler Engine process, but malware can disguise itself using this name. Random black box pop-ups usually stem from a broken or malicious scheduled task rather than a virus itself, though trojans can occasionally mimic the file

All scans using AVG show no results.

Problem #2:
While looking for that, I found another online scanner that discovered a potentially unwanted program embedded in the AVG installation software itself:

If MalwareBytes AntiMalware says your system is clean, you’re probably OK. If you want another opinion, run the free ESET online virus scanner: https://www.eset.com/us/home/online-scanner/

C:\Users\…\Downloads\avg_secure_browser_setup.exe a variant of Win32/Avast.AVGSecureBrowser. A potentially unwanted application, a variant of Win32/CCleaner. A potentially unsafe application cleaned by deleting

Don’t be confused.. I am not using MalwareBytes.

Problem #3:
As this was an installation program, and that software removed it, I felt a “repair” option might be in order, so I ran that. It failed saying the server was experiencing temporary difficulties or my online connection had been lost. (Well, I’m online now, so draw your own conclusions about that one).

Problem #4:
I then ran another install from this website to overwrite the whole damned thing, hoping that might solve this entire list of issues in one fell swoop. Guess again.

I won’t worry about it, but maybe you want to see if you can duplicate any of these issues yourself, AVG..
Bon Chance!

Perhaps its a PICNIC issue? Problem in chair, not in computer.

That sounds like quite the troubleshooting adventure! I would not immediately assume it is a PICNIC issue, though. You have already done a pretty thorough job of checking different possibilities.

The taskeng.exe warning is worth investigating since it is a legitimate Windows process that can also be impersonated by malware but a clean result from AVG does not necessarily mean there is nothing to investigate. As for the AVG Secure Browser installer being flagged as a potentially unwanted application, that could be related to bundled software rather than an actual infection.

At this point, I would probably let Malwarebytes or another reputable second-opinion scanner check the system and avoid repeatedly reinstalling AVG until you know what’s actually triggering the alerts. Hopefully AVG can reproduce the issue on their end!

1 Like

It may not be taskeng at all, but the Process that called it (the PID), which is identified by number inside the [braces] following the name of the executable trapped by AVG as acting in an odd way…. it’s not very well described in most help files…

We’ve secured taskeng.exe [18156]
We’ve secured taskeng.exe [5984]
Detected by Anti-Exploit Shield
Origin: C:\Windows\system32\taskeng.exe

Spyware: Detected by Anti-Exploit Shield
Win32:Malware-gen is a generic detection label used by antivirus programs meaning your software found a file behaving suspiciously, but it does not match an exact, named virus signature. It could be real spyware, a trojan, or a false positive on a safe file.

I did that with a couple of other virus detection software programs, and one reported 12 items that need my attention.. AVG free found none of them.

There is another website that suggested a third party that runs multiple top virus detectors on your single submitted file, and produces a reply in the form of a polling result. Some virus detection things are not like the others, apparently.