Where Is The Log For "Threats Detected and BLocked"?

v2014.9.0.2007

During a SecondCopy backup (which seems to use Windows Copy commands), Avast keeps throwing popups about a “Win32: Evo-Gen”.

I want to find out where the problem file is and delete it from the backup’s source.

I can do the RightClick | Show Last Popup Message thing, but the popup truncates the path.

Spent the last half hour trying to find the log that shows this stuff, but no luck.

I’m guessing it is in the UI and I’m looking right at it and not seeing it.

??

When they were in rea time shields you need to go to the program files of Avast

C:>Windows>Program Data>Avast Software>Avast>log

There you can find a log for every shield.

After the UI, that was the first place I looked. Browsed every file with a .log suffix, but did not find anything.

But just now - thinking I must have missed something - I went back to C:>Windows>Program Data>Avast Software>Avast to look again and, guess what?.. There is no “log” directory. Screen snap: http://tinyurl.com/m3upg9r

Now I’m wondering if my mind is slipping…

Have you tried to go to programs>Avast Software>Avast

When there is nothing,i might have missed something, i think the saving place of the Log files changed.

Suspicion confirmed: I am losing my mind. The second time around, I was looking at Program Files instead of ProgramData.

But I went through all the .log files one more time - even did a search on the problem file name - but was unable to find anything. Also, none of the files even looked like they contained popup messages.

ProgramData is an hidden folder by the way.

You need to go to Organize>Folder and search options and in the list you can show hidden files.

a screenshot is attached.

Been there, done that - twice already.

But the question remains: which .log file contains the information behind those popup messages?

I’ve opened every .log file twice and still do not see one that seems like it contains that information.

I would think the resident.log.

But it depends on from what shield it was blocked.

Not enough detail there:

11/7/2013	8:40:33 PM	logCleanupUrls (0)
11/7/2013	8:54:15 PM	logCleanupUrls (16)
11/7/2013	9:09:13 PM	logCleanupUrls (16)
11/7/2013	9:16:14 PM	logCleanupUrls (15)
11/7/2013	9:32:56 PM	logCleanupUrls (15)
11/8/2013	8:26:59 AM	logCleanupUrls (47)
11/8/2013	8:33:26 AM	logCleanupUrls (32)
11/8/2013	11:40:26 AM	logCleanupUrls (93)
11/8/2013	12:41:17 PM	logCleanupUrls (94)
11/8/2013	1:25:23 PM	logCleanupUrls (93)
11/8/2013	1:33:55 PM	logCleanupUrls (109)
11/8/2013	1:51:26 PM	logCleanupUrls (94)
11/8/2013	3:15:33 PM	logCleanupUrls (94)
11/8/2013	3:29:06 PM	logCleanupUrls (78)
11/8/2013	5:34:25 PM	logCleanupUrls (141)
11/9/2013	10:18:35 AM	logCleanupUrls (202)
11/9/2013	11:08:58 AM	logCleanupUrls (94)
11/9/2013	11:33:18 AM	logCleanupUrls (110)
11/9/2013	3:25:13 PM	logCleanupUrls (93)
11/9/2013	4:06:44 PM	logCleanupUrls (109)
11/9/2013	5:54:45 PM	logCleanupUrls (124)
11/9/2013	7:05:46 PM	logCleanupUrls (109)
11/9/2013	7:35:52 PM	logCleanupUrls (125)
11/10/2013	10:12:21 AM	logCleanupUrls (125)
11/10/2013	10:47:02 AM	logCleanupUrls (109)
11/10/2013	12:19:34 PM	logCleanupUrls (109)
11/10/2013	12:31:20 PM	logCleanupUrls (125)
11/10/2013	8:12:00 PM	logCleanupUrls (140)
11/10/2013	8:24:57 PM	logCleanupUrls (203)
11/10/2013	9:03:06 PM	logCleanupUrls (125)
11/11/2013	10:05:59 PM	logCleanupUrls (265)
11/12/2013	9:21:10 AM	logCleanupUrls (374)
11/12/2013	11:16:18 AM	logCleanupUrls (281)
11/12/2013	11:41:29 AM	logCleanupUrls (327)
11/13/2013	10:08:22 AM	logCleanupUrls (296)
11/15/2013	11:08:15 AM	logCleanupUrls (780)

Is there anything in the Virus chest?

Under scan at the bottom.

At the bottom of the UI home screen? I see a “Quick Scan” icon, but the only thing under that is an advertisement for “firewall”.

In the log directory? All I see is “Chest.log” and that’s just a list to start/stop times for “chest”.

On the left side under scan is the chest at the bottom.

Screenshot

I don’t know what shield initiated the popup alerts, but I think you are more likely to find something in the C:\ProgramData\AVAST Software\Avast\report folder, the WebShield.txt is one if the alerts were from the Web Shield. then there is the FileSystemShield.txt or any of the on-demand scans that run.

See image example of folders, this one is from my XP system so yours would be from the path I gave above.

Got it!.

It’s a German-English translation thing.

In English it would be:

  • Click “Scan” on the home screen
  • Click “Quarrantine (Virus Chest)” on the resulting “Scan” screen
  • A “Virus Chest” window will open, showing the contents of the virus chest.

Thanks!

good translation.

Or, do it the easy way:
http://forum.avast.com/index.php?topic=93544.msg1010008#msg1010008

Sweet!.. Thanks.

My pleasure. :slight_smile: