PDA

View Full Version : Avast 'suspicious file'


BOAC
17th Mar 2011, 08:16
Win XP/Avast 5.1.889: I am getting frequent pop-ups warning of a '**/temp/xxxx.tmp' 'suspicious' file. It does not appear in the Virus chest nor on a search of the stated directory. Options 'ignore/delete'

Any ideas how I check it?

mixture
17th Mar 2011, 10:10
Have you tried clearing temp stuff and rescanning ? (either manually or with something like CCleaner (http://www.piriform.com/ccleaner) ?)

BOAC
17th Mar 2011, 12:10
Yes and it is not there. What I cannot fathom is where it is!

Saab Dastard
17th Mar 2011, 12:45
Is it perhaps in a system restore file?

SD

mixture
17th Mar 2011, 12:50
Good point Saab. Have you tried trashing your historical System Restore snapshots BOAC ?

BOAC
17th Mar 2011, 12:58
I don't think it is/was there - the location was given as in #1 - actually in docs and settings/me/temp/dBPD9.tmp

This is the third day Avast has thrown this up, each time a different filename and each time not found. An Mbam scan yesterday found nowt.

mixture
17th Mar 2011, 14:50
Starting to sound potentially like a bug in AVAST if other things (Mbam) are not picking up anything.

Given the nature of temp files, it may well be that the file is getting modified as it's being scanned and AVAST isn't coping well with that.

Never say never as they say, but it seems like you've (correctly) gone to the effort of scanning with other software and found nothing it's difficult to say if it's something to worry about.

BOAC
17th Mar 2011, 15:59
My thoughts too, but

"Just because you are paranoid it does not mean they are not out to get you":)

mixture
17th Mar 2011, 16:51
Have been looking around a bit, interestingly enough, Symantec recently had an issue where it was quarantining its own files (i.e. temp files it was creating during AV scans).

Perhaps AVAST is suffering a similar fate ?

See :
Enterprise Support - Symantec Corp. - DWH***.tmp files are detected in the user profile temp directory. (http://www.symantec.com/business/support/index?page=content&id=TECH92399&locale=en_US)

BOAC
17th Mar 2011, 17:19
Interesting. I'm pretty sure I have all the Avast scans 'barking to order' and I don't think it is associated with any scan, but it might explain the *.tmp file name plus 'disppearance'.

I'll watch during the next twice daily db update.