Author Topic: Comodo Internet Security found something in Avast!'s temp folder  (Read 8333 times)

0 Members and 1 Guest are viewing this topic.

MaxyDawg

  • Guest
Comodo Internet Security found some virus in Avast!'s temp folder. And another.
Should I be worried?

Today, while I was online, Comodo Internet Security had gotten wind from, I would guess, its Resident Shield (whatever it is that watches files being accessed) found four infected items in temp and AppData folders, three of said items appearing to be in Avast's temp folders, or something, and the other being in Opera's AppData folder. Of course I shot all four alerts to Quarantine and not just a minute ago exported a log file for your viewing pleasure. Unfortunately, the log file (which is in HTML) cna't be uploaded, so here's a cut-and-paste;

COMODO Internet Security Logs
        Date Created: 1/26/2009 7:34:15 PM
Log Scope: All The Times
Date/Time   Action   Location   Malware Name   Status
1/26/2009 4:46:48 PM   Detect   C:\Windows\Temp\_avast4_\unp54280650.tmp   TrojWare.HTML.CrashIE.A@7162   Success
1/26/2009 4:48:48 PM   Detect   C:\Windows\Temp\_avast4_\unp54280650.tmp   TrojWare.HTML.CrashIE.A@7162   Success
1/26/2009 4:49:34 PM   Quarantine   C:\Windows\Temp\_avast4_\unp54280650.tmp   TrojWare.HTML.CrashIE.A@7162   Success
1/26/2009 4:49:34 PM   Detect   C:\Windows\Temp\_avast4_\unp10894333.tmp   TrojWare.HTML.CrashIE.A@7162   Success
1/26/2009 4:49:37 PM   Quarantine   C:\Windows\Temp\_avast4_\unp10894333.tmp   TrojWare.HTML.CrashIE.A@7162   Success
1/26/2009 4:49:37 PM   Detect   C:\Windows\Temp\_avast4_\unp132339247.tmp   TrojWare.HTML.CrashIE.A@7162   Success
1/26/2009 4:49:38 PM   Quarantine   C:\Windows\Temp\_avast4_\unp132339247.tmp   TrojWare.HTML.CrashIE.A@7162   Success
1/26/2009 4:49:40 PM   Detect   C:\Users\Max\AppData\Local\Opera\Opera\profile\cache4\opr02WD1   TrojWare.HTML.CrashIE.A@7162   Success
1/26/2009 4:49:44 PM   Quarantine   C:\Users\Max\AppData\Local\Opera\Opera\profile\cache4\opr02WD1   TrojWare.HTML.CrashIE.A@7162   Success
End of The Report

As the report shows, there were more files than I thought were infected. I'll run a full scan, but is it just coincidence that there was something that infected Avast's stuff but the other program (Comodo) caught it first?
« Last Edit: January 27, 2009, 02:55:06 AM by MaxyDawg »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89150
  • No support PMs thanks
Re: Comodo Internet Security found something in Avast!'s temp folder
« Reply #1 on: January 27, 2009, 02:39:48 AM »
This is where avast unpacks files so they can be scanned, hence the unp bit at the start of the file name, a whole bunch of numbers followed by the .tmp file type. These are normally cleared out after completion of the scan. Why that didn't happen is not known, see below.

However, your use of the Comodo Internet Security effectively means you have two resident AVs installed and that is simply a no, no.

Conflict between resident AVs:
Such as what has happened above, the unp123456.tmp files remaining when they should have been removed, could come about because the second AV hooks those files as they are unpacked to be scanned and avast effectively can't remove them.

Worse still resident scanners can be more of a problem than this at worst they could lock your system.

So you really need to make a decision which resident AV you which to have on your system and remove the other.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Vladimyr

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1639
  • Super(massive black hole) Poster
Re: Comodo Internet Security found something in Avast!'s temp folder
« Reply #2 on: January 27, 2009, 02:50:06 AM »
Even if CIS was your only on-access AV, it's "good" at flagging False Positives. However it's best not to assume.
To be sure the files are safe, upload them to jotti or virustotal for multiple "second opinions".
There is a way that seems right to a man,
       but in the end it leads to death
.” - Proverbs 16:25

MaxyDawg

  • Guest
Re: Comodo Internet Security found something in Avast!'s temp folder
« Reply #3 on: January 27, 2009, 02:58:02 AM »
I'm going to disable Comodo, but can I delete those temp files then? If they were supposed to be removed anyway, would it hurt anything? They're already in Quarantine with Comodo, and nothing seems to have gone awry yet... And what about what's in Opera's AppData folder?

Offline Vladimyr

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1639
  • Super(massive black hole) Poster
Re: Comodo Internet Security found something in Avast!'s temp folder
« Reply #4 on: January 27, 2009, 03:36:18 AM »
Everything about those files indicates that you can safely delete them from the COMODO quarantine.
To be super-cautious you could restore them and then add them to the the avast! Virus Chest (see image) before uninstalling COMODO AV.
Disabling isn't enough. You need to uninstall the AV part of CIS from Add/Remove Programs. (see attached CIS images)
There is a way that seems right to a man,
       but in the end it leads to death
.” - Proverbs 16:25

silvertones

  • Guest
Re: Comodo Internet Security found something in Avast!'s temp folder
« Reply #5 on: April 10, 2009, 09:16:15 PM »
This is very similar to an issue I'm having and reported in the forums under" Is anyone having this problem" however for me it is PC Tools Spyware Doctor that is flagging these unp******.tmp files as malware. My temp files are not being deleted either. SD flags Avast's webshield at 2 times so far. When I try to post a message on the PC Tools forum and when I try to log into this forum. The time this started happening is about the same.
When I tried to post this message SD flagged Avast's webshield.I have to put an exception for both sites into the Webshield customize section.
BTW Spyware Doctor is flagging the Avast unp*******.tmp files as:

