Recommended Posts

What is this that EAM is trying  to run

C:\Program Files\Emsisoft Anti-Malware\a2service.exe > C:\Windows\Temp\tmp000000c0\tmp00000058

 

I have blocked it so far

 

Pete

Share this post


Link to post
Share on other sites

It comes from Mzwritescanner which is flagging the temp file as some kind of executable being initiated  the EAM services exe file

Share this post


Link to post
Share on other sites

i believe these temp files seems to be Bitdefender related and is not to worry about. This is not new behavior.

 

19 minutes ago, Peter2150 said:

I tried running an update and it said none were available.

This could happen when no updates are available, which happens so now and then

Share this post


Link to post
Share on other sites

Here (Win 8.1) such a file is shown as 0 bytes by File Explorer... but it's open to a2service, so I suppose what FE shows is misleading.  Sysinternals says:

C:\Windows\system32>handle -a \temp\tmp

Nthandle v4.21 - Handle viewer
Copyright (C) 1997-2018 Mark Russinovich
Sysinternals - www.sysinternals.com

a2service.exe      pid: 9140   type: File          27E0: C:\Windows\Temp\tmp0000049d\tmp00000000

C:\Windows\system32>

and dir also shows it's empty

C:\Windows\system32>dir /s "c:\windows\temp\tmp*.*"
 Volume in drive C has no label.
 Volume Serial Number is F607-7930

 Directory of c:\windows\temp

11/06/2019  20:48    <DIR>          tmp0000049d
               0 File(s)              0 bytes

 Directory of c:\windows\temp\tmp0000049d

11/06/2019  20:48                 0 tmp00000000
               1 File(s)              0 bytes

     Total Files Listed:
               1 File(s)              0 bytes
               1 Dir(s)  210,853,363,712 bytes free

C:\Windows\system32>

 

So... did something get unpacked into it,then removed, or what?

Share this post


Link to post
Share on other sites
45 minutes ago, Frank H said:

i believe these temp files seems to be Bitdefender related and is not to worry about. This is not new behavior.

 

This could happen when no updates are available, which happens so now and then

 May not be a worry  but it is a real PIA for me as it seems to be some what random, but it triggers mzwritescanner which is a pain.   Okay now that I know I have to figure out how to whitelist it.

Share this post


Link to post
Share on other sites

Running multiple protection apps concurrently is a source for PIA's anyway.

Share this post


Link to post
Share on other sites
Guest
This topic is now closed to further replies.

  • Recently Browsing   0 members

    No registered users viewing this page.