Author Topic: suddenly old pdf-files are infected with PDF.UrlMal-inf [Trj]  (Read 15693 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
suddenly old pdf-files are infected with PDF.UrlMal-inf [Trj]
« on: November 26, 2015, 05:25:28 PM »
Hello,

I did a full-system-scan today (with avast internet security 2015) and it suddenly marked several pdf's from 2012 as infected with PDF.UrlMal-inf [Trj]
All the infected pdf-files are from the same company (they concern my solarpanels, so I would like to keep these pdf's)
For now Avast has put them in quarantine in the Virus Chest.

Would it be safe to recover them ? Or are they really infected ?

Thanks a lot for your help.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: suddenly old pdf-files are infected with PDF.UrlMal-inf [Trj]
« Reply #1 on: November 26, 2015, 05:48:38 PM »
You are using a old(er) version of avast.
Latest final : https://forum.avast.com/index.php?topic=178580.0
Latest beta : https://forum.avast.com/index.php?topic=179386.0

If you believe the detection is a false positive : https://blog.avast.com/tag/false-positive/

REDACTED

  • Guest
Re: suddenly old pdf-files are infected with PDF.UrlMal-inf [Trj]
« Reply #2 on: November 26, 2015, 06:14:36 PM »
ok, I have updated Avast programm.
Now I have the new version, but where is the Virus Chest now ?? I cannot find it. So I cannot restore the items and do a new scan with the updated programm..

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: suddenly old pdf-files are infected with PDF.UrlMal-inf [Trj]
« Reply #3 on: November 26, 2015, 06:22:17 PM »
Quote
I did a full-system-scan today (with avast internet security 2015) and it suddenly marked several pdf's from 2012 as infected with PDF.UrlMal-inf [Trj]
it means pdf file(s) containe Blacklisted URLs ... not 100% sure but i think avast only detect this if links are clickable







REDACTED

  • Guest
Re: suddenly old pdf-files are infected with PDF.UrlMal-inf [Trj]
« Reply #4 on: November 26, 2015, 06:24:36 PM »
Never mind, I have found the viruschest. I wil now do a new full-system-scan, perhaps it will give different results.

Anyway, I cannot imagine why the url's that these documents may contain are blacklisted. They are pdf-files from a ligit company

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: suddenly old pdf-files are infected with PDF.UrlMal-inf [Trj]
« Reply #5 on: November 26, 2015, 06:28:43 PM »
Quote
They are pdf-files from a ligit company
Why should that be an issue?

FBI may send you pdf doc tomorrow containing a URL to some webiste, then one month later that website is hacked and infected and end up on a blacklist ... then nextime you open that pdf it is detected as containing a blacklisted URL




« Last Edit: November 26, 2015, 06:30:18 PM by Pondus »

REDACTED

  • Guest
Re: suddenly old pdf-files are infected with PDF.UrlMal-inf [Trj]
« Reply #6 on: November 26, 2015, 06:41:58 PM »
OK. So what should I do with these pdf's now ? Should I leave them quarantined?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: suddenly old pdf-files are infected with PDF.UrlMal-inf [Trj]
« Reply #7 on: November 26, 2015, 06:55:17 PM »
OK. So what should I do with these pdf's now ? Should I leave them quarantined?
at the moment yes, if the urls are taken of blacklist detection will be gone and you can restore them
you may right click files in chest and report to avast lab as False Positives -> https://www.avast.com/faq.php?article=AVKB21#artTitle





« Last Edit: November 26, 2015, 06:57:12 PM by Pondus »

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: suddenly old pdf-files are infected with PDF.UrlMal-inf [Trj]
« Reply #8 on: November 26, 2015, 06:57:30 PM »
Can you find all the links, paste them here so we can take a look? Break the links so they aren't clickable by others. Have you already reported them as FP to Avast!? If not, dpi g that may resolve the issue.

@Pondus, that'd be the NSA. They want into iPhones now lol. However, I find the FBI just as untrustworthy
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: suddenly old pdf-files are infected with PDF.UrlMal-inf [Trj]
« Reply #9 on: November 26, 2015, 10:29:28 PM »
Yup, as others pointed out, this detections flags PDF files if they have a clickable link to a blacklisted URL. I am not sure if we can actually solve the problem without having the PDF(s) ;)
You can send the file for example by using:
- FTP server (post the filename here) (https://www.avast.com/faq.php?article=AVKB160)
- any file hosting (post the link here)

REDACTED

  • Guest
Re: suddenly old pdf-files are infected with PDF.UrlMal-inf [Trj]
« Reply #10 on: November 27, 2015, 08:13:16 AM »
Michael, how do I find the url's if I cannot open the pdf-file because it is in the viruschest ?

Offline mikaelrask

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1556
Re: suddenly old pdf-files are infected with PDF.UrlMal-inf [Trj]
« Reply #11 on: November 27, 2015, 08:21:21 AM »
hey if you want to send the files to avast, you can go into the viruschest and right click on the files in there and click on send to virus lab.
Windows 8.1 amd a10-5700 64 bit
12 GB ram 1 tb hard drive. Avast 18, MBAM

REDACTED

  • Guest
Re: suddenly old pdf-files are infected with PDF.UrlMal-inf [Trj]
« Reply #12 on: November 27, 2015, 10:02:35 AM »
ok, thanks I did that now

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: suddenly old pdf-files are infected with PDF.UrlMal-inf [Trj]
« Reply #13 on: November 27, 2015, 10:08:29 AM »
While the file should be in our system now (or maybe at your next update, depending on your settings), I have no way of finding it, if you do not supply additional data. Could you turn the shields off, restore the file from the chest, upload it to virustotal and post the link to virustotal results here?