Pages: 1
RSS
Strange behavior of anti-virus software
 
Hi,

For the last two days, the Bat has been interacting in a strange way with my antivirus app (TREND MICRO OfficeScan).

When The Bat is running, every 10-15 minutes I get a message from the antivirus saying that it found WORM_NETSKY.P in my local temp folder.  The file name is always like this:
  bat1D.tmp (document.txt            .exe)
(yes, that's many spaces between .txt and .exe).

It says that the file has been quarantined, but the same message comes back over and over.  The file name changes every time (bat59.tmp, bat32.tmp etc.).

If I close The Bat, the messages don't appear anymore.

I've scanned the entire Bat installation directory.  I've searched for strange attachments.  Nothing.

Also, this started happening out of the blue.  I didn't install anything new at that time.

Does anyone have an idea about what this is about?

Oh yes, I was using an early version 4 before, and today I've upgraded to 4.2.23.

Best,
Michal
Edited: Phrixo Psakpinoglou - 04 February 2010 17:20:55
 
probably AV deletes the message, and theBat thinks it's not received, so tries to download it again which triggers another AV alert. Or something like that.
Most mail servers have AV protection or some sorting capabilities or option to create rules. If yours has AV enable it, or see if you can sort messages with potentially unsafe attachments in the server's trash folder.
 
Hi,

Thanks!  Indeed, I looked at the logs (in Bat), and found stuff like that:

04/02/2010, 14:08:22: FETCH - 203 messages in the mailbox, 1 new
04/02/2010, 14:08:23: FETCH - Received message from matt@mattkruse.com, size: 42090 bytes, subject: "Re: Extended Mail"
!04/02/2010, 14:08:23: FETCH - could not store message (file name - C:\DOCUME~1\mblazejc\LOCALS~1\Temp\bat189.tmp)
04/02/2010, 14:08:23: FETCH - connection finished - 1 messages received

So, there was one offending message, and The Bat has been trying to download it for the last 2 days.  I logged on to my e-mail account via WebMail, deleted the e-mail, and everything is back to normal!

Thanks a lot!

Michal
Pages: 1