avast doesn't like python

Hello everyone,

Earlier today when I turned on my PC, I was informed by avast that it had prevented a malicious attack. Here is the message recorded in the FileSystemShield log:

11/5/2010 1:03:31 PM C:\Windows\Installer{D40AF016-506C-43FB-A738-BD54FA8C1E86}\python_icon.exe [L] Win32:Malware-gen (0)
While moving file to chest, error occurred: The process cannot access the file because it is being used by another process
During the file delete, error occurred: The process cannot access the file because it is being used by another process

The file, python_icon.exe, is used with the idle3 interpreter for python 3.2.1. For some reason, avast is picking this up as a trojan. I’m thinking false positive. Anyway, I decided to uninstall python to remove the file and this worked fine. I uninstalled the program and the file was gone after installation. After that, I went to pythons website, http://www.python.org/ , and redownloaded the python installer (Windows AMD64 / Intel 64 / X86-64 binary [1] – does not include source) and when it finished avast told me a threat was detected! Here is the log:

11/5/2010 7:15:06 PM http://www.python.org/ftp/python/3.1.2/python-3.1.2.amd64.msi|>Icon.python_icon.exe [L] Win32:Malware-gen (0)

What is going on here? Has python been compromised or is avast on the fritz?

Well I have extracted the file from within the msi file and there aren’t a great deal of hits on virustotal, http://www.virustotal.com/file-scan/report.html?id=ba2a63546f479362ecbe93fd3b1f3d64d0d11361b6510f3f81fc97aad72e292a-1289002510.

So I have submitted it for further analysis.

Thank you David. I also checked on my laptop by scanning the same file, and avast finds the same trojan.

You’re welcome.

Hopefully it won’t take long for it to be analysed, Avast are generally quick to correct if it is confirmed to be an FP.

Looks like the problem has been corrected with the latest virus definitions!

Yes looks that way, thanks for the feedback.

Yes, it was fixed in last VPS.
sorry for your inconvenience.
Best regards
Jan Sirmer

@ ryans fryin,

Now that your issue is resolved/fixed, please go back to the first open post in this topic, click the modify button in that Post and change the title/subject, add [Resolved] to the beginning of the title so this thread can be closed.

Feel free to come back any time you need help, to learn something new, or just to ask questions. We are here 24/7 for your convenience. Thank you.