We are in the process of installing avast! 8 on our workstations. We are getting several email virus alerts for multiple machines including one server. I seems like most of them are exe files that we run from our app servers but there are also log files and dlls. Here is one of the alerts.
avast! [107-]: File “C:\Windows\SoftwareDistribution\DataStore\Logs\tmp.edb” is infected by “Win32:Expiro-CE” virus.
“File System Shield” task used
Version of current VPS file is 130715-0, 07/15/2013
I have added some of the exe files to the exclusions I’m not sure if that is the fix or if someone is having similar problems and I don’t know what I would exclude for the .edb files.
I sent an email with the message we get in email and a print screen of the files it has “Moved to Chest”. It seems almost every program on the users machines and the server I installed it on are coming up with this virus warning, including Autocad, media player and office programs. It is not every machine but one of them is a fresh image that we are building so it is highly unlikely that it has a virus. I’m not sure what file you would like sent. We did find the chest which has many files in it.
Thanks.
I changed the Heuristics level to low and that didn’t help. It was set to normal.
I have removed as a test almost every setting in the File System Shield and tried to run a network program that I know is not a virus and it continues to come up with an alert. “Malware Blocked. avast! File System Shield has blocked a threat. No Further action is required. The threat was detected and blocked when the file was created or modified.” I tried turning off those settings that scan when a file is created or modified along with any other setting that I found under the "Scan when… " settings are and nothing works. The only way I can get it to stop is the Stop the File System Shield from running. The files is is finding and moving to chest or blocking are local files such as media player files, files in system32. Nothing even related to the program or programs that we are trying to run. Any other ideas?