Author Topic: avast quarantined tmp******** files during Ad-Aware scans  (Read 2096 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
avast quarantined tmp******** files during Ad-Aware scans
« on: June 05, 2015, 06:02:30 PM »
I've been using Ad-Aware Antivirus to do occasional on-demand scans. Yesterday, I did a few custom and quick scans in Ad-Aware. Immediately before each of the scans finished, Avast's File System Shield alerted me that it detected a tmp******** file infected with Win32:Evo-gen [Susp] in C:\WINDOWS\Temp\********-****-****-****-************\tmp******** directory, attributed to the process AdAwareService ('*' are digits/letters); avast automatically and immediately quarantined those files. In same tmp******** directories, there was another tmp******** file which disappeared as soon as Ad-Aware was closed. I then, restored the supposedly infected files from avast's Virus Chest to their original locations. However, after rebooting Windows, I checked  C:\WINDOWS\Temp directory and verified that the ********-****-****-****-************\tmp******** subdirectories were still there, still containing no other files than those restored by me from the Virus Chest!

 Considering that those tmp******** files are probably avast's false positives, and that those files were likely produced by Ad-Aware during each scan and would probably be cleared out by the program itself, were it not for avast's untimely action, I want to know if it is safe to manually delete them now and the resulting empty directories containing them, given that each file is 39,1 MB in size, which is not negligible. I also added the path C:\WINDOWS\Temp\* to Exclusions list in avast Settings to prevent this from happening again in future Ad-aware scans.


REDACTED

  • Guest
Re: avast quarantined tmp******** files during Ad-Aware scans
« Reply #2 on: June 09, 2015, 06:11:36 PM »
ok, thank you for the link, that article is useful. I was already fully aware that I should not use active (real-time) protection of more than one antivirus program simultaneously. Nevertheless, I've been using sometimes Ad-Aware Antivirus, always and only in compatibility mode (real-time protection *OFF*), merely to do occasional on-demand scans. I've been doing this since a long time, for years, mainly to detect and remove tracking cookies and/or other forms of spyware, without any previous conflicts with my primary antivirus, that is, until beginning of the current month.

I tried unsuccessfully to report the false positives and submit the files in question to Avast Virus Lab, I tried to do it either from within the Virus Chest or via the online form, but couldn't do it in either way: In Virus Chest, after right-clicking each of the files and selecting the option 'Submit to virus lab...' from the context menu, the application form does not appear! In the online form, after clicking the Submit button and waiting for a while, Firefox delivers an error page saying that Secure Connection Failed! I'll try to submit a support ticked on this issue.
I can only hope that after future avast virus definition updates, files such as those may no longer be wrongly identified as threats. Until that happens, I decided to temporarily disable avast's active protection (only File System Shield, not Web Shield, nor Mail Shield) prior doing any future scans with Ad-Aware.

But my main purpose when I started this topic was to try to figure out what are those tmp******** files (and why Ad-Aware generates them) and whether it is safe to manually delete them now (and the folders containing them). For that matter, I soon realized that it was far more suitable to ask that question rather in the Lavasoft support forums, and that was what I did next. For those interested, here's the link to that thread.