Recently I was on the Help2Go pc forum.
http://www.help2go.com/component/option,com_forum/Itemid,32/page,viewforum/f,5/(can't link you to the specific thread, because will set off Avast again, but it's the thread last week by author "needhelpnow" topic was "Internet Explorer and My Computer Folder won't open..........eeek!", if you'd like to try it yourself.)
I was casually reading some posts on their spyware help forum and not once, but
TWICE (went back later to site and selected the post again to test my theory), when I clicked on one particular thread, Avast alerted a virus warning for
Win32.Mhtplo-30 [Trj]in a Temporary Internet File. Wouldn't let me move to chest or delete because "was in use by another process". I clicked No Action. As I had
JUST cleaned out my TempIntFiles folder before going on line, I knew if it was a virus infection, it had
JUST occurred. Immediately disconnected and rebooted into safe mode and could not see a temp folder. But did a complete scan with Avast and Ewido and found nothing!. Went back into regular mode and could now see a TempIntFiles folder with the named file in it. Did two scans again and nothing found. Zipped said file up to Jotti and nothing found by any of their scanners. Trend Micro Housecall found nothing. Then I went to Help2Go site and posted the oddity for them to check into. Their main spyware guy (not an Avast user) said HE could open the thread with no problem, but saw a line in the poster's HJT log that may have been what set off Avast because it was a "reference to a baddie." The line was:
016 - DPF {10003000-1000-0000-1000-000000000000}
He said it must have been a False Positive by Avast and not to worry and to just delete the file in the usual manner. I have no bizarre, virus type symptoms, so I believe he is correct in saying it is an FP. I'm new to Avast (under a month) and am surprised it is so sensitive that it sees references to baddies in HJT logs posted on forums I like to read? Is Avast's database signature recognition for this particular virus not specific enough?
I don't guess I'll
ever get to read that particular poster's thread on H2Go.