3/30/2009 8:07:25 AM:793    
IntelliGuard: System Event Blocked
Threat Name - Adware.Adsponsor
Details - Spyware Doctor has blocked an application attempting to access a file.
Risk Level - Low
Infection - C:\WINNT\TEMP\_AVAST4_\UNP181347045.TMP
« Last Edit: April 10, 2009, 09:22:54 PM by silvertones »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89150
  • No support PMs thanks
Re: Comodo Internet Security found something in Avast!'s temp folder
« Reply #6 on: April 10, 2009, 11:03:03 PM »
That is where avast unpacks the files that it going to scan, hence the unp file prefix and the .tmp file type. Once avast has scanned them they would be deleted. However it looks like the interference form Spyware Doctor blocks that action as it would effectively lock the file. So basically you have a conflict between the two scanners.

Why would you put an exception into the web shield when it is SD doing the detection, you should exclude ashWebSv.exe (the web shield) in SD. It would probably be advisable to also exclude the _avast4_ folder too.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline lukor

  • Administrator
  • Super Poster
  • ***
  • Posts: 1884
    • AVAST Software
Re: Comodo Internet Security found something in Avast!'s temp folder
« Reply #7 on: April 10, 2009, 11:51:32 PM »
One scanner blocks the other one from accessing the files. Not only can this cause one antivirus to detect temp files of the other one, but it also prevents one antivirus to correctly recognize the files as infected (since the other one - Comodo here - blocks all access to the virus, or deletes it completely - but as it may be just extracted temp file, it would get deleted anyway). If one antivirus (avast here) would be doing other good things when the virus is detected - such as terminating the download, or deleting an attachment from email - this actions wouldn't get executed which effectively ruins all.

So, this is why running two resident scanners at the same time is a bad idea. Moreover frequently your computer can deadlock or bluescreen :)


Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89150
  • No support PMs thanks
Re: Comodo Internet Security found something in Avast!'s temp folder
« Reply #8 on: April 11, 2009, 01:14:19 AM »
In this particular case it isn't comodo but Spyware Doctor a resident anti-spyware (not anti-virus) that is causing the clash.

Whist two resident AVs has always been frowned upon, nothing much has been said of resident anti-spyware, but there will always be some areas of crossover on detections.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

sta_minghia

  • Guest
Re: Comodo Internet Security found something in Avast!'s temp folder
« Reply #9 on: April 11, 2009, 01:58:19 AM »
In this particular case it isn't comodo but Spyware Doctor a resident anti-spyware (not anti-virus) that is causing the clash.

Whist two resident AVs has always been frowned upon, nothing much has been said of resident anti-spyware, but there will always be some areas of crossover on detections.
i m running avast and  Spyware Doctor (could that cause me some problem?)
thank you Giovanni

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89150
  • No support PMs thanks
Re: Comodo Internet Security found something in Avast!'s temp folder
« Reply #10 on: April 11, 2009, 03:40:35 AM »
Basically what I said in Reply #6 and what lukor stated in Reply #7.

In light of this I would suggest you consider excluding the _avast4_ folder from scans in Spyware Doctor.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

silvertones

  • Guest
Re: Comodo Internet Security found something in Avast!'s temp folder
« Reply #11 on: April 11, 2009, 01:40:29 PM »
First you all  need to understand that Avast and SD have always co existed quite nicely. I've been using the 2 together for over a year with no issues.Many of the folks on the PC Tools forums also prefer Avast to PC Tools AV.  You may not believe this .I found the answer. At the same time this started happening I remember that Firefox had updated to v 3.0.8. I removed all of the exclusions from Avast and tried things with IE and everything worked as it should. I then uninstalled firefox 3.0.8 and installed 3.0.7 and all is well. I'm going to download the complete file of 3.0.8 instead of the letting it do an auto update. i've had problems before with Firefox and their auto update.This indeed is queer but the truth is in thr pudding as they say. Maybe someone has thoughts on this.
« Last Edit: April 11, 2009, 01:46:54 PM by silvertones »

silvertones

  • Guest
Re: Comodo Internet Security found something in Avast!'s temp folder
« Reply #12 on: April 11, 2009, 03:23:17 PM »
I quit. I don't know what's going on. It's doing it now with 3.0.7 :-[
BTW I did try having the web shield on the Global Action list of SD and that didn't help.
You can't put folders on the global action list only files and seeing as the temp files come and go.........

PS I really do appreciate all of the help!
« Last Edit: April 11, 2009, 03:30:00 PM by silvertones »

abhinashh

  • Guest
Re: Comodo Internet Security found something in Avast!'s temp folder
« Reply #13 on: April 11, 2009, 03:28:17 PM »
This is where avast unpacks files so they can be scanned, hence the unp bit at the start of the file name, a whole bunch of numbers followed by the .tmp file type. These are normally cleared out after completion of the scan. Why that didn't happen is not known, see below.

However, your use of the Comodo Internet Security effectively means you have two resident AVs installed and that is simply a no, no.

Conflict between resident AVs:
Such as what has happened above, the unp123456.tmp files remaining when they should have been removed, could come about because the second AV hooks those files as they are unpacked to be scanned and avast effectively can't remove them.

Worse still resident scanners can be more of a problem than this at worst they could lock your system.

So you really need to make a decision which resident AV you which to have on your system and remove the other.

silvertones

  • Guest
Re: Comodo Internet Security found something in Avast!'s temp folder
« Reply #14 on: April 11, 2009, 11:30:24 PM »
Spyware Doctor did an update an hour ago and the problem has disappeared. Coincidence ?