Running SAV 9.0 on a networked PC, user received the following notification while working on an excel file: Symantec Anti-Virus Notification Scan Type: Auto-Protect Scan Threat: Bloodhound.Exploit.45 File: C:\Windows\Temp\~DF3B02.TMP Location: Quarantine Computer: xxxx User: xxxx Action Taken: Qaurantine succeeded: Access denied Date Found: Sunday, 13 November 2005 14:52:39 As I understand auto-protect, this service scans files AS THEY ARE ACCESSED. (Opened, moved, copied, etc). The user was working on an excel spreadsheet, there was no other activity on the pc. No other applications in use, and a virus scan was not in progress. So what would have triggered an auto-protect notification? Does this mean that something else touched a file on the users pc? Any help appreciated, With thanks,