Author Topic: PDF:UrlMal-inf[Trj] moved to Virus Chest - but it wasn't  (Read 2326 times)

0 Members and 1 Guest are viewing this topic.

Offline gladtobegrey

  • Newbie
  • *
  • Posts: 9
PDF:UrlMal-inf[Trj] moved to Virus Chest - but it wasn't
« on: September 23, 2019, 12:18:42 PM »
This morning a message popped up to say that this had been detected in a pdf file in a copy of the Windows File History (from another machine).  I understand that it means that the document has a URL reference to a malicious/blacklisted site.

However, when I looked in the Virus Chest, the document was not there.  I am running a targeted scan to see if it is reported again.

Why was it (apparently) not moved to the Virus Chest?

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2294
Re: PDF:UrlMal-inf[Trj] moved to Virus Chest - but it wasn't
« Reply #1 on: September 23, 2019, 12:28:48 PM »
Hello,
the Virus chest can be full or the file too big to fit in there (check virus chest settings).

Milos

Offline gladtobegrey

  • Newbie
  • *
  • Posts: 9
Re: PDF:UrlMal-inf[Trj] moved to Virus Chest - but it wasn't
« Reply #2 on: September 23, 2019, 05:38:45 PM »
Virus Chest: 256MB (the default, presumably, as I have not changed it.
There were five or six items in the Chest already, so perhaps it was full.  I'll increase the size (to 1024MB) and see if that makes any difference.

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2294
Re: PDF:UrlMal-inf[Trj] moved to Virus Chest - but it wasn't
« Reply #3 on: September 24, 2019, 09:19:30 AM »
Also check the settings for actions in case of detection -- if there is "Move to chest".

Milos

Offline gladtobegrey

  • Newbie
  • *
  • Posts: 9
Re: PDF:UrlMal-inf[Trj] moved to Virus Chest - but it wasn't
« Reply #4 on: September 26, 2019, 11:29:53 AM »
"Move to Chest" is set.  It would seem the Virus Chest was too small at 256MB with half a dozen items already in there.  I've cleared it, upped the size, and this time the new item(s) were moved in.

Pity Avast doesn't:
  • Report that it was unable to move the item into the Virus chest because of lack of space
  • identify the offending url(s) it found.  It must have that information.

I sent the offending PDFs to Avast for evaluation.

Offline gladtobegrey

  • Newbie
  • *
  • Posts: 9
Re: PDF:UrlMal-inf[Trj] moved to Virus Chest - but it wasn't
« Reply #5 on: September 28, 2019, 11:44:05 AM »
I have not yet received a response to sending the 'offending' pdfs to Avast for evaluation.

The original files were held on an external USB drive.  I copied them to my hard drive, and the copies were flagged and moved to the Virus Chest.

Opening the files in Adobe Reader does not trigger the same response.

If I  "Scan the files for viruses" from Windows File Explorer right-click context menu Avast reports "Scan from Windows Explorer has finished. No issues found."

Is the File Explorer scan only checking for viruses, and not for links to malicious sites?  Seems like a serious omission, if so.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89051
  • No support PMs thanks
Re: PDF:UrlMal-inf[Trj] moved to Virus Chest - but it wasn't
« Reply #6 on: September 28, 2019, 05:56:26 PM »
@  gladtobegrey
You could try creating a new folder on your drive c:\ drive or somewhere convenient and call is something like c:\avast-exclude and exclude the location within the avast program exclusions. 

That should allow you to copy to that location and from there to avast.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: PDF:UrlMal-inf[Trj] moved to Virus Chest - but it wasn't
« Reply #7 on: September 28, 2019, 06:33:16 PM »
Do these PDFs contain any private information? If not, can you upload them to something like Dropbox/Google and DM me a link?

Are there any links visible in the PDF that you can click? (Don't click them!)
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline gladtobegrey

  • Newbie
  • *
  • Posts: 9
Re: PDF:UrlMal-inf[Trj] moved to Virus Chest - but it wasn't
« Reply #8 on: October 02, 2019, 06:14:48 PM »
@DavidR re: "That should allow you to copy to that location and from there to avast".  Thanks for the suggestion, however I sent the files from the Virus Chest, so didn't need to set up a separate exclude folder.

I've  had cause to reload files from the disk which originally cause the problem, and Avast seems to no longer be flagging them/moving them to the Virus Chest.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89051
  • No support PMs thanks
Re: PDF:UrlMal-inf[Trj] moved to Virus Chest - but it wasn't
« Reply #9 on: October 02, 2019, 07:30:10 PM »
You're welcome, good to hear that it is now resolved.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security