Ah!

Now we’re getting somewhere. That trz##.tmp file is still sitting on a cleaned PC although with a different name.
So now I had better check some of these PC’s for rootkits.
edit seems that it’s not a root kit. The PC I had looked at had simply been reinfected by the users USB Device.

I have infected a PC several times (on purpose) but it has not once been infected with the trz##.tmp part of the virus. I wonder why.

Still doesn’t answer why Avast! doesn’t detect “on access”.