The virus was a Swen32 type (don’t remember the exact). Menybe a good idea would be a “Copy message” function in the alert box to cut out all the important info (the question “what was the exact message” keeps appearing here).

I think what happened was:

  • I have setup the mail scanner to scanned ZIPped files
  • Avast temporarily extracted a ZIPped attachement
  • The on-access scanner check the file and triggered the alert

So could be some poor communcation between the mail-scanner and the oridinary scanner. But I still can’t see why I got two messages. The first one SHOULD BLOCK all access to the file, right. So the 2nd message shouldn’t ever be.