Virus scan creates temp files which are not cleaned up.

已鎖定 Virus scan creates temp files which are not cleaned up.

  • 2007年8月18日 下午 11:37
     
     

    While the OneCare virus scan is running it creates several files in the Windows/temp folder. If a virus is detected which it cannot remove, then three of these temp files are not cleaned up when virus scan completes. Two of these files are of size 73,936KB in size and the third is 72,220KB. (I noticed that this was occuring when investigating why my Windows/Temp folder had reached a size of 25GIGABYTES!. I had been running regular virus scans with OneCare v1 for several months. The same is happening with OneCare v2 beta which I installed this week)

     

    By experimenting and running the vius scan on selected files and folders only, I have confirmed that this only occurs when a virus is detected (and cannot be removed). When a virus is not detected, these temp files are created but are then cleaned up at completion of the scan.

     

    The temp files are named similar to TMP000006D5DCC130F13B75263 but with random hex digits after the first five '0's. The file type is given as "Winamp.File".

     

    In addition to the virus in the log below there was another one which I have since deleted manually, called by OneCare as "Trojan:Win32/PornDialer.AI"

     

    This would seem to be a serious design flaw with OneCare as these temp files rapidly consume disk space when virus scans are done regularly. Tune up does not remove these files either but that is another issue!!

     

    The support log created from onecare is as follows (This is a dual boot system with Windows XP SP2 on drive D:\and with virus scan set to exclude scanning of the other drives)....

     

    19/08/2007 3:14 AM
    Virus and spyware scan was completed
    Scanned Items: C:\
    D:\
    E:\
    F:\
    Q:\
    Scan Type: Custom Scan
    Scan StartTime: 19/08/2007 1:24 AM
    Scan EndTime: 19/08/2007 3:09 AM
    Total Number of Files Scanned: 444038
    Total Number of Files Not Scanned: 133
    Total Number of Threats Found: 1
    Total Number of Threats Cleaned: 0
    Total Number of Threats Removed: 0
    Total Number of Threats Quarantined: 0
    Total Number of Threats Still Present But Suspended: 1
    19/08/2007 3:14 AM
    Windows Live OneCare found potentially harmful or unwanted software on your computer
    Threat Name: Exploit:HTML/IFrame_Exploit.E
    Detection Date and Time: 19/08/2007 1:24 AM
    File Name: D:\Documents and Settings\xxx\Desktop\Old Mail\xxxxxxxxxx.dbx->(Message.294: _xxxxxxx.k9@hawknet.com.au - Re: rough collie pups)->(part0001Smile
    Threat Severity: Severe
    Threat Category: Exploit
    Contained Object: (Message.294: _xxxxxxx.k9@hawknet.com.au - Re: rough collie pups)->(part0001Smile
    Threat found by On Demand Scan: (ANTIVIRUS_ONDEMAND)
    Threat Status: Quarantine failed
    19/08/2007 3:14 AM
    Windows Live OneCare found potentially harmful or unwanted software on your computer
    Threat Name: Exploit:HTML/IFrame_Exploit.E
    Detection Date and Time: 19/08/2007 1:24 AM
    File Name: D:\Documents and Settings\xxxx\Local Settings\Application Data\Identities\{406653AC-0F4D-441C-B5E9-2D155CC7CC39}\Microsoft\Outlook Express\Old Mail.dbx->(Message.294: _xxxxxxx.k9@hawknet.com.au - Re: rough collie pups)->(part0001Smile
    Threat Severity: Severe
    Threat Category: Exploit
    Contained Object: (Message.294: _xxxxxxx.k9@hawknet.com.au - Re: rough collie pups)->(part0001Smile
    Threat found by On Demand Scan: (ANTIVIRUS_ONDEMAND)
    Threat Status: Quarantine failed
    19/08/2007 3:14 AM
    Windows Live OneCare found potentially harmful or unwanted software on your computer
    Threat Name: Exploit:HTML/IFrame_Exploit.E
    Detection Date and Time: 19/08/2007 1:24 AM
    File Name: D:\Documents and Settings\xxxx\Desktop\MailTransfer\xxxxxxxxxx.dbx->(Message.294: _xxxxxxx.k9@hawknet.com.au - Re: rough collie pups)->(part0001Smile
    Threat Severity: Severe
    Threat Category: Exploit
    Contained Object: (Message.294: _xxxxxxx.k9@hawknet.com.au - Re: rough collie pups)->(part0001Smile
    Threat found by On Demand Scan: (ANTIVIRUS_ONDEMAND)
    Threat Status: Quarantine failed

所有回覆

  • 2007年8月20日 上午 01:15
    版主
     
     已答覆

    If you are seeing this in the 2.0 beta, please file a bug on Connect - https://connect.microsoft.com/site/sitehome.aspx?SiteID=168

    Include your support logs per the bug filing instructions and also attach the temp files you are referring to. Thanks.

