E
Ernie B.
I have a minor mystery....
I did a boot-time scan with Avast free on the 17th. No infected files were
found.
Early this morning I started a complete scan with a-squared and heard the
Avast siren after a few minutes. The file, C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
\a2archive\keygen.exe, was moved to the Virus Chest and the a-squared scan
allowed to complete. It found a few tracking cookies but nothing else.
I do have keygen.exe on my system, scanned it with Avast. No complaints, so I
suppose that the file is clean.
The file was scanned with Avast from the VC with the following result:
==============================================================
Scanning of selected files
------------------------------------------------------------------------------
------------
Program will try to scan 1 selected file(s) in the Chest
Move files to temporary folder: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\_avast4_
\unp231646429.tmp
FileID: 0000000035 Original file name: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
\a2archive\keygen.exe New folder: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\_avast4_
\unp231646429.tmp\35.exe
Scan files in the temporary folder: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\_avast4
_\unp231646429.tmp
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\_avast4_\unp231646429.tmp\35.exe
Win32:Keygen-AO [Trj]
------------------------------------------------------------------------------
------------
Action was completed successfully!
================================================================
The same thing happened on 2/25/08 and again just now when I re-ran the a-
squared scan. I also note that the 'Last changed' time for one of the files
in the Avast VC is 3/19/2008 6:31:28 PM, which isn't here yet, and the
'Transfer time' to the VC is 3/19/2008 1:31:46 PM, which is correct. The
other subject file move to the VC early this morning has a similar time
discrepancy.
Where did this infected file come from? Is it an artifact of a-squared?
What causes the time discrepancy noted above?
I don't belive my computer is infected but it's puzzling, any thoughts would
be appreciated.
I did a boot-time scan with Avast free on the 17th. No infected files were
found.
Early this morning I started a complete scan with a-squared and heard the
Avast siren after a few minutes. The file, C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
\a2archive\keygen.exe, was moved to the Virus Chest and the a-squared scan
allowed to complete. It found a few tracking cookies but nothing else.
I do have keygen.exe on my system, scanned it with Avast. No complaints, so I
suppose that the file is clean.
The file was scanned with Avast from the VC with the following result:
==============================================================
Scanning of selected files
------------------------------------------------------------------------------
------------
Program will try to scan 1 selected file(s) in the Chest
Move files to temporary folder: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\_avast4_
\unp231646429.tmp
FileID: 0000000035 Original file name: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
\a2archive\keygen.exe New folder: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\_avast4_
\unp231646429.tmp\35.exe
Scan files in the temporary folder: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\_avast4
_\unp231646429.tmp
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\_avast4_\unp231646429.tmp\35.exe
Win32:Keygen-AO [Trj]
------------------------------------------------------------------------------
------------
Action was completed successfully!
================================================================
The same thing happened on 2/25/08 and again just now when I re-ran the a-
squared scan. I also note that the 'Last changed' time for one of the files
in the Avast VC is 3/19/2008 6:31:28 PM, which isn't here yet, and the
'Transfer time' to the VC is 3/19/2008 1:31:46 PM, which is correct. The
other subject file move to the VC early this morning has a similar time
discrepancy.
Where did this infected file come from? Is it an artifact of a-squared?
What causes the time discrepancy noted above?
I don't belive my computer is infected but it's puzzling, any thoughts would
be appreciated.