    -steve

  • 2007年8月21日 上午 08:59
     
     
    Thanks Stephen,
    I have filed a bug report via feedback with log file. Unable to attach copies of the TEMP files because of 5MB limit.
  • 2007年8月21日 下午 04:04
    版主
     
     

    That's okay, then. If Microsoft needs to see the log files, they will contact you. Thanks for reporting it.

    -steve

     

  • 2007年8月27日 下午 02:27
     
     

    I am having the same issue with version 1.6.2111.30.  When my computer got slowr and slower - I went looking and found huge amounts of space being taken up with temp files, after OLC had run a scan.  Also, each time it runs, it finds an Exploit file which can not be deleted (the scan report says).   I had to delete each of the huge temp files by hand - and finanlly found a program that will keep the temp files emptied for me to prevent the problem.

     

    Will this problem be fixed soon?  Do I actually have an exploit file problem on my computer, or is this being picked up from another data base in a virus program that is actually safe?

     

    Thanks!

  • 2007年8月27日 下午 04:44
    版主
     
     

    I'm glad you have a workaround for now. I can't say when this will be fixed, but since it has been reported, I'm sure that the team is looking into it.

    As for the exploit file, does the scan report show it as "Quarantine Failed?" If so, see this post - http://forums.microsoft.com/WindowsOneCare/ShowPost.aspx?PostID=1548384&SiteID=2

     

    If you open OneCare and go to the Logging Tab from Change Settings, you can create a detailed support log report. In the virus scan section it should tell you more about the infection so that you can take manual action to remove it. If you need help, contact support.

    -steve

     

  • 2007年8月27日 下午 07:31
     
     

    Hi,

     

    Appreciate the report and necessary details.  I've been able to reproduce the problem and will be filing a bug against the product.

     

    Appreciate your time and thanks for making the product better.

    -Eddy

  • 2007年8月28日 上午 01:11
     
     

    Thanks for your response Steve.  Although OneCare identifies "Exploit:HTML/IFrame_Exploit.E" as a virus that needs to be removed - and gives the action as t "Quarantine Failed"  - I am still not able to locate a file with this name on my computer to deal with it manually.   

     

    When I looked on Google to check information about this file "Exploit:HTML/IFrame_Exploit.E" it only came up as related to Windows OneCare.   If this is a trojan or virus, wouldn't it be written about somewhere on the net?

     

    Thanks.

  • 2007年8月28日 上午 09:33
     
     

    Therapyave,

     

    "Exploit:HTML/IFrame_Exploit.E" is the name given to the virus by the antivirus community. You will not find a file of that name on your computer. The virus infects and will be located WITHIN one of your own files. To find the name of the file that has become infected...

     

    Open OneCare.

    On the left side of the "Windows Live OneCare box, click on "Change settings (or it might be called "options in earlier versions).

    In the box/window that opens, click on the "Logging" tab.

    Now click on "Create support log".

    Internet Explorer will open with a support log.

    Scrolldown to the virus and spyware protection section (it might be called something different but similar in earlier versions).

     

    You should now be able to read details of the virus and where it is located on your computer.

    Most likely it will be in a ".dbx" file. DO NOT DELETE THIS FILE. It contains ALL your emails. The log should give you some clues as to which email is infected. You can then delete this particular email from within your email program

  • 2007年8月30日 上午 04:15
     
     

    rroentgen,

     

    Thanks so much for your detailed explanation.  It helped me to finally locate the email that was being identified - or rather the batch of files where the exploit culprit was located.  It was on an old c drive, and I wound up just having to delete the delete file of the email program no longer in use.  The scan finally came up clean. 

     

    Thanks again for taking the time you did to help me out.

     

    JA

  • 2008年6月8日 下午 04:36
     
     
    When you get the virus report try clicking on the name of the virus.  It should show you the files where the virus is stored.  I had one in several old emails that were stored in both a Windows OneCare backup and my Maxtor backup.  I can't seem to delete the Windows backup - that's what I'm looking for here.

     

  • 2008年6月10日 下午 09:00
    版主
     
     

    Open OneCare, click on Change Settings. On the logging tab, click on create a support log. In the report that opens in your browser, scroll to the virus and spyware section to view where the infected file is located. If the infection is within a OneCare backup, I'd recommend deleting the backups and starting a new Full backup or simply adding the OneCare backup folders to the scanning exclusions from the Virus and spyware tab in OneCare Change Settings.

    -